home.social

#codeinjection — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #codeinjection, aggregated by home.social.

fetched live
  1. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  2. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  3. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  4. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  5. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  6. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  7. GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension

    A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

    osintsights.com/github-breach-

    #Github #VsCode #SupplyChain #CodeInjection #ExtensionVulnerability

  8. SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

    SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

    osintsights.com/sap-patches-cr

    #SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity

  9. GitHub swiftly patches flaw exposing millions of private repos

    GitHub quickly squashed a massive security flaw, CVE-2026-3854, that could have let hackers access millions of private repositories with just one sneaky git push. The vulnerability allowed attackers to inject malicious code by exploiting how GitHub handled user-supplied options during git push operations.

    osintsights.com/github-swiftly

    #Github #Cve20263854 #SupplyChain #CodeInjection #EmergingThreats

  10. Apache ActiveMQ Vulnerability Exploited, Hits 6,400 Servers

    More than 6,400 publicly accessible Apache ActiveMQ servers are under attack, thanks to a high-severity code injection vulnerability that's being actively exploited. Is your server among them?

    osintsights.com/apache-activem

    #ApacheActivemq #CodeInjection #VulnerabilityExploitation #EmergingThreats #ServerSecurity

  11. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  12. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  13. 🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! radar.offseq.com/threat/cve-20 #OffSeq #n8n #CodeInjection #Infosec

  14. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  15. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  16. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  17. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  18. Attack Using Fake Python Infrastructure

    A sophisticated attack campaign was uncovered targeting the software supply chain and successfully exploiting multiple victims through account takeover, malicious code injection in repositories, and publishing of poisoned Python packages. The threat actors set up fake Python infrastructure to distribute malware that harvested sensitive data.

    Pulse ID: 6602e45fbee5bc3d4c622ae3
    Pulse Link: otx.alienvault.com/pulse/6602e
    Pulse Author: AlienVault
    Created: 2024-03-26 15:06:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #SupplyChain #bot #AlienVault

  19. Attack Using Fake Python Infrastructure

    A sophisticated attack campaign was uncovered targeting the software supply chain and successfully exploiting multiple victims through account takeover, malicious code injection in repositories, and publishing of poisoned Python packages. The threat actors set up fake Python infrastructure to distribute malware that harvested sensitive data.

    Pulse ID: 6602e45fbee5bc3d4c622ae3
    Pulse Link: otx.alienvault.com/pulse/6602e
    Pulse Author: AlienVault
    Created: 2024-03-26 15:06:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #SupplyChain #bot #AlienVault

  20. The malware strategically injects a specialized script tag into the victim’s browser, leading to an external script, enhancing the attack’s stealth by avoiding detection as simple loader scripts often are.

    #Cybersecurity #Trojan #CodeInjection #IBM #JavaScript #Banking

    cybersec84.wordpress.com/2023/

  21. The malware strategically injects a specialized script tag into the victim’s browser, leading to an external script, enhancing the attack’s stealth by avoiding detection as simple loader scripts often are.

    #Cybersecurity #Trojan #CodeInjection #IBM #JavaScript #Banking

    cybersec84.wordpress.com/2023/

  22. Hey #infosec/#appsec peeps...

    Ever wanted to work on #videogames? :) Cheat devs are using #hypervisor mods to do hard-to-detect #codeinjection and in-memory modification.

    #Bungie needs a low-level security engineer to help develop strategies that can be implemented in game clients running on compromised hardware to detect, mitigate, and run psyops on cheaters and cheat devs.

    If you like adversarial work, it's pretty awesome. Come talk to me :)

    #security #gamedev #ReverseEngineering #RE

  23. Nachdem das Problem bereits bei Facebook und Instagram aufgedeckt worden war, hat sich ein Sicherheitsforscher nun auch den chinesischen Videodienst angesehen.
    Auch TikTok-App soll mit internem iPhone-Browser spionieren können
  24. Eine Schwachstelle der Luca-App hätte ganze Gesundheitsämter lahmlegen können. Nun kommt auch Kritik vom Bundesamt für Sicherheit in der Informationstechnik. BSI kritisiert ebenfalls Luca-App: "Angriffs-Szenario plausibel"
  25. Eine dem Anbieter bereits bekannte Sicherheitslücke der Luca-App kann ausgenutzt werden, um Schadcode einzuschleusen – und so Gesundheitsämter lahmzulegen. Gefahr für Gesundheitsämter: Luca-App ermöglicht Code Injection
  26. :firefox: Browser: Mozilla härtet Firefox gegen Code-Injection

    📌 Das Security-Team von Mozilla will den Firefox-Browser besser gegen Code-Injection-Lücken härten, verzichtet dafür auf Inline-Aufrufe in den eigenen About-Seiten und hat die Nutzung der eval()-Funktion überarbeitet.

    #Browser #Mozilla #Firefox #codeinjection #CodeInjectionLücken #Internet

    golem.de/news/browser-mozilla-