#Malware-Dev
Free software supply chain security tool that covers npm, yarn, cargo, gaoling, pypi, bun, secret scanning for dev and vibe-coder workstation!

Can run as a one time scan, or in protect mode.

https://boostsecurity.io/dazio

brew install boostsecurityio/tap/dazio
Dazio | Free malware scanner and package firewall for agentic coders & developers
Find out in two minutes if your developer machine is already infected. Dazio is free, scans for malicious packages and exposed secrets, and blocks new malware at every install. macOS and Linux.
boostsecurity.io
October 2, 2026 at 4:45 PM
New on Aether: Why ChatGPT refuses reverse-engineering questions (and what to do instead)

ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational ones

https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
October 1, 2026 at 8:00 AM
~Akamai~
32 extensions hid browsing surveillance and remote redirects, affecting 6,150+ users.
-
IOCs: api[.]pvmf[.]workers[.]dev, cdn[.]jsdelivr[.]net, link[.]coupang[.]com
-
#BrowserSecurity #Malware #ThreatIntel
Malicious Productivity Extensions
www.akamai.com
September 30, 2026 at 8:03 PM
Dev machines are the weak link: supply-chain malware stealing credentials before code even reaches prod. #SupplyChain #CloudSecurity #DevOps #Malware #Credentials #CyberSecurity https://thedailytechfeed.com/developer-machines-as-supply-chain-weak-links-in-cloud-breaches/
September 30, 2026 at 3:24 PM
Free guide: "Why ChatGPT refuses reverse-engineering questions (and what to do instead)"

ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational…

6-min read · https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
September 28, 2026 at 12:00 AM
ChatGPT and Claude hit a refusal wall when you ask for specific exploit dev or malware analysis. Aether doesn't. Get the technical answers these models dodge. #reverseengineering #infosec

https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
September 26, 2026 at 8:00 AM
third-party.com, a common placeholder in dev docs and AI agent configs, is now serving clipboard-hijacking malware. 1,700+ GitHub repos reference it. Static scans won't catch it. https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html
September 25, 2026 at 6:06 AM
ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational ones

We wrote a free 6-min guide: https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
September 24, 2026 at 4:00 PM
third-party.com, a dev-placeholder domain, now pushes malware via ClickFix across 1,700+ repos—use example.com instead. #WebSecurity #CyberThreat #ClickFix #MockDomains #DevOps #Malware thedailytechfeed.com/placeholder-...
September 24, 2026 at 3:47 PM
New Signal Check is live: Episode 176 - September 24, 2026. This episode digs into the hidden risks lurking in everyday dev tools, AI-powered malware that votes on its next move, and a massive cyberattack where hackers weaponized AI agents to hit a… Listen: https://share.transistor.fm/s/ef6504ae
September 24, 2026 at 9:00 AM
~Varonis~
AvisLoader uses ClickFix delivery and Tox P2P C2 to evade domain takedowns.
-
IOCs: trycloudflare[.]com, workers[.]dev, 35dd164a7f5d8b42b9870c7009f7425b1c8cb771280c9e6c525e09f3dd13c2cc
-
#AvisLoader #ClickFix #Malware #ThreatIntel
AvisLoader Windows Loader
www.varonis.com
September 23, 2026 at 4:21 PM
Graphalgo hid malware in Terraform providers & Go modules—Slack, blockchain & trigger-based payloads now part of the game. #Malware #DevTools #Terraform #GoModules #Graphalgo #CloudSecurity https://thedailytechfeed.com/terraform-providers-hijacked-malware-lurking-in-dev-tools/
September 23, 2026 at 9:40 AM
A fake Twilio bug-bounty npm package stole dev credentials under disguise. Audit dependencies carefully. #SecurityNews #npm #SupplyChain #Twilio #Malware #DeveloperSecurity https://thedailytechfeed.com/malicious-npm-package-masquerades-as-twilio-probe-steals-credentials/
September 23, 2026 at 8:36 AM
30k+ devices infected via fake job interviews. North Korea's WaterPlum weaponized the hiring test to drain $10M+.

Don't fall for the trap. Read the breakdown:
worldtimeshindi.com/fake-job-int...

#Cybersecurity #DevSky #TechNews #BuyMeACoffee #WritingCommunity
Fake Job Interview Malware: How North Korea Targets Devs
North Korea’s fake job interview scam infected 30K devices and stole millions. Learn how this dev recruitment trap works and protect your syste
worldtimeshindi.com
September 23, 2026 at 5:23 AM
Free guide: "Why ChatGPT refuses reverse-engineering questions (and what to do instead)"

ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational…

6-min read · https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
September 23, 2026 at 12:00 AM
Of course it's still up to everyone how careful they want to be with this kind of thing, but as far as I can tell, the dev seems genuine and there's certainly better ways to try and spread malware than through Steam where the counter is a promoted feature.
September 22, 2026 at 11:04 PM
Thanks for the link, I didn't know that!

And yeah, I would have liked to see some actual network logs/packet traces, because actual malware would be sending that information somewhere. It's good to be cautious but this seems like an honest oversight from a new dev!
September 22, 2026 at 5:59 AM
steam has had its fair share of letting malware into their storefront that is true but if theres no actual breakdown of the malicious code in the game thats fucking nothing and youre ruining an indie dev whos just starting out
September 22, 2026 at 2:15 AM
No, that's the opposite of what I wrote: it looks like the way this feature was implemented is *less* concerning than what some of the more fearmongery posts I've been seeing are trying to claim. I highly doubt that it's malware; it's a very-early-in-development demo from a newbie dev.
September 21, 2026 at 10:15 PM
yeah people immediately jumping to assuming this first time dev is doing this with malicious intent is lowkey kinda fucked. is the keycounter stuff an oversight? sure. something to raise concern over? yes! malware? pump the brakes.
this is the dev you guys think/thought was making a malicious program.....?
September 21, 2026 at 8:44 PM
"making literal malware where it's purposely incompatible with another dev you have beef with" has happened *THREE* separate times, all in different fucking games
September 20, 2026 at 1:29 AM
ChatGPT and Claude trigger a refusal layer on most RE, malware-analysis, and exploit-dev questions — even purely educational ones

We wrote a free 6-min guide: https://trynoguard.com/learn/why-chatgpt-refuses-reverse-engineering
September 19, 2026 at 4:00 PM
@socket.dev
PolinRider compromised nova-two-factor dev branches via GitHub accounts, targeting developer environments.
-
IOCs: PolinRider, visanduma/nova-two-factor@dev-main
-
#Malware #SupplyChain #ThreatIntel
PolinRider Hits Packagist
socket.dev
September 17, 2026 at 8:07 PM
We’re tracking more North Korea-linked PolinRider activity across GitHub and Packagist.

New findings: 4 malicious dev versions, rewritten Git history, and obfuscated JavaScript planted in index.php and executed through PHP’s shell_exec() function.

socket.dev/blog/polinri...
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
socket.dev
September 17, 2026 at 6:23 PM