home.social

#sha1hulud — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sha1hulud, aggregated by home.social.

fetched live
  1. Just checked back on the Sha1-Hulud virus/worm. FINALLY npm appears free of obviously infected packages.

    I still however am seeing infected machines posting their private data publicly on GitHub.

    Not only that, I can see infected developer's github repos are being defaced in realtime.

    These microsoft owned platforms seem to be really struggling with stopping this worm.

    Query for defaced repos 👇🏿

    github.com/search?q=api.airfor

    #NPM #microsoft #github #Sha1Hulud #WalkWithoutRhythm #cybersecurity

  2. Just checked back on the Sha1-Hulud virus/worm. FINALLY npm appears free of obviously infected packages.

    I still however am seeing infected machines posting their private data publicly on GitHub.

    Not only that, I can see infected developer's github repos are being defaced in realtime.

    These microsoft owned platforms seem to be really struggling with stopping this worm.

    Query for defaced repos 👇🏿

    github.com/search?q=api.airfor

    #NPM #microsoft #github #Sha1Hulud #WalkWithoutRhythm #cybersecurity

  3. Just checked back on the Sha1-Hulud virus/worm. FINALLY npm appears free of obviously infected packages.

    I still however am seeing infected machines posting their private data publicly on GitHub.

    Not only that, I can see infected developer's github repos are being defaced in realtime.

    These microsoft owned platforms seem to be really struggling with stopping this worm.

    Query for defaced repos 👇🏿

    github.com/search?q=api.airfor

    #NPM #microsoft #github #Sha1Hulud #WalkWithoutRhythm #cybersecurity

  4. Just checked back on the Sha1-Hulud virus/worm. FINALLY npm appears free of obviously infected packages.

    I still however am seeing infected machines posting their private data publicly on GitHub.

    Not only that, I can see infected developer's github repos are being defaced in realtime.

    These microsoft owned platforms seem to be really struggling with stopping this worm.

    Query for defaced repos 👇🏿

    github.com/search?q=api.airfor

    #NPM #microsoft #github #Sha1Hulud #WalkWithoutRhythm #cybersecurity

  5. Just checked back on the Sha1-Hulud virus/worm. FINALLY npm appears free of obviously infected packages.

    I still however am seeing infected machines posting their private data publicly on GitHub.

    Not only that, I can see infected developer's github repos are being defaced in realtime.

    These microsoft owned platforms seem to be really struggling with stopping this worm.

    Query for defaced repos 👇🏿

    github.com/search?q=api.airfor

    #NPM #microsoft #github #Sha1Hulud #WalkWithoutRhythm #cybersecurity

  6. so with #sha1hulud v2 around, there's never been a worse time to experiment with #typescript. (which i'm doing now. timing.)

    me: "how do i check *all* the dependencies? not just the top level, but recursively through their dependencies as well?"
    google results: `npm view ls` will do that for your installed packages :)

    ...yeah but guess when sha1hulud detonates? in a pre- or post- install script.

    so i made this. github.com/AdamRGrey/npm-depen
    hopefully npm doesn't mind being pinged that much. (and then i manually cross reference with a list of known infected packages; here's one: jfrog.com/blog/shai-hulud-npm- )

  7. so with #sha1hulud v2 around, there's never been a worse time to experiment with #typescript. (which i'm doing now. timing.)

    me: "how do i check *all* the dependencies? not just the top level, but recursively through their dependencies as well?"
    google results: `npm view ls` will do that for your installed packages :)

    ...yeah but guess when sha1hulud detonates? in a pre- or post- install script.

    so i made this. github.com/AdamRGrey/npm-depen
    hopefully npm doesn't mind being pinged that much. (and then i manually cross reference with a list of known infected packages; here's one: jfrog.com/blog/shai-hulud-npm- )

  8. so with #sha1hulud v2 around, there's never been a worse time to experiment with #typescript. (which i'm doing now. timing.)

    me: "how do i check *all* the dependencies? not just the top level, but recursively through their dependencies as well?"
    google results: `npm view ls` will do that for your installed packages :)

    ...yeah but guess when sha1hulud detonates? in a pre- or post- install script.

    so i made this. github.com/AdamRGrey/npm-depen
    hopefully npm doesn't mind being pinged that much. (and then i manually cross reference with a list of known infected packages; here's one: jfrog.com/blog/shai-hulud-npm- )

  9. so with #sha1hulud v2 around, there's never been a worse time to experiment with #typescript. (which i'm doing now. timing.)

    me: "how do i check *all* the dependencies? not just the top level, but recursively through their dependencies as well?"
    google results: `npm view ls` will do that for your installed packages :)

    ...yeah but guess when sha1hulud detonates? in a pre- or post- install script.

    so i made this. github.com/AdamRGrey/npm-depen
    hopefully npm doesn't mind being pinged that much. (and then i manually cross reference with a list of known infected packages; here's one: jfrog.com/blog/shai-hulud-npm- )

  10. #pypi on the #sha1hulud situation:

    "PyPI has not been exploited, however some PyPI credentials were found exposed in compromised repositories. We've revoked these tokens as a precaution, there's no evidence they have been used maliciously. This post raises awareness about the attack and encourages proactive steps to secure your accounts, especially if you're using build platforms to publish packages to PyPI."

    blog.pypi.org/posts/2025-11-26

  11. #pypi on the #sha1hulud situation:

    "PyPI has not been exploited, however some PyPI credentials were found exposed in compromised repositories. We've revoked these tokens as a precaution, there's no evidence they have been used maliciously. This post raises awareness about the attack and encourages proactive steps to secure your accounts, especially if you're using build platforms to publish packages to PyPI."

    blog.pypi.org/posts/2025-11-26

  12. #pypi on the #sha1hulud situation:

    "PyPI has not been exploited, however some PyPI credentials were found exposed in compromised repositories. We've revoked these tokens as a precaution, there's no evidence they have been used maliciously. This post raises awareness about the attack and encourages proactive steps to secure your accounts, especially if you're using build platforms to publish packages to PyPI."

    blog.pypi.org/posts/2025-11-26

  13. #pypi on the #sha1hulud situation:

    "PyPI has not been exploited, however some PyPI credentials were found exposed in compromised repositories. We've revoked these tokens as a precaution, there's no evidence they have been used maliciously. This post raises awareness about the attack and encourages proactive steps to secure your accounts, especially if you're using build platforms to publish packages to PyPI."

    blog.pypi.org/posts/2025-11-26

  14. #pypi on the #sha1hulud situation:

    "PyPI has not been exploited, however some PyPI credentials were found exposed in compromised repositories. We've revoked these tokens as a precaution, there's no evidence they have been used maliciously. This post raises awareness about the attack and encourages proactive steps to secure your accounts, especially if you're using build platforms to publish packages to PyPI."

    blog.pypi.org/posts/2025-11-26

  15. Theo doing a deeper dive into #sha1hulud and points out how central #Github actions are to this fiasco.

    youtu.be/weLhik7ArCY?si=8RMSgK

  16. Theo doing a deeper dive into #sha1hulud and points out how central #Github actions are to this fiasco.

    youtu.be/weLhik7ArCY?si=8RMSgK

  17. Theo doing a deeper dive into #sha1hulud and points out how central #Github actions are to this fiasco.

    youtu.be/weLhik7ArCY?si=8RMSgK

  18. Theo doing a deeper dive into #sha1hulud and points out how central #Github actions are to this fiasco.

    youtu.be/weLhik7ArCY?si=8RMSgK

  19. Theo doing a deeper dive into #sha1hulud and points out how central #Github actions are to this fiasco.

    youtu.be/weLhik7ArCY?si=8RMSgK

  20. I was able to track down 3 out of the remaining 5 affected packages and posted bug reports & security alerts to those developers I located.

    Sure would be nice if NPM and GitHub did this automatically.... kinda feel like I've done an awful lot of free labor for Microsoft this week.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #microsoft #npm

  21. I was able to track down 3 out of the remaining 5 affected packages and posted bug reports & security alerts to those developers I located.

    Sure would be nice if NPM and GitHub did this automatically.... kinda feel like I've done an awful lot of free labor for Microsoft this week.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #microsoft #npm

  22. I was able to track down 3 out of the remaining 5 affected packages and posted bug reports & security alerts to those developers I located.

    Sure would be nice if NPM and GitHub did this automatically.... kinda feel like I've done an awful lot of free labor for Microsoft this week.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #microsoft #npm

  23. I was able to track down 3 out of the remaining 5 affected packages and posted bug reports & security alerts to those developers I located.

    Sure would be nice if NPM and GitHub did this automatically.... kinda feel like I've done an awful lot of free labor for Microsoft this week.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #microsoft #npm

  24. I was able to track down 3 out of the remaining 5 affected packages and posted bug reports & security alerts to those developers I located.

    Sure would be nice if NPM and GitHub did this automatically.... kinda feel like I've done an awful lot of free labor for Microsoft this week.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #microsoft #npm

  25. Is NPM still dangerous?

    Yes, we're down to five known infected packages still circulating on the Microsoft owned platform.

    The following five packages continue to spread the Sha1-Hulud worm with no warning at all on the NPM page nor at download/install time:

    hyper-fullfacing 1.0.3

    @ifelsedeveloper/protocol-contracts-svm-idl 0.1.2

    quickswap-ads-list 1.0.33

    @seung-ju/react-native-action-sheet 0.2.1

    tcsp 2.0.2

    #Sha1Hulud #microsoft #npm

  26. Is NPM still dangerous?

    Yes, we're down to five known infected packages still circulating on the Microsoft owned platform.

    The following five packages continue to spread the Sha1-Hulud worm with no warning at all on the NPM page nor at download/install time:

    hyper-fullfacing 1.0.3

    @ifelsedeveloper/protocol-contracts-svm-idl 0.1.2

    quickswap-ads-list 1.0.33

    @seung-ju/react-native-action-sheet 0.2.1

    tcsp 2.0.2

    #Sha1Hulud #microsoft #npm

  27. Is NPM still dangerous?

    Yes, we're down to five known infected packages still circulating on the Microsoft owned platform.

    The following five packages continue to spread the Sha1-Hulud worm with no warning at all on the NPM page nor at download/install time:

    hyper-fullfacing 1.0.3

    @ifelsedeveloper/protocol-contracts-svm-idl 0.1.2

    quickswap-ads-list 1.0.33

    @seung-ju/react-native-action-sheet 0.2.1

    tcsp 2.0.2

    #Sha1Hulud #microsoft #npm

  28. Is NPM still dangerous?

    Yes, we're down to five known infected packages still circulating on the Microsoft owned platform.

    The following five packages continue to spread the Sha1-Hulud worm with no warning at all on the NPM page nor at download/install time:

    hyper-fullfacing 1.0.3

    @ifelsedeveloper/protocol-contracts-svm-idl 0.1.2

    quickswap-ads-list 1.0.33

    @seung-ju/react-native-action-sheet 0.2.1

    tcsp 2.0.2

    #Sha1Hulud #microsoft #npm

  29. Is NPM still dangerous?

    Yes, we're down to five known infected packages still circulating on the Microsoft owned platform.

    The following five packages continue to spread the Sha1-Hulud worm with no warning at all on the NPM page nor at download/install time:

    hyper-fullfacing 1.0.3

    @ifelsedeveloper/protocol-contracts-svm-idl 0.1.2

    quickswap-ads-list 1.0.33

    @seung-ju/react-native-action-sheet 0.2.1

    tcsp 2.0.2

    #Sha1Hulud #microsoft #npm

  30. #sha1hulud has me so very spooked, that I dare not open any #electron apps and purged many of my dot files out of sheer paranoia. It is a scenario I dreaded for a long time. Fortunately, I never trusted vscode extensions and have disabled automatic update since forever. But when will the methods reach other languages, like #neovim #lua or #emacs #lisp? Nothing can be done the old way anymore, always checkout the repo, run analysis and build from there. This is killing the registry ecosystem.

  31. #sha1hulud has me so very spooked, that I dare not open any #electron apps and purged many of my dot files out of sheer paranoia. It is a scenario I dreaded for a long time. Fortunately, I never trusted vscode extensions and have disabled automatic update since forever. But when will the methods reach other languages, like #neovim #lua or #emacs #lisp? Nothing can be done the old way anymore, always checkout the repo, run analysis and build from there. This is killing the registry ecosystem.

  32. #sha1hulud has me so very spooked, that I dare not open any #electron apps and purged many of my dot files out of sheer paranoia. It is a scenario I dreaded for a long time. Fortunately, I never trusted vscode extensions and have disabled automatic update since forever. But when will the methods reach other languages, like #neovim #lua or #emacs #lisp? Nothing can be done the old way anymore, always checkout the repo, run analysis and build from there. This is killing the registry ecosystem.

  33. Running my NPM checks again today, I see eight remaining infected packages still circulating on the Microsoft owned platform.

    Unlike nodejs package index socket.dev NPM does not show ANY security warnings on these package's pages.

    It's pretty wild that these known compromised packages have been circulating for four days now with now response or action from Microsoft despite it being one of the largest security stories this month.

    #NPM #microsoft #GitHub #Sha1Hulud #cybersecurity

  34. Running my NPM checks again today, I see eight remaining infected packages still circulating on the Microsoft owned platform.

    Unlike nodejs package index socket.dev NPM does not show ANY security warnings on these package's pages.

    It's pretty wild that these known compromised packages have been circulating for four days now with now response or action from Microsoft despite it being one of the largest security stories this month.

    #NPM #microsoft #GitHub #Sha1Hulud #cybersecurity

  35. Running my NPM checks again today, I see eight remaining infected packages still circulating on the Microsoft owned platform.

    Unlike nodejs package index socket.dev NPM does not show ANY security warnings on these package's pages.

    It's pretty wild that these known compromised packages have been circulating for four days now with now response or action from Microsoft despite it being one of the largest security stories this month.

    #NPM #microsoft #GitHub #Sha1Hulud #cybersecurity

  36. Running my NPM checks again today, I see eight remaining infected packages still circulating on the Microsoft owned platform.

    Unlike nodejs package index socket.dev NPM does not show ANY security warnings on these package's pages.

    It's pretty wild that these known compromised packages have been circulating for four days now with now response or action from Microsoft despite it being one of the largest security stories this month.

    #NPM #microsoft #GitHub #Sha1Hulud #cybersecurity

  37. Running my NPM checks again today, I see eight remaining infected packages still circulating on the Microsoft owned platform.

    Unlike nodejs package index socket.dev NPM does not show ANY security warnings on these package's pages.

    It's pretty wild that these known compromised packages have been circulating for four days now with now response or action from Microsoft despite it being one of the largest security stories this month.

    #NPM #microsoft #GitHub #Sha1Hulud #cybersecurity

  38. Just finished writing another tool, now I can see NINE known compromised packages are still up for download on NPM! ⚠️

    This tool crawls the list of known bad packages and downloads the latest bundle.

    It then runs my other checks against the downloaded bundle and logs the results.

    github.com/datapartyjs/walk-wi

    #WalkWithoutRhythm #Sha1Hulud #NPM #GitHub #Microsoft #nodejs #javascript #cybersecurity #devlog #bash

  39. Just finished writing another tool, now I can see NINE known compromised packages are still up for download on NPM! ⚠️

    This tool crawls the list of known bad packages and downloads the latest bundle.

    It then runs my other checks against the downloaded bundle and logs the results.

    github.com/datapartyjs/walk-wi

    #WalkWithoutRhythm #Sha1Hulud #NPM #GitHub #Microsoft #nodejs #javascript #cybersecurity #devlog #bash

  40. Just finished writing another tool, now I can see NINE known compromised packages are still up for download on NPM! ⚠️

    This tool crawls the list of known bad packages and downloads the latest bundle.

    It then runs my other checks against the downloaded bundle and logs the results.

    github.com/datapartyjs/walk-wi

    #WalkWithoutRhythm #Sha1Hulud #NPM #GitHub #Microsoft #nodejs #javascript #cybersecurity #devlog #bash

  41. Just finished writing another tool, now I can see NINE known compromised packages are still up for download on NPM! ⚠️

    This tool crawls the list of known bad packages and downloads the latest bundle.

    It then runs my other checks against the downloaded bundle and logs the results.

    github.com/datapartyjs/walk-wi

    #WalkWithoutRhythm #Sha1Hulud #NPM #GitHub #Microsoft #nodejs #javascript #cybersecurity #devlog #bash

  42. Just finished writing another tool, now I can see NINE known compromised packages are still up for download on NPM! ⚠️

    This tool crawls the list of known bad packages and downloads the latest bundle.

    It then runs my other checks against the downloaded bundle and logs the results.

    github.com/datapartyjs/walk-wi

    #WalkWithoutRhythm #Sha1Hulud #NPM #GitHub #Microsoft #nodejs #javascript #cybersecurity #devlog #bash

  43. I've updated my suggestions to include links and info on how to get fine grained control over the scripts your projects run at compile time.

    There's two fairly interesting community projects that seem to address this part of the problem and make it possible to disable most install scripts while keeping the ones your project actually requires.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #NPM #nodejs #javascript

  44. I've updated my suggestions to include links and info on how to get fine grained control over the scripts your projects run at compile time.

    There's two fairly interesting community projects that seem to address this part of the problem and make it possible to disable most install scripts while keeping the ones your project actually requires.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #NPM #nodejs #javascript

  45. I've updated my suggestions to include links and info on how to get fine grained control over the scripts your projects run at compile time.

    There's two fairly interesting community projects that seem to address this part of the problem and make it possible to disable most install scripts while keeping the ones your project actually requires.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #NPM #nodejs #javascript

  46. I've updated my suggestions to include links and info on how to get fine grained control over the scripts your projects run at compile time.

    There's two fairly interesting community projects that seem to address this part of the problem and make it possible to disable most install scripts while keeping the ones your project actually requires.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #NPM #nodejs #javascript

  47. I've updated my suggestions to include links and info on how to get fine grained control over the scripts your projects run at compile time.

    There's two fairly interesting community projects that seem to address this part of the problem and make it possible to disable most install scripts while keeping the ones your project actually requires.

    github.com/datapartyjs/walk-wi

    #Sha1Hulud #NPM #nodejs #javascript

  48. These sorts of NPM worms have been around for a LONG time.

    It's typically due a common practice of low 2fa opt-in on NPM accounts.

    So be sure to setup NPM 2FA if you're a package maintainer do that asap!

    A lesser known NPM capability is that you can disable install time scripts. This may break some packages but its worth a try to see if your projects can work with out any install scripts. 👇🏿

    blog.npmjs.org/post/1417028810

    #GitHub #NPM #Microsoft #Sha1Hulud #nodejs #javascript

  49. These sorts of NPM worms have been around for a LONG time.

    It's typically due a common practice of low 2fa opt-in on NPM accounts.

    So be sure to setup NPM 2FA if you're a package maintainer do that asap!

    A lesser known NPM capability is that you can disable install time scripts. This may break some packages but its worth a try to see if your projects can work with out any install scripts. 👇🏿

    blog.npmjs.org/post/1417028810

    #GitHub #NPM #Microsoft #Sha1Hulud #nodejs #javascript

  50. These sorts of NPM worms have been around for a LONG time.

    It's typically due a common practice of low 2fa opt-in on NPM accounts.

    So be sure to setup NPM 2FA if you're a package maintainer do that asap!

    A lesser known NPM capability is that you can disable install time scripts. This may break some packages but its worth a try to see if your projects can work with out any install scripts. 👇🏿

    blog.npmjs.org/post/1417028810

    #GitHub #NPM #Microsoft #Sha1Hulud #nodejs #javascript