Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
UntitledFlow Security Launches Next-Gen Data Security Platform Following $10 Million Seed Round
First-of-its-kind solution discovers and protects both data at rest and in motion.
___________________________
@hacking_Attack
@Hacking_Video
UntitledFlow Security Launches Next-Gen Data Security Platform Following $10 Million Seed Round
First-of-its-kind solution discovers and protects both data at rest and in motion.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Flow Security Launches Next-Gen Data Security Platform Following $10 Million Seed Round
First-of-its-kind solution discovers and protects both data at rest and in motion.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Hackerrank Mutations problem solution in Python | python problem solution SoftwareTechIT
https://cdn-images-1.medium.com/max/600/0*t5dwAi0pjjZYW15b.png
Read More:-Mutations problem solution in Python
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Hackerrank Mutations problem solution in Python | python problem solution SoftwareTechIT
https://cdn-images-1.medium.com/max/600/0*t5dwAi0pjjZYW15b.png
Read More:-Mutations problem solution in Python
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hackerrank Mutations problem solution in Python | python problem solution SoftwareTechIT
Read More:-Mutations problem solution in Python
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Ransoms and Hackers!
In real world there are thieves and dacoits. In I.T there are black hat hackers. Black hat hackers search for weaknesses in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Ransoms and Hackers!
In real world there are thieves and dacoits. In I.T there are black hat hackers. Black hat hackers search for weaknesses in…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Ransoms and Hackers!
In real world there are thieves and dacoits. In I.T there are black hat hackers. Black hat hackers search for weaknesses in…
Hacking Articles Tips Tricks Videos Tutorials
1*Zojs82O4rGGEexSLiDhtmw.gif
Hacking on Medium
Why Crypto Projects Pay Hackers To Return Stolen Funds
https://cdn-images-1.medium.com/max/800/1*Zojs82O4rGGEexSLiDhtmw.gif
Did you know that $14 billion worth of blockchain transactions was tied to crypto crimes, hacks, and scams in 2021? This is the low end of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Why Crypto Projects Pay Hackers To Return Stolen Funds
https://cdn-images-1.medium.com/max/800/1*Zojs82O4rGGEexSLiDhtmw.gif
Did you know that $14 billion worth of blockchain transactions was tied to crypto crimes, hacks, and scams in 2021? This is the low end of…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Why Crypto Projects Pay Hackers To Return Stolen Funds
Did you know that $14 billion worth of blockchain transactions was tied to crypto crimes, hacks, and scams in 2021? This is the low end of…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Wszystko o atakach Denial Of Service znajdziesz tutaj, włącznie z narzędziami.
Ataki Denial Of Service polegają na zalaniu dużą ilością zapytań systemu, który haker chce odciąć od sieci, czyniąc daną usługę…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Wszystko o atakach Denial Of Service znajdziesz tutaj, włącznie z narzędziami.
Ataki Denial Of Service polegają na zalaniu dużą ilością zapytań systemu, który haker chce odciąć od sieci, czyniąc daną usługę…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Wszystko o atakach Denial Of Service znajdziesz tutaj, włącznie z narzędziami.
Ataki Denial Of Service polegają na zalaniu dużą ilością zapytań systemu, który haker chce odciąć od sieci, czyniąc daną usługę niedostępną…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Coding on Holiday — Hacking Huawei MiFi
https://cdn-images-1.medium.com/max/620/0*TGdyGlfCR5ngTHCG
Back in 2014 i bought a Huawei B593s-22 which would allow me to be able to work non office locations using WiFi.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Coding on Holiday — Hacking Huawei MiFi
https://cdn-images-1.medium.com/max/620/0*TGdyGlfCR5ngTHCG
Back in 2014 i bought a Huawei B593s-22 which would allow me to be able to work non office locations using WiFi.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Coding on Holiday — Hacking Huawei MiFi
Back in 2014 i bought a Huawei B593s-22 which would allow me to be able to work non office locations using WiFi.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
2,525 milliards de dollars piratés : Le marché des cryptomonnaies est-il devenu un guichet…
https://cdn-images-1.medium.com/max/1280/1*6zzNPq_PBC9eK8xXT7ZdJw.png
Alors que la capitalisation totale du marché des crypto-actifs ne cesse d’augmenter, les piratages sont de plus en plus fréquents. Selon…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
2,525 milliards de dollars piratés : Le marché des cryptomonnaies est-il devenu un guichet…
https://cdn-images-1.medium.com/max/1280/1*6zzNPq_PBC9eK8xXT7ZdJw.png
Alors que la capitalisation totale du marché des crypto-actifs ne cesse d’augmenter, les piratages sont de plus en plus fréquents. Selon…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
2,525 milliards de dollars piratés : Le marché des cryptomonnaies est-il devenu un guichet automatique pour les pirates informatiques…
Alors que la capitalisation totale du marché des crypto-actifs ne cesse d’augmenter, les piratages sont de plus en plus fréquents. Selon…
Packj - Large-Scale Security Analysis Platform To Detect Malicious/Risky Open-Source Packages
http://www.kitploit.com/2022/08/packj-large-scale-security-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/08/packj-large-scale-security-analysis.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Packj - Large-Scale Security Analysis Platform To Detect Malicious/Risky Open-Source Packages
Packj (pronounced package) is a command line (CLI) tool to vet open-source software packages for "risky" attributes that make them vulnerable to supply chain attacks. This is the tool behind our large-scale security analysis platform Packj.dev (https://packj.dev/) that continuously vets packages and provides free reports.
How to use Packj accepts two input args: name of the registry or package manager, pypi, npm, or rubygems. name of the package to be vetted Packj supports vetting of PyPI, NPM, and RubyGems packages. It performs static code analysis (https://www.kitploit.com/search/label/Static%20Code%20Analysis) and checks for several metadata attributes such as release timestamps, author email, downloads, dependencies. Packages with expired email domains, large release time gap, sensitive APIs, etc. are flagged as risky for security reasons (https://github.com/ossillate-inc/packj#risky-attributes). Packj also analyzes public repo code as well as metadata (e.g., stars, forks). By comparing the repo description and package title, you can be sure if the package indeed has been created from the repo to mitigate any starjacking attacks. Containerized The best way to use Packj is to run it inside Docker (or Podman) container. You can pull our latest image from DockerHub to get started. docker pull ossillate/packj:latest $ docker run --mount type=bind,source=/tmp,target=/tmp ossillate/packj:latest npm browserify
[+] Fetching 'browserify' from npm...OK [ver 17.0.0]
[+] Checking version...ALERT [598 days old]
[+] Checking release history...OK [484 version(s)]
[+] Checking release time gap...OK [68 days since last release]
[+] Checking author...OK [mail@substack.net]
[+] Checking email/domain validity...ALERT [expired author email domain]
[+] Checking readme...OK [26838 bytes]
[+] Checking homepage...OK [https://github.com/browserify/browserify#readme]
[+] Checking downloads...OK [2.2M weekly]
[+] Checking repo_url URL...OK [https://github.com/browserify/browserify]
[+] Checking repo data...OK [stars: 14077, forks: 1236]
[+] Checking repo activity...OK [commits: 2290, contributors: 207, tags: 413]
[+] Checking for CVEs...OK [none found]
[+] Checking dependencies...ALERT [48 found]
[+] Downloading package 'browserify' (ver 17. 0.0) from npm...OK [163.83 KB]
[+] Analyzing code...ALERT [needs 3 perms: process,file,codegen]
[+] Checking files/funcs...OK [429 files (383 .js), 744 funcs, LoC: 9.7K]
=============================================
[+] 5 risk(s) found, package is undesirable!
=> Complete report: /tmp/npm-browserify-17.0.0.json
{
"undesirable": [
"old package: 598 days old",
"invalid or no author email: expired author email domain",
"generates new code at runtime",
"reads files and dirs",
"forks or exits OS processes",
]
}
Specific package versions to be vetted could be specified using ==. Please refer to the example below $ docker run --mount type=bind,source=/tmp,target=/tmp ossillate/packj:latest pypi requests==2.18.4
[+] Fetching 'requests' from pypi...OK [ver 2.18.4]
[+] Checking version...ALERT [1750 days old]
[+] Checking release history...OK [142 version(s)]
[+] Checking release time gap...OK [14 days since last release]
[+] Checking author...OK [me@kennethreitz.org]
[+] Checking email/domain validity...OK [me@kennethreitz.org]
[+] Checking readme...OK [49006 bytes]
[+] Checking homepage...OK [http://python-requests.org]
[+] Checking downloads...OK [50M weekly]
[+] Checking repo_url URL...OK [https://github.com/psf/requests]
[+] Checking repo data...OK [stars: 47547, forks: 8758]
[+] Checking repo activity...OK [commits: 6112, contributors: 725, tags: 144]
[+] Checking for CVEs...ALERT [2 found]
[+] Checking dependencies...OK [9 direct]
[+] Downloading package 'requests' (ver 2.18.4) from pypi...OK [123.27 KB]
[+ ] Analyzing code...ALERT [needs 4 perms: codegen,process,file,network]
___________________________
@hacking_Attack
@Hacking_Video
How to use Packj accepts two input args: name of the registry or package manager, pypi, npm, or rubygems. name of the package to be vetted Packj supports vetting of PyPI, NPM, and RubyGems packages. It performs static code analysis (https://www.kitploit.com/search/label/Static%20Code%20Analysis) and checks for several metadata attributes such as release timestamps, author email, downloads, dependencies. Packages with expired email domains, large release time gap, sensitive APIs, etc. are flagged as risky for security reasons (https://github.com/ossillate-inc/packj#risky-attributes). Packj also analyzes public repo code as well as metadata (e.g., stars, forks). By comparing the repo description and package title, you can be sure if the package indeed has been created from the repo to mitigate any starjacking attacks. Containerized The best way to use Packj is to run it inside Docker (or Podman) container. You can pull our latest image from DockerHub to get started. docker pull ossillate/packj:latest $ docker run --mount type=bind,source=/tmp,target=/tmp ossillate/packj:latest npm browserify
[+] Fetching 'browserify' from npm...OK [ver 17.0.0]
[+] Checking version...ALERT [598 days old]
[+] Checking release history...OK [484 version(s)]
[+] Checking release time gap...OK [68 days since last release]
[+] Checking author...OK [mail@substack.net]
[+] Checking email/domain validity...ALERT [expired author email domain]
[+] Checking readme...OK [26838 bytes]
[+] Checking homepage...OK [https://github.com/browserify/browserify#readme]
[+] Checking downloads...OK [2.2M weekly]
[+] Checking repo_url URL...OK [https://github.com/browserify/browserify]
[+] Checking repo data...OK [stars: 14077, forks: 1236]
[+] Checking repo activity...OK [commits: 2290, contributors: 207, tags: 413]
[+] Checking for CVEs...OK [none found]
[+] Checking dependencies...ALERT [48 found]
[+] Downloading package 'browserify' (ver 17. 0.0) from npm...OK [163.83 KB]
[+] Analyzing code...ALERT [needs 3 perms: process,file,codegen]
[+] Checking files/funcs...OK [429 files (383 .js), 744 funcs, LoC: 9.7K]
=============================================
[+] 5 risk(s) found, package is undesirable!
=> Complete report: /tmp/npm-browserify-17.0.0.json
{
"undesirable": [
"old package: 598 days old",
"invalid or no author email: expired author email domain",
"generates new code at runtime",
"reads files and dirs",
"forks or exits OS processes",
]
}
Specific package versions to be vetted could be specified using ==. Please refer to the example below $ docker run --mount type=bind,source=/tmp,target=/tmp ossillate/packj:latest pypi requests==2.18.4
[+] Fetching 'requests' from pypi...OK [ver 2.18.4]
[+] Checking version...ALERT [1750 days old]
[+] Checking release history...OK [142 version(s)]
[+] Checking release time gap...OK [14 days since last release]
[+] Checking author...OK [me@kennethreitz.org]
[+] Checking email/domain validity...OK [me@kennethreitz.org]
[+] Checking readme...OK [49006 bytes]
[+] Checking homepage...OK [http://python-requests.org]
[+] Checking downloads...OK [50M weekly]
[+] Checking repo_url URL...OK [https://github.com/psf/requests]
[+] Checking repo data...OK [stars: 47547, forks: 8758]
[+] Checking repo activity...OK [commits: 6112, contributors: 725, tags: 144]
[+] Checking for CVEs...ALERT [2 found]
[+] Checking dependencies...OK [9 direct]
[+] Downloading package 'requests' (ver 2.18.4) from pypi...OK [123.27 KB]
[+ ] Analyzing code...ALERT [needs 4 perms: codegen,process,file,network]
___________________________
@hacking_Attack
@Hacking_Video
{
"undesirable": [
"generates new code at runtime",
"reads files and dirs: ['package/lib/cli-engine/load-rules.js:37', 'package/lib/cli-engine/file-enumerator.js:142']"
]
}
=> Complete report: /tmp/npm-eslint-8.16.0.json
How it works It first downloads the metadata from the registry using their APIs and analyze it for "risky" attributes. To perform API analysis, the package is downloaded from the registry using their APIs into a temp dir. Then, packj performs static code analysis (https://www.kitploit.com/search/label/Code%20Analysis) to detect API usage. API analysis is based on MalOSS (https://github.com/osssanitizer/maloss), a research project (https://www.kitploit.com/search/label/Research%20Project) from our group at Georgia Tech. Vulnerabilities (CVEs) are checked by pulling info from OSV database at OSV (https://osv.dev/) Python PyPI and NPM package downloads are fetched from pypistats (https://pypistats.org/) and npmjs (https://api.npmjs.org/downloads) All risks detected are aggregated and reported Risky attributes The design of Packj is guided by our study of 651 malware samples (https://www.kitploit.com/search/label/Malware%20Samples) of documented open-source software supply chain attacks. Specifically, we have empirically identified a number of risky code and metadata attributes that make a package vulnerable to supply chain attacks. For instance, we flag inactive or unmaintained packages that no longer receive security fixes. Inspired by Android app runtime permissions, Packj uses a permission-based security model to offer control and code transparency to developers. Packages that invoke sensitive operating system functionality such as file accesses and remote network communication are flagged as risky as this functionality could leak sensitive data. Some of the attributes we vet for, include Attribute Type Description Reason Release date Metadata Version release date to flag old or abandonded packages Old or unmaintained packages do not receive security fixes OS or lang APIs Code Use of sensitive APIs, such as exec and eval Malware uses APIs from the operating system or language runtime to perform sensitive operations (e.g., read SSH keys) Contributors' email Metadata Email addresses of the contributors Incorrect or invalid of email addresses suggest lack of 2FA Source repo Metadata Presence and validity of public source repo Absence of a public repo means no easy way to audit or review the source code publicly Full list of the attributes we track can be viewed at threats.csv (https://github.com/ossillate-inc/packj/blob/main/threats.csv) These attributes have been identified as risky by several other researchers [1 (https://arxiv.org/pdf/2112.10165.pdf), 2 (https://www.usenix.org/system/files/sec19-zimmermann.pdf), 3 (https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-1_23055_paper.pdf)] as well. How to customize Packj has been developed with a goal to assist developers in identifying and reviewing potential supply chain risks in packages. However, since the degree of perceived security risk from an untrusted package depends on the specific security requirements, Packj can be customized according to your threat model. For instance, a package with no 2FA may be perceived to pose greater security risks to some developers, compared to others who may be more willing to use such packages for the functionality offered. Given the volatile nature of the problem, providing customized and granular risk measurement is one of our goals. Packj can be customized to minimize noise and reduce alert fatigue by simply commenting out unwanted attributes in threats.csv (https://github.com/ossillate-inc/packj/blob/main/threats.csv) Malware found We found over 40 malicious packages on PyPI using this tool. A number of them been taken down. Refer to an example below: $ python3 main.py pypi krisqian
___________________________
@hacking_Attack
@Hacking_Video
"undesirable": [
"generates new code at runtime",
"reads files and dirs: ['package/lib/cli-engine/load-rules.js:37', 'package/lib/cli-engine/file-enumerator.js:142']"
]
}
=> Complete report: /tmp/npm-eslint-8.16.0.json
How it works It first downloads the metadata from the registry using their APIs and analyze it for "risky" attributes. To perform API analysis, the package is downloaded from the registry using their APIs into a temp dir. Then, packj performs static code analysis (https://www.kitploit.com/search/label/Code%20Analysis) to detect API usage. API analysis is based on MalOSS (https://github.com/osssanitizer/maloss), a research project (https://www.kitploit.com/search/label/Research%20Project) from our group at Georgia Tech. Vulnerabilities (CVEs) are checked by pulling info from OSV database at OSV (https://osv.dev/) Python PyPI and NPM package downloads are fetched from pypistats (https://pypistats.org/) and npmjs (https://api.npmjs.org/downloads) All risks detected are aggregated and reported Risky attributes The design of Packj is guided by our study of 651 malware samples (https://www.kitploit.com/search/label/Malware%20Samples) of documented open-source software supply chain attacks. Specifically, we have empirically identified a number of risky code and metadata attributes that make a package vulnerable to supply chain attacks. For instance, we flag inactive or unmaintained packages that no longer receive security fixes. Inspired by Android app runtime permissions, Packj uses a permission-based security model to offer control and code transparency to developers. Packages that invoke sensitive operating system functionality such as file accesses and remote network communication are flagged as risky as this functionality could leak sensitive data. Some of the attributes we vet for, include Attribute Type Description Reason Release date Metadata Version release date to flag old or abandonded packages Old or unmaintained packages do not receive security fixes OS or lang APIs Code Use of sensitive APIs, such as exec and eval Malware uses APIs from the operating system or language runtime to perform sensitive operations (e.g., read SSH keys) Contributors' email Metadata Email addresses of the contributors Incorrect or invalid of email addresses suggest lack of 2FA Source repo Metadata Presence and validity of public source repo Absence of a public repo means no easy way to audit or review the source code publicly Full list of the attributes we track can be viewed at threats.csv (https://github.com/ossillate-inc/packj/blob/main/threats.csv) These attributes have been identified as risky by several other researchers [1 (https://arxiv.org/pdf/2112.10165.pdf), 2 (https://www.usenix.org/system/files/sec19-zimmermann.pdf), 3 (https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-1_23055_paper.pdf)] as well. How to customize Packj has been developed with a goal to assist developers in identifying and reviewing potential supply chain risks in packages. However, since the degree of perceived security risk from an untrusted package depends on the specific security requirements, Packj can be customized according to your threat model. For instance, a package with no 2FA may be perceived to pose greater security risks to some developers, compared to others who may be more willing to use such packages for the functionality offered. Given the volatile nature of the problem, providing customized and granular risk measurement is one of our goals. Packj can be customized to minimize noise and reduce alert fatigue by simply commenting out unwanted attributes in threats.csv (https://github.com/ossillate-inc/packj/blob/main/threats.csv) Malware found We found over 40 malicious packages on PyPI using this tool. A number of them been taken down. Refer to an example below: $ python3 main.py pypi krisqian
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
[+] Fetching 'krisqian' from pypi...OK [ver 0.0.7]
[+] Checking version...OK [256 days old]
[+] Checking release history...OK [7 version(s)]
[+] Checking release time gap...OK [1 days since last release]
[+] Checking author...OK [KrisWuQian@baidu.com]
[+] Checking email/domain validity...OK [KrisWuQian@baidu.com]
[+] Checking readme...ALERT [no readme]
[+] Checking homepage...OK [https://www.bilibili.com/bangumi/media/md140632]
[+] Checking downloads...OK [13 weekly]
[+] Checking repo_url URL...OK [None]
[+] Checking for CVEs...OK [none found]
[+] Checking dependencies...OK [none found]
[+] Downloading package 'KrisQian' (ver 0.0.7) from pypi...OK [1.94 KB]
[+] Analyzing code...ALERT [needs 3 perms: process,network,file]
[+] Checking files/funcs...OK [9 files (2 .py), 6 funcs, LoC: 184]
=============================================
[+] 6 risk(s) found, package is undes irable!
{
"undesirable": [
"no readme",
"only 45 weekly downloads",
"no source repo found",
"generates new code at runtime",
"fetches data over the network: ['KrisQian-0.0.7/setup.py:40', 'KrisQian-0.0.7/setup.py:50']",
"reads files and dirs: ['KrisQian-0.0.7/setup.py:59', 'KrisQian-0.0.7/setup.py:70']"
]
}
=> Complete report: pypi-KrisQian-0.0.7.json
=> View pre-vetted package report at https://packj.dev/package/PyPi/KrisQian/0.0.7
Packj flagged KrisQian (v0.0.7) as suspicious due to absence of source repo and use of sensitive APIs (network, code generation) during package installation time (in setup.py). We decided to take a deeper look, and found the package malicious. Please find our detailed analysis at https://packj.dev/malware/krisqian. More examples of malware we found are listed at https://packj.dev/malware Please reach out to us at oss@ossillate.com (mailto:oss@ossillate.com) for full list. Resources To learn more about Packj tool or open-source software supply chain attacks, refer to our 🚀 behind our large-scale security analysis platform to detect malicious/risky open-source packages (34)">
___________________________
@hacking_Attack
@Hacking_Video
[+] Checking version...OK [256 days old]
[+] Checking release history...OK [7 version(s)]
[+] Checking release time gap...OK [1 days since last release]
[+] Checking author...OK [KrisWuQian@baidu.com]
[+] Checking email/domain validity...OK [KrisWuQian@baidu.com]
[+] Checking readme...ALERT [no readme]
[+] Checking homepage...OK [https://www.bilibili.com/bangumi/media/md140632]
[+] Checking downloads...OK [13 weekly]
[+] Checking repo_url URL...OK [None]
[+] Checking for CVEs...OK [none found]
[+] Checking dependencies...OK [none found]
[+] Downloading package 'KrisQian' (ver 0.0.7) from pypi...OK [1.94 KB]
[+] Analyzing code...ALERT [needs 3 perms: process,network,file]
[+] Checking files/funcs...OK [9 files (2 .py), 6 funcs, LoC: 184]
=============================================
[+] 6 risk(s) found, package is undes irable!
{
"undesirable": [
"no readme",
"only 45 weekly downloads",
"no source repo found",
"generates new code at runtime",
"fetches data over the network: ['KrisQian-0.0.7/setup.py:40', 'KrisQian-0.0.7/setup.py:50']",
"reads files and dirs: ['KrisQian-0.0.7/setup.py:59', 'KrisQian-0.0.7/setup.py:70']"
]
}
=> Complete report: pypi-KrisQian-0.0.7.json
=> View pre-vetted package report at https://packj.dev/package/PyPi/KrisQian/0.0.7
Packj flagged KrisQian (v0.0.7) as suspicious due to absence of source repo and use of sensitive APIs (network, code generation) during package installation time (in setup.py). We decided to take a deeper look, and found the package malicious. Please find our detailed analysis at https://packj.dev/malware/krisqian. More examples of malware we found are listed at https://packj.dev/malware Please reach out to us at oss@ossillate.com (mailto:oss@ossillate.com) for full list. Resources To learn more about Packj tool or open-source software supply chain attacks, refer to our 🚀 behind our large-scale security analysis platform to detect malicious/risky open-source packages (34)">
___________________________
@hacking_Attack
@Hacking_Video
Bilibili
天线宝宝
《天线宝宝》有两个元素:一个是“幻想园地”、一个是“真实纪录”。“幻想园地”是指《天线宝宝》的主要场景“神奇岛”(香港译名为天线得得园),岛上有许多幻想奇观,让孩子有创造力、想像力;四个天线宝宝在神奇