#Malware-Dev
wooow the axo dot dev website (rip) is now serving malware

..just so you know.
November 28, 2025 at 1:13 PM
"making literal malware where it's purposely incompatible with another dev you have beef with" has happened *THREE* separate times, all in different fucking games
September 20, 2026 at 1:29 AM
yeah people immediately jumping to assuming this first time dev is doing this with malicious intent is lowkey kinda fucked. is the keycounter stuff an oversight? sure. something to raise concern over? yes! malware? pump the brakes.
this is the dev you guys think/thought was making a malicious program.....?
September 21, 2026 at 8:44 PM
"hey smelly how do i learn malware reverse engineering?"

I DONT KNOW.

I never took classes, I barely read any books on it. I learned C, malware dev, then I somehow magically learned asm and reverse engineering

I learned backwards. You figure out a better way
March 12, 2026 at 4:44 PM
- dev accidentally puts malware in build
- people freak out bc obviously, there's malware (also the dev only has some of the source code open)
- dev can't handle it, crashes out and says he is not going to work on the project going forward
April 29, 2025 at 4:24 PM
As The Choicer Voicer's popularity grows, more and more copycats exist. If you search the game's name, 95% of what you see are websites designed to siphon your clicks. Please exercise caution. I was made aware that someone even used my dev name on Github to upload malware.
August 18, 2026 at 6:51 AM
i love pds malware as a service too, are u interested in doing this dev on top of tranquil
March 6, 2026 at 7:36 AM
Sideloading is critical to app dev so my uninformed guess here is that it will come down to flipping a switch in Developer Options to allow unsigned/unverified apps.

I understand the reasoning (there's been a huge uptick in Android malware) but they're not being particularly transparent about this.
August 26, 2025 at 8:21 PM
I just realized we missed a great opportunity to feature this #MadeWithGodot game in this #GodotEngine blog post :(
store.steampowered.com/app/3019370/...

They'll have to wait for an upcoming dev snapshot ;)
November 29, 2024 at 11:43 PM
Malicious extension to AI software development assistant Cursor contained malware. It silently executed PowerShell scripts, installed remote access tools, and stole $500K in crypto from a blockchain dev. securelist.com/open-source-...
July 11, 2025 at 5:56 AM
Heads up. I got hit by something similar a few years back when someone hacked a dev I know. Got a DM asking for feedback for a game he was making. Nothing about the request was suspicious other than it being a rhythm game which was not the dev's usual? It was malware. Have to be careful nowadays.
@rittzler.bsky.social (creator of Pseudoregalia), has had their Discord and email hacked and is linking to a virus in disguise. If you see anything linking to a game called "Furfall", DO NOT engage with it. It's not made by Rittz and isn't a real game (it's a Remote Access Trojan) DO NOT CLICK IT.
December 28, 2025 at 11:54 AM
Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
Microsoft spots fresh XCSSET malware strain hiding in Apple dev projects
Upgraded nasty slips into Xcode builds, steals crypto, and disables macOS defenses The long-running XCSSET malware strain has evolved again, with Microsoft warning of a new macOS variant that expands its bag of tricks while continuing to target developers.…
dlvr.it
September 26, 2025 at 3:26 PM
somebody has let me know that my old domain (.site) now links to malware so just for reference my homepage is my url here, npckc.net 🥲

any other sites that have "npckc" in them but have different top-level domains are not actually mine so please do not click on links leading to them...
home
npckc, game dev & translator - making games to connect with other people
npckc.net
February 13, 2026 at 1:34 PM
Hello world! With Bluesky picking up steam I guess a (re-)introduction is in order. My name is Cas, I'm a red teamer at a big bank in the Netherlands. I like malware development (specifically in modern languages like Rust or Go) and learning more dev stuff every day. Content may include shitposts! 💜
November 17, 2024 at 10:20 PM
Hundreds of code libraries posted to NPM try to install malware on dev machines. arstechnica.com
November 4, 2024 at 11:49 PM
I don’t have an uma in this race because I only used gshade and promptly removed it when the dev put literal malware on it; god be with y’all
August 28, 2025 at 5:35 AM
Dev machines are the weak link: supply-chain malware stealing credentials before code even reaches prod. #SupplyChain #CloudSecurity #DevOps #Malware #Credentials #CyberSecurity https://thedailytechfeed.com/developer-machines-as-supply-chain-weak-links-in-cloud-breaches/
September 30, 2026 at 3:24 PM
Extension isolation: Dev Containers again.

With them, not only `pnpm start` runs in a container, but also many editor extensions, linters, or type checkers.

Malware in an extension or language server again can’t steal secrets from your system.
May 20, 2026 at 3:10 PM
First time using Fiverr:

— Created an account
— Found a Steam capsule artist
— Sent my first message about a commission
— Got permanently suspended for “phishing or malware activity”

All in about 10 minutes.

Indie dev comes with unexpected side quests. 😆

#IndieDev #GameDev
August 14, 2026 at 9:59 AM
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
TeamPCP? Or copycat malware dev?
www.theregister.com
June 1, 2026 at 9:59 PM
Next, apply the second question to npm: isolation.

Use Dev Containers, so the whole project runs inside a container, and malware from a dependency can’t steal your npm token or your GitHub or Slack cookies from browser.
May 20, 2026 at 3:10 PM
'far less likely to upload my entire drive to a malware site' doing incredible work as a product endorsement. We really speedran the trust decay on dev tools. Two years ago this would've been a joke
March 18, 2026 at 1:40 AM
third-party.com, a dev-placeholder domain, now pushes malware via ClickFix across 1,700+ repos—use example.com instead. #WebSecurity #CyberThreat #ClickFix #MockDomains #DevOps #Malware thedailytechfeed.com/placeholder-...
September 24, 2026 at 3:47 PM
New on Aether: Why ChatGPT refuses reverse-engineering questions (and what to do instead)

ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational ones

https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
October 1, 2026 at 8:00 AM
Hi Bluesky: I'm jeFF0Falltrades and you may remember me from such films as "Modding RollerCoaster Tycoon into a Peele Horror Film" or "Building a DIY Malware Analysis Lab"

I make #reverseengineering, #software dev, and #cybersecurity content by night, and memes and occasional research by day. NTMY👋
November 18, 2024 at 2:34 PM