Do It by Code
54 subscribers
714 photos
100 videos
15 files
1.24K links
We uhhhhh... do things by coding them.
Download Telegram
NPM debug and chalk packages compromised

🔸A malicious code was pushed to 18 popular npm packages, hijacking crypto and web3 activity in browsers. The attacker was caught and informed the maintainer after Aikido's intel feed alert, and some compromises were cleaned up.
Do It by Code
NPM debug and chalk packages compromised 🔸A malicious code was pushed to 18 popular npm packages, hijacking crypto and web3 activity in browsers. The attacker was caught and informed the maintainer after Aikido's intel feed alert, and some compromises were…
packages list:

- backslash (0.26m downloads per week)
- chalk-template (3.9m downloads per week)
- supports-hyperlinks (19.2m downloads per week)
- has-ansi (12.1m downloads per week)
- simple-swizzle (26.26m downloads per week)
- color-string (27.48m downloads per week)
- error-ex (47.17m downloads per week)
- color-name (191.71m downloads per week)
- is-arrayish (73.8m downloads per week)
- slice-ansi (59.8m downloads per week)
- color-convert (193.5m downloads per week)
- wrap-ansi (197.99m downloads per week)
- ansi-regex (243.64m downloads per week)
- supports-color (287.1m downloads per week)
- strip-ansi (261.17m downloads per week)
- chalk (299.99m downloads per week)
- debug (357.6m downloads per week)
- ansi-styles (371.41m downloads per week)
> do largest supply chain attack in history
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise

I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT

(stole this post from here)
🤓2
Windows KASLR Bypass – CVE-2025-53136

🔸Microsoft fixed a kernel address leak vulnerability in Windows 11/Server 2022 24H2, but introduced a new bug in CVE-2024-43511. The new bug allows a powerful kernel address leak through a race condition in the RtlSidHashInitialize() function.

11 Sep 2025

comments
Astrophysics Source Code Library

The Astrophysics Source Code Library (ASCL) is a free online registry and repository for source codes used in astronomy and astrophysics research. It is indexed by the SAO/NASA Astrophysics Data System (ADS) and Web of Science.
CVE-2023-52440:
Linux kernel ksmbd: slub overflow in ksmbd_decode_ntlmssp_auth_blob function.
If authblob->SessionKey.Length is bigger than session key size (CIFS_KEY_SIZE), slub overflow can happen in key exchange codes. cifs_arc4_crypt copy to session key array from SessionKey of client.

- patch commit
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVE-2023-4130:
Linux kernel ksmbd: wrong next length validation of ea buffer in smb2_set_ea function.
There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request from client.
ksmbd will then find next smb2_ea_info using ->NextEntryOffset of current smb2_ea_info. ksmbd needs to validate buffer length before accessing the next ea.
ksmbd should check buffer length using buf_len, not the next variable. next variable is the start offset of current ea that got from previous ea.

- patch commit

#cve #linux
Open mail relay

An open mail relay is a Simple Mail Transfer Protocol (SMTP) server configured in such a way that it allows anyone on the Internet to send e-mail through it, not just mail destined to or originating from known users.
This used to be the default configuration in many mail servers; indeed, it was the way the Internet was initially set up, but open mail relays have become unpopular because of their exploitation by spammers and worms. Many relays were closed, or were placed on blacklists by other servers.

https://en.m.wikipedia.org/wiki/Open_mail_relay
New York Tribune newspaper, December 4, 1921 (104 years ago)
sora2:
https://sora.chatgpt.com/

invite code:
3RZ05P (can be used only 4 times)
note:
* requires USA VPN
* it has way too many brainrots
CVE-2025-9864: Use after free in V8 in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

- issue tracker
- announcement
- heapspray PoC
- Heap spraying
there is a really basic kind of mutex in computer science that requires no operating system features: the spinlock.

Instead of blocking, the threads simply try to lock it again and again in a tight loop, thus burning CPU time until the mutex is free again.

Because they avoid overhead from operating system process rescheduling or context switching, spinlocks are efficient if threads are likely to be blocked for only short periods.
For this reason, operating-system kernels often use spinlocks. However, spinlocks become wasteful if held for longer durations, as they may prevent other threads from running and require rescheduling.

The longer a thread holds a lock, the greater the risk that the thread will be interrupted by the OS scheduler while holding the lock. If this happens, other threads will be left "spinning" (repeatedly trying to acquire the lock), while the thread holding the lock is not making progress towards releasing it.
The result is an indefinite postponement until the thread holding the lock can finish and release it. This is especially true on a single-processor system, where each waiting thread of the same priority is likely to waste its quantum (allocated time where a thread can run) spinning until the thread that holds the lock is finally finished.

Implementing spinlocks correctly is challenging because programmers must take into account the possibility of simultaneous access to the lock, which could cause race conditions. Generally, such an implementation is possible only with special assembly language instructions, such as atomic (i.e. un-interruptible) test-and-set operations and cannot be easily implemented in programming languages not supporting truly atomic operations.
1
https://www.pixnapping.com/

Pixnapping is a new class of attacks that allows a malicious Android app to stealthily leak information displayed by other Android apps or arbitrary websites. Pixnapping exploits Android APIs and a hardware side channel that affects nearly all modern Android devices. We have demonstrated Pixnapping attacks on Google and Samsung phones and end-to-end recovery of sensitive data from websites including Gmail and Google Accounts and apps including Signal, Google Authenticator, Venmo, and Google Maps. Notably, our attack against Google Authenticator allows any malicious app to steal 2FA codes in under 30 seconds while hiding the attack from the user.
Any running Android app can mount this attack, even if it does not have any Android permissions (i.e., no permissions are specified in its manifest file).
2