Security Researcher @AikidoSecurity. Previously @SecCodeWarrior, co-founder at Adversaryio & Principal Security Engineer/Partner @thesyndis. Opinions all my own

Joined December 2008
145 Photos and videos
Charlie Eriksen retweeted
Looks like GitHub has a PR in the works to block checkout of fork-origin code in actions/checkout by default (it will require explicit opt-in by setting an unsafe flag) for workflow_run and pull_request_target About time! github.com/actions/checkout/…
1
1
6
259
It turns out that AMD never actually fixed a vulnerability I reported back in 2012. Are you KIDDING ME?! charlieeriksen.github.io/201…

AMD retcons bug bounty rules after researcher finds exploit: youtube.com/watch?v=4HjWHNLR…
1
13
1,250
Charlie Eriksen retweeted
Aikido 🤝 @Docker Aikido now supports Docker Hardened Images with built-in VEX integration. Scan Docker Hardened Images in Aikido and filter out CVEs Docker has already verified as fixed, not affected, or not exploitable. No additional setup. Less noise, more signal in your containers.
2
3
26
1,999
We're seeing signs that Windows Defender pushed a signature update this morning, which is flagging the npm package `prisma` 7.8.0 and 7.7.0 (at least). We've analyzed both and don't see any signs of malware. Prisma has 12.5m weekly downloads, so this will create some noise.
2
11
48
3,843
It's also flagging 7.6.0, 7.5.0, 7.4.x, and older versions as Shai Hulud. 😅
1
3
434
Charlie Eriksen retweeted
We detected a supply-chain compromise in onering 1.4.1, a Rust crate on crates.io with 18,000 downloads. The latest version uses a malicious build.rs script to quietly exfiltrate git data and source code from your latest commit on every build, disguised as Sentry traffic. The GitHub repository is also compromised, so pulling directly from git is not a safe workaround.
4
22
92
37,942
Charlie Eriksen retweeted
We find high/crits everytime we scan OSS, web applications are "easy" targets for LLMs by now. This one is a simple account takeover leading to unauth RCE on latest version. Went 10 years unnoticed. Public prices for 0day brokers: $50k, costed us $800 aikido.dev/blog/phpbb-authen…
2
11
69
3,633
We have detected that the popular package `onering` on crates.io has been compromised with an information stealer that runs on build, which sends a git diff to a Sentry endpoint without authorization: github.com/cenotelie/onering… This is quite novel.

1
16
35
2,929
Charlie Eriksen retweeted
I wrote this to be like, "hey, be careful with prescription medication hehe it sucks", and sharing some personal stuff and letting my stinky nerds know I'm about to go through some shit I did NOT imagine so many people coming forward publicly, and in private, sharing their stories about addiction to prescription medication God damn. Chat, I don't want to sound cliche, but I do unironically think we might have a drug problem. I don't know if it's the doctors, or the drug companies, or what, but holy cannoli bro a LOT of people have gotten hooked on drugs given to them by their doctor
I don't expect any of you to give a shit, but I would like to share something with all of you. This is kind of a cautionary tale for younger person in my audience. For the love of God: DO NOT FUCK AROUND WITH BENZODIAZEPINE. Like it was a plague, don't do Xanax, or Klonopin, or Valium, unless it is under strict medical supervision and you're well educated on the drug. When I was 18 I had severe anxiety. My anxiety was so extreme I was afraid to shower, put gas in my car, etc. Once I was so afraid to shower I didn't bathe for 8 months. My anxiety was debilitating. I was eventually given a narcotic called Klonopin. The doctor didn't warn me about the drug. Klonopin is an extremely effective anti-anxiety medication. It was like a breathe of fresh air. I was able to function. It saved my life. However, what the doctor DID NOT tell me is that Klonopin is like rat poison and is INCREDIBLY DANGEROUS. I cannot stress this enough: INCREDIBLY DANGEROUS. The long term effects of Benzodiazepine is catastrophic. General speaking, physicians only want you taking drugs like Klonopin for 90 days MAXIMUM. I've been taking it for over 15 years. My brain and body are both heavily dependent on the drug. If I don't have my Klonopin I physically cannot function. My arms shake, I get headaches, I get confused, I get overwhelming anxiety, I get physically sick, it is absolutely awful. It feels very similar to having the Influenza virus mixed with extreme sleep depravation mixed with being hung over. Additionally, whenever I told other physicians I take Klonopin I am treated like a drug addict and they scoff at me. Several times in the past, when in an Emergency Room or whatever, and I mention I take Klonopin, I've had doctors directly tell me, "Well, I'm not going to give you any Xanax", or "Why are you really here?". It's terrible and embarrassing. Anyway, to make a long story short I've decided to begin the journey of quiting the drug. I can't quit cold turkey, because it can kill you .. because it can cause death by stroke, heart attack, seizure, ... whatever. Instead I am working with my physician to slowly taper off the drug. I'm day five into a 25% reduction, which in some cases is fast, but I agreed to try it. I've had mild insomnia and mild irritability. Besides this though I'm doing pretty good. Once I've kept at this 25% reduction for about 8 weeks I will try to reduce by another 25%. Seriously though, don't fuck around Benzos like Xanax, Klonopin, Valium, etc. This shit will fuck you up bro
89
51
1,169
57,383
Once v12 is out, getting everybody to upgrade will be the big challenge. I hope all security vendors will help alert people that it's really important to update to v12.
It's finally happening. We can put this whole install script NPM worm madness behind us... github.blog/changelog/2026-0…
1
1
7
1,489
NPM just applied a security tag to many 1-character-name packages. But unlike normally, when they take down malicious packages, they haven't removed the old versions. And many of these packages were quite popular, and there's no indication they were malicious at a glance. Example: npmjs.com/package/i

1
4
13
1,336
Charlie Eriksen retweeted
A clean package.json is no longer evidence that nothing runs. The mere presence of binding.gyp is enough for code to run at install time. No scripts block needed. Payloads can hide under any field name, at any depth. The sandbox around it can be escaped. And node-gyp pulls in files automatically that nothing even points to. The latest Miasma variant used binding.gyp. We dug deeper and found it goes much further.
1
18
56
4,329
Another sad example of @github having been warned about big security risks, and blatantly ignoring it. It is incredibly disappointing.
Sad thing is GitHub has known about this since at least August. Reported multiple times by different researchers. When bugs don't get fixed eventually black-hats find them and abuse them.
1
1
11
1,775
Charlie Eriksen retweeted
Replying to @KirkDerpca
Oh boy. they dropped an 0day in this too.
3
6
36
15,014
My GitHub issue was deleted, presumably by the attacker. 😅
The popular gpt-pilot project on GitHub has been compromised with malware: github.com/Pythagora-io/gpt-…
3
3
36
5,926
Charlie Eriksen retweeted
So - looking at this malware the secret dumper contains a GitHub 0day. (Well 0day as in a long-standing bypass GitHub has known about). I’m guessing they found it.
1
1
14
1,434
We're seeing the package `executable-stories-cypress` on npm being compromised with Miasma. Versions 8.3.2, 7.0.3, 6.1.1, 5.0.1, 4.0.1, 3.1.1. npmjs.com/package/executable…

1
3
8
1,968