Finding bad software extensions at @SocketSecurity (acquired @secureannex) #️⃣ githash.org

Kansas City, MO
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately. We don't know what's exactly going on yet. Stay tuned for more info.
61
529
3,165
374,213
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
3
7
1,840
HILARIOUS solidity malware directly copied the warning from the real solidity extension
1
9
494
Had a blast with @fleetctl at Atlas 9 KC for their JNUC afterparty yesterday! I hear it's a lot like Meow Wolf.
1
1
5
274
Absolutely crazy that these two GitHub Actions which were quarantined could be reactivated with the malware still armed. Many of the these workflows run on a cron without any true repository activity trigging them.
🚨 Two GitHub Actions compromised in May’s Mini Shai-Hulud campaign are running malware again. The repositories were re-enabled with malicious release tags intact, putting thousands of downstream repositories at risk. socket.dev/blog/mini-shai-hu…
5
15
6,938
Ouch. A hijacked past commit to remove PolinRider... adds PolinRider
1
4
11
995
Pretty wild how this extension will piece together it's code from a C2 server.
Socket researchers found a malicious Firefox extension that poses as a PDF identity verifier to hijack Google accounts. It fetches its payload after installation, steals Google session cookies, and can silently reset the victim’s password. socket.dev/blog/firefox-goog…
1
4
32
6,979
tuckner retweeted
“We want evaluators more independent than METR!” *monkey’s paw curls*
We’re partnering with Accenture on independent evaluation of frontier AI—part of our recent commitment to embed evaluators at Anthropic. Both we and Accenture expect to invest at least $1 billion to build capacity in this area over the next five years. anthropic.com/news/accenture…
Community note
Anthropic presents this as an "independent evaluation" but will directly fund Accenture's work and has a prior commercial partnership with the firm for deploying its models, including training ~30,000 Accenture professionals on Claude. anthropic.com/news/accenture… anthropic.com/news/anthropic…
18
29
971
48,725
Okay we’re all going to die
6
471
so remember when certain DPRK groups stored their C2 infra details (often base64-encoded & XOR-encrypted) in smart contracts? it was called EtherHiding. well, our PolinRider "friends" (and other groups) have gotten a bit more "creative". they now use a new pattern called "NullReceiver": simply put, they send a zero-value tx with zero calldata, while hiding the C2 IP address directly in the `to` address lol. let's take real-world example: - tx hash: `0x910d35c6620bea357c867bd93b291dc6feb1990bb57a0a063fa652cd29d096b2` - `to` address: `0xa658863ea658863e68656c6c6f6970626f742121` this will lead to - a658863e -> 166[.]88[.]134[.]62 - a658863e -> repetition of the above IP - the rest (68656c6c6f6970626f742121) is some string "helloipbot!!"
21
39
351
23,888
Are you extensions taking control of embedded browser AI? Great research!
Excited to finally share my recent research, where I managed to hack Chrome, Comet, Edge, Opera and Claude in Chrome using one single browser extension 2 CVEs & $20,000 in bounties 🙂 Introducing - BragJack! forever.security/blog/bragja…
1
3
4
727
KREMLIN is a multi-stage credential theft toolkit targeting Brazilian banking users. New research from Elastic Security Labs (REF9334): go.es.io/4yfkg4R by @cyril_t_f and @andythevariable The infection chain combines JavaScript loaders, an optional PE injector, and a custom C++ installer. The installer downloads and installs a malicious browser extension for Chrome and Edge and/or deploys an embedded PULSAR or REMCOS RAT. This malicious extension is then used for web-browser data interception and exfiltration. KREMLIN resolves its C2 endpoints from Ethereum. Smart contracts store payload URLs and extension download locations as on-chain key-value pairs. The operators update endpoints by writing a new transaction. The extension installation bypasses Chromium's integrity system. The installer launches Chrome under a debugger, recovers the App-Bound OSCrypt key from process memory, extracts the seed from resources.pak, then regenerates the HMACs and encrypted SHA-256 hashes that Secure Preferences requires. The extension registers silently with developer mode forced on. Once active, it logs input fields, intercepts HTTP requests by configurable URL and method rules, injects attacker-controlled HTML, and exfiltrates intercepted data, cookies, and credentials over WebSocket and HTTP. Elastic Security Labs Threat Command registered the network canary domain that operates as a kill switch. We observed thousands of implants from Brazil attempting to check in to this domain. Once this domain was live, the KREMLIN loaders crash before trying to update or install the final payload, temporarily disrupting this campaign. The targeting is clear. Lure filenames impersonate PIX transfers, bank statements, and receipts from Banco do Brasil, Bradesco, Sicoob, Santander, C6 Bank, and PagBank. Ethereum transaction timestamps cluster in São Paulo working hours. Portuguese-language artifacts appear throughout the codebase.
1
27
95
6,362
Glad I started Careless People last week. It is a fantastic view into high growth startups, the tradeoffs in doing business and how people truly shape what a company is. Very timely with current AI discourse too. I have to imagine there will be OpenAI and Anthropic versions in the years to come.
1
7
527
tuckner retweeted
MacOS #clickfix campaign called #PasteSwitch - this was a fun one, lots of detail and IoCs in this one - very illusive group who has a big focus on Malvertising. The group got access to legit HBO Max account on reddit 👀 adamnet.works/blog/hbo-max-a…
Going to be dropping a detailed #clickfix MacOS campaign post tomorrow morning that is quite unknown but large - very illusive. Several outlets have small fragments of the campaign but going to tie it together under #PasteSwitch. oh btw, Mac malware - so hot right now.
1
8
18
4,290
Was told my products UI is terrible (it's true), but the API/MCP always work. They said it was a better experience than a beautiful product which had sparse and barely functioning APIs. A beautiful product does sell, but outcomes do matter.
2
1
15
1,956
tuckner retweeted
Browser extensions are still the wild west. You really need to know what they’re actually doing once you install them. This Twitch extension does what it says in the description, plus just a little bit extra... 🫠 Still live in the Chrome and Firefox stores, by the way.
Socket researchers found a malicious Twitch browser extension on Chrome and Firefox with 30,000+ reported users. It forwards full account-scoped OAuth tokens to a Russian bot service, exposing chat, whispers, and account settings. socket.dev/blog/malicious-tw…
1
3
637
tuckner retweeted
10
37
496
9,090
No revenue 10B valuation I guess Facebook did it
Instinct looking to raise $1B, potentially at a $10B valuation. Compute costs are high and Noah doesn’t want to charge users for the product. Instinct has raised $350M to date, mostly uses open source models and wants to own chips and data centers theinformation.com/articles/…
2
498
WTAF we've totally lost the plot if Norton is now collecting clickstream data in exchange for 5% off your infrared facemask
13
618