International Cyber Digest
6.84K subscribers
1.21K photos
61 videos
2 files
222 links
Independent reporting on cybersecurity, tech, AI & digital policy. Got a tip? http://internationalcyberdigest.com/tips
Download Telegram
πŸš¨β€ΌοΈ MAJOR SUPPLY CHAIN ATTACK: npm package axios is compromised after the maintainer's npm account was hijacked.

Malicious versions contain a Remote Access Trojan. axios has 100M+ weekly downloads β€” it's in practically everything.

If you have installed axios@1.14.1 or axios@0.30.4, assume compromise.

Axios' lead maintainer jasonsaayman's npm account was compromised β€” email was swapped to an anonymous Proton Mail address.

Both malicious versions were pushed manually via npm CLI, bypassing GitHub Actions OIDC entirely, without commits.

πŸ”΄ Stepsecurity report: https://stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan

πŸ”΄ Socket report:
https://socket.dev/blog/axios-npm-package-compromised
❀9πŸ₯΄2
πŸš¨β€ΌοΈ BREAKING: Claude Code's source code has been leaked via a map file exposed in Anthropic's npm registry.

The leaked code appears to reveal new and previously undisclosed features.

Source code backups:

1)
https://github.com/chatgptprojects/claude-code

2)
https://pub-aea8527898604c1bbb12468b1581d95e.r2.dev/src.zip
πŸ‘13😱7❀5😁3
Claude Code uses axios btw πŸ₯΄
😭21😁5πŸ₯΄3
Forget the Strait of Hormuz. The world economy now relies on the compromised lead axios maintainer finding a GitHub contact on X...
😁15😭7πŸ”₯2
Ain’t no npm package crisis complete without this meme πŸ˜‚
Please open Telegram to view this post
VIEW IN TELEGRAM
🀣30😁4
‼️ Meet the guy almost everyone loves for alerting the axios devs about the supply chain attack.

He built a supply chain monitoring system last week, and was alerted within minutes of the axios compromise.

The world should be thanking Elastic Security's finest:
Joe
X:dez_
🀣14❀4πŸ™3
This media is not supported in your browser
VIEW IN TELEGRAM
Joe is our saviour. Respect Joe.
🀣13πŸ₯°9πŸ’©1
‼️ Tomorrow we're dropping a TeamPCP supply chain attack victim list, including verification status and more.

Got tips? DM us or use our Signal (see bio).

❀️ rodents.
❀15
πŸš¨β€ΌοΈ BREAKING: Anthropic has decided to open source their entire codebase and is rebranding their AI to OpenClaude.

Anthropic CEO Dario Amodei said: "Yesterday was no slip-up. If we disappear just like OpenAI is vanishing right now, our code can live on through the community."
🀣71❀14πŸ”₯7πŸŽ‰4πŸ₯°2πŸ₯΄1
😭25πŸ€ͺ6πŸ”₯3😁2
We're so cooked! 😱
🀣40😱6😁3
‼️ TeamPCP and ShinyHunters are threatening each other right now. A ShinyHunters spokesperson told us:

"TeamPCP/SkidPCP can do nothing. A better name for them is 'VibePCP' because all they can do is use AI.

It's good we robbed them because we made better use of the credentials than they ever could.

We bet they wouldn't even know what IAM is on AWS.

Maybe they should've asked AI to help secure their storage server so it wouldn't get hacked and backdoored by us."

ShinyHunters declined to comment further, instead they will leak all the data on them (first names: R. is PCP, A. is Vect), along with all their chat logs.
🀣15❀3