Cyfar.ca
@[email protected]
Package Version(s) Publisher
tiktoken-mcp 0.13.1, 0.13.2 — <-- LLM INJECTION
instructor-mcp 1.15.2, 1.15.3 —
langchain-core-mcp 1.4.2, 1.4.3 —
openai-mcp 2.41.1, 2.41.2 —
orchestr8-platform 3.3.2 Orchestr8 Team
ray-mcp-server 0.2.1 Vaskin Kissoyan
@socket.dev
Package Version(s) Publisher
tiktoken-mcp 0.13.1, 0.13.2 — <-- LLM INJECTION
instructor-mcp 1.15.2, 1.15.3 —
langchain-core-mcp 1.4.2, 1.4.3 —
openai-mcp 2.41.1, 2.41.2 —
orchestr8-platform 3.3.2 Orchestr8 Team
ray-mcp-server 0.2.1 Vaskin Kissoyan
@socket.dev
rlask==3.1.4-7
tlask== 3.1.4
same aes encryption (128) just rot 20 this time.
pypi.org/user/elitexp/
@socket.dev
rlask==3.1.4-7
tlask== 3.1.4
same aes encryption (128) just rot 20 this time.
pypi.org/user/elitexp/
@socket.dev
Seems like theres an active shai hulud across 27 packages on pypi? 99.9% sure.
coolbox, funcdesc, ... Weize Xu
Seems like theres an active shai hulud across 27 packages on pypi? 99.9% sure.
coolbox, funcdesc, ... Weize Xu
Another attack involved a script being dropped onto every docker container.
new engagements coming soon detailing these
Another attack involved a script being dropped onto every docker container.
new engagements coming soon detailing these
claudecode(.)us(.)com -> setup-code(.)com
#malware #socialengineering #bing #brocomeon #didntfallforittho #claude
claudecode(.)us(.)com -> setup-code(.)com
#malware #socialengineering #bing #brocomeon #didntfallforittho #claude
Seen on Docker API sensors, @greynoise.io spotted it too, not sure what they saw.
41.249.87.)223
#Threatintel #docker #AI #LLM
Seen on Docker API sensors, @greynoise.io spotted it too, not sure what they saw.
41.249.87.)223
#Threatintel #docker #AI #LLM
hoteldelpaseocampeche[.]com/
https[:]//shield.pages[.]dev/js/shield[.]min[.]js
c2'ish : https[:]//api[.]cdn0v3[.]com/api/v1
dropper/loader: https[:]//gateway9[.]pages[.]dev/tom[.]tar
builds payload via csc
hoteldelpaseocampeche[.]com/
https[:]//shield.pages[.]dev/js/shield[.]min[.]js
c2'ish : https[:]//api[.]cdn0v3[.]com/api/v1
dropper/loader: https[:]//gateway9[.]pages[.]dev/tom[.]tar
builds payload via csc
microsoft. myluresevil .win
microsoft. myluresevil .win
seen in the wild.
196.251.70.)215
401120
#redishell #exploit #reverseshell
seen in the wild.
196.251.70.)215
401120
#redishell #exploit #reverseshell
https://1337x[.]to/torrent/6339414/Image-Line-FL-Studio-Producer-Edition-v24-2-2-Build-4597-All-Plugins-Edition-Crack-Repackmaster/
drops aurotun/monsterv2 via nsis
C2s: 198.251.84[.]224 & 196.251.72[.]174
port:7172
https://1337x[.]to/torrent/6339414/Image-Line-FL-Studio-Producer-Edition-v24-2-2-Build-4597-All-Plugins-Edition-Crack-Repackmaster/
drops aurotun/monsterv2 via nsis
C2s: 198.251.84[.]224 & 196.251.72[.]174
port:7172