Post #4131877
2026-07-27 07:52 UTC
It also never ceases to amaze me that people will compromise a widely used library / service and then ship a highly specific Bitcoin malware instead of a more general infostealer or something like that. If you have that kind of access, why burn it on something dumb?
I mean, I guess I'm happy they did, but still.
Also, Permission Policy works - on the site I was doing incident response for, the malware was actually blocked by the Permission Policy disabling clipboard access requests.
Replies (2)
-
@d33pjs@infosec.exchange 2026-07-27 22:13
@hacksilon@infosec.exchange PS. I like to add more hashtags to make it easier for people to find your post about malicious adform package. #supplychain #supplychainsecurity #supplychainattack #npm #npmsecurity #ioc
-
@d33pjs@infosec.exchange 2026-07-27 22:03
@hacksilon@infosec.exchange Now it would be pretty nice, having a SBOM Management Platform and all of your software supply chain SBOMs to check, which one did use it. Thanks for making the public aware of that.