boredchilada
cyfar.ca
boredchilada
@cyfar.ca
I sheer alpacas and try to defend the internet from malware, minimal memes, mostly biznez

Cyfar.ca
@[email protected]
30 day distribution of wp2shell
September 5, 2026 at 2:58 PM
July 27, 2026 at 12:03 AM
more shai!

Package Version(s) Publisher
tiktoken-mcp 0.13.1, 0.13.2 — <-- LLM INJECTION
instructor-mcp 1.15.2, 1.15.3 —
langchain-core-mcp 1.4.2, 1.4.3 —
openai-mcp 2.41.1, 2.41.2 —
orchestr8-platform 3.3.2 Orchestr8 Team
ray-mcp-server 0.2.1 Vaskin Kissoyan

@socket.dev
June 7, 2026 at 11:23 PM
Another one

rlask==3.1.4-7
tlask== 3.1.4

same aes encryption (128) just rot 20 this time.

pypi.org/user/elitexp/

@socket.dev
June 7, 2026 at 3:02 PM
@socket.dev

Seems like theres an active shai hulud across 27 packages on pypi? 99.9% sure.

coolbox, funcdesc, ... Weize Xu
June 5, 2026 at 11:51 PM
we've been seeing a lot of docker attacks, more and more are carrying what looks like agentic command nomenclature you see when you use tools like Claude code.

Another attack involved a script being dropped onto every docker container.

new engagements coming soon detailing these
May 31, 2026 at 5:05 PM
thanks bing

claudecode(.)us(.)com -> setup-code(.)com

#malware #socialengineering #bing #brocomeon #didntfallforittho #claude
May 27, 2026 at 10:26 PM
hi bb

ioc:34.70.205[.]211

#xmrig #cryptominer
May 19, 2026 at 5:24 PM
whats up with this recent attack chain uptick?

attackers are rotating them or something X)

#malware #webdav #ntlm
May 18, 2026 at 12:13 PM
AI agent? or Vibes?

Seen on Docker API sensors, @greynoise.io spotted it too, not sure what they saw.

41.249.87.)223

#Threatintel #docker #AI #LLM
May 3, 2026 at 1:20 AM
clickfix / clearfake

hoteldelpaseocampeche[.]com/

https[:]//shield.pages[.]dev/js/shield[.]min[.]js

c2'ish : https[:]//api[.]cdn0v3[.]com/api/v1

dropper/loader: https[:]//gateway9[.]pages[.]dev/tom[.]tar

builds payload via csc
February 1, 2026 at 10:39 PM
hmmmm ...
January 7, 2026 at 5:45 AM
Okay, who let AI into @sophossecurity.bsky.social webservers?
December 19, 2025 at 5:13 PM
some weird lures with an obvious domain name?

microsoft. myluresevil .win
December 9, 2025 at 9:03 PM
Seems like redishell is being exploited now

seen in the wild.

196.251.70.)215
401120

#redishell #exploit #reverseshell
November 2, 2025 at 10:28 PM
Hackers be like
September 25, 2025 at 2:22 PM
Malware if anyone is interested:
https://1337x[.]to/torrent/6339414/Image-Line-FL-Studio-Producer-Edition-v24-2-2-Build-4597-All-Plugins-Edition-Crack-Repackmaster/

drops aurotun/monsterv2 via nsis

C2s: 198.251.84[.]224 & 196.251.72[.]174
port:7172
July 30, 2025 at 12:12 AM
June 17, 2025 at 11:58 PM