Post #2869146
2025-11-26 22:22 UTC
@claushoumann@mastodon.social , in case if this new malware strain fails to exfiltrate data or authenticate it attempts to wipe user’s home directory ! (Windows & Linux) ⚠️
aka Should be a real asshole : dead man’s switch. Somehow nasty and revengeful.
Credential Harvest: Aggressively scrapes AWS, GCP, Azure, npm, and GitHub tokens.
Self-Propagation: Uses stolen npm tokens to instantly republish malicious versions of packages Devs maintain.
Replies (1)
-
@mabote@infosec.exchange 2025-11-27 19:18
@verbrecher@mastodon.social @claushoumann@mastodon.social you forgot to add: registers the host as a GitHub action runner to remote control it through a malicious workflow containing a voluntary injection vulnerability. Yeah, that's thing really is friendly.