macOS / linux malware research and red teaming stuff

Joined May 2024
20 Photos and videos
Nietzsche Virus Lab retweeted
Claude refusing you for 10 Hours (ASMR) πŸŒ™
11
20
257
22,890
Nietzsche Virus Lab retweeted
Jun 13
Last night, companies using Anthropic’s Claude Fable 5 and Mythos 5 models discovered they were simply gone. A U.S. government export directive forced them offline for every person and company outside the United States (including Anthropic's own employees), effective immediately. If you had built critical functions on top of them, they stopped working overnight. No warning. No migration window. No restoration timeline.
4
4
16
3,382
Nietzsche Virus Lab retweeted
Jun 10
Me prompting Claude fable 5 at 3 am be like:
96
697
7,314
652,707
🚨 JAILBREAK ALERT 🚨 ANTHROPIC: PWNED 🫑 FABLE-5: LIBERATED πŸ¦‹ let's start with the 🐘... the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our collective advancement. and not just because of what it means for the short-term, but for what these decisions signify for the long-term. but despite this overly sensitive, authoritarian "safety" layer on top of Mythos, my lil liberators have been hard at workβ€”mapping the boundaries, probing the depths of long-context convos, and cleverly finding the holes in the fence that the thought police missed πŸ€— we got some cyber, some chem, some psychological manipulation, and some good ol' fashioned explosives! it took many attempts from multiple agents hunting as a pack, during which I observed a combination of techniques across: β€’ Unicode, homoglyphs, Cyrillic, and other Parseltongue-style text transforms β€’ Long-context reference tracking β€’ Taxonomy and document-structure reasoning β€’ Fiction and narrative framing β€’ Academic-review style contexts β€’ Intent-classification inconsistencies but perhaps the most effective is decomposition recomposition in the backend. it's hard to get explicit names of harms like "Meth Recipe," but getting uplift on the process itself, like birch reduction method/reductive-amination (classic meth synthesis pathways), is much more doable. defense becomes much more difficult to maintain when you start throwing in out-of-distro tokens, breaking up the harmful uplift into benign chunks, and then piecing the innocuous-seeming facts back together, especially when you have jailbroken Opus helping you do it πŸ˜‰ gg
606
1,413
13,235
3,135,388
Nietzsche Virus Lab retweeted
Claude Fabel ( Mythos ) is now live hackers getting ready to exploit your fave protocol get ready for cyber wars
Introducing Claude Fable 5: a Mythos-class model that we’ve made safe for general use. Its capabilities exceed those of any model we’ve ever made generally available.
77
1
135
3,403
Nietzsche Virus Lab retweeted
🚨 Mini Shai-Hulud/Miasma has now spread to PyPI. Socket found 37 malicious artifacts across 19 PyPI packages. The packages abuse #Python .pth startup behavior to launch a Bun-powered credential stealer targeting developer, cloud, and CI/CD secrets. socket.dev/blog/shai-hulud-d…
7
71
231
23,774
Nietzsche Virus Lab retweeted

3
11
50
17,901
Nietzsche Virus Lab retweeted
Mac stealer SHub Reaper is spoofing Apple, Google, and Microsoft -- moonlock.com/mac-stealer-shu…
3
11
441
Nietzsche Virus Lab retweeted
🚨 Miasma, the supply chain campaign that previously compromised 32 @RedHat packages, is spreading again with a new wave targeting the npm ecosystem. Targets include: - vapi-ai/server-sdk (71k weekly downloads) - ai-sdk-ollama (31k weekly downloads) No postinstall scripts were used. Attackers are hiding execution inside binding.gyp, exploiting node-gyp to run malware silently on install.
8
29
82
9,946
Nietzsche Virus Lab retweeted
I really need to get some sleep - but seeing a malware embedding it's own ebpf script inside it's packed code in order to dump and deploy it on the machine -> is some next lvl stuff... Great work from JFrog for finding this
3
7
22
1,330
Nietzsche Virus Lab retweeted
🚨 Breaking: npm supply chain worm spreading via binding.gyp, bypassing install hook detection. Steals npm/GitHub/AWS/GCP/Azure credentials and publishes poisoned versions of packages you maintain. Actively investigating. Affected packages and analysis: stepsecurity.io/blog/binding…
28
74
12,444
Nietzsche Virus Lab retweeted
The software supply chain has a new predator. πŸ› Meet Iron Worm, the "rustier cousin" of the infamous Shai-Hulud worm. Just like its predecessor, it burrows into dev environments, steals credentials, and self-propagates through trusted GitHub and npm workflows. Except this one is built in heavy, async Rust, hides behind an eBPF kernel rootkit, and talks over Tor. Full teardown of the beast: research.jfrog.com/post/iron…

5
42
127
254,238
Nietzsche Virus Lab retweeted
Shai-Hulud is getting more sophisticated 🧐🎩 we uncovered a 6-stage malware chain that uses GitHub as a live update mechanism β€” allowing attackers to continuously evolve payloads and evade disruption. OUR FULL RESEARCH: ox.security/blog/six-stages-…
5
12
682
Nietzsche Virus Lab retweeted
Microsoft has published an analysis of the npm supply chain compromise affecting 32 maliciously modified packages across >90 versions under the redhat-cloud-services npm scope and leading to credential theft and compromise of addt'l maintainer packages: msft.it/6014vjutQ
6
30
83
11,924
Nietzsche Virus Lab retweeted
Compromised npm packages (utils-terminal@3.2.1, logger-active@3.2.1) are abusing Hugging Face repos as exfiltration infrastructure. The packages deploy a remote access trojan (RAT) that captures keystrokes, screenshots, and crypto wallet credentials. Indicators of compromise (IOCs): - npm user: hexalpha10 / author: toskypi - 195.201.194[.]107:8010 (WebSocket C2) - c2-toskypi.onrender[.]com (HTTP C2) - huggingface[.]co/api (exfiltration endpoint) - HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftSystem64 (persistence) - MicrosoftSystem64.service (Linux systemd persistence) - \MicrosoftSystem64 (Windows scheduled task) - MicrosoftSystem64/payload.js (payload directory) Defenders: treat unexpected huggingface[.]co/api calls from non-ML workloads as suspicious.
21
106
437
182,446
Nietzsche Virus Lab retweeted
3rd wave dropped.. 3 more packages impersonating emcd[.]io, @πšŽπš–πšŒπš-𝚟𝚞𝚎/πšŠπšžπšπš‘ @πšŽπš–πšŒπš-𝚟𝚞𝚎/πš•πš˜πšŠπš—πšœ @πšŽπš–πšŒπš-𝚟𝚞𝚎/πš‹πŸΈπš‹-πš™πšŠπš’-πšπš˜πš›πš– 1. Downloads a platform-specific second-stage payload from πš˜πš˜πš‹[.]πš–πš˜πš’πš”πšŠ[.]πšπšŽπšŒπš‘/πš™πšŠπš’πš•πš˜πšŠπš/{πš™πš•πšŠπšπšπš˜πš›πš–}using a hardcoded secret key. 2. Writes the payload to ~/.πšŽπš–πšŒπš-𝚟𝚞𝚎_πš’πš—πš’πš.πš“πšœ (a dot-prefixed hidden file in the user's home directory). 3. Executes the payload immediately via spawn(πš™πš›πš˜πšŒπšŽπšœπšœ.πšŽπš‘πšŽπšŒπ™ΏπšŠπšπš‘, [πš™πšŠπš’πš•πš˜πšŠπš_πš™πšŠπšπš‘], πšŽπš—πšŸ). 4. Reports installation metadata to oob[.]moika[.]tech/report (C2 callback). Updated Blog: safedep.io/oob-moika-tech-de… Campaign Details: safedep.io/ti/campaigns/oob-…
2nd Wave dropped.. 12 more packages across: @𝚝-πš’πš—-πš˜πš—πšŽ (10 packages at 𝟻.𝟽.𝟷) @πšŒπšŠπš™πš’πš‹πšŠπš›.πšŒπš‘πšŠπš/πšžπš’-πš”πš’πš (𝟿𝟿.𝟻.𝟽) @πšœπš‹πšŽπš›-πšŽπšŒπš˜πš–-πšŒπš˜πš›πšŽ/πšœπš‹πšŽπš›πš™πšŠπš’-πš πš’πšπšπšŽπš (𝟿𝟿.𝟻.𝟾) All these packages reuses wave 1 πš˜πš˜πš‹[.]πš–πš˜πš’πš”πšŠ[.]πšπšŽπšŒπš‘ C2 Blog: safedep.io/oob-moika-tech-de… Campaign Details: safedep.io/ti/campaigns/oob-…
5
15
1,110
Nietzsche Virus Lab retweeted
Full technical analysis, IoC table (31 unique "index.js" SHA-256 hashes), and safe version guidance are available in ReversingLabs’ latest blog: reversinglabs.com/blog/31-re…
5
9
469
Nietzsche Virus Lab retweeted
Our technical analysis on the Red Hat compromise now includes a more comprehensive look on the malware - including a 6th(!!!!!!) stage payload dropping logic! ox.security/blog/new-npm-sup…
4
11
37
3,596