Joined March 2011
646 Photos and videos
Pinned Tweet
4 Mar 2025
The last few months I have had so much fun rapidly prototyping personal and @permisosecurity projects. I treat every weekend as a hackathon. Using @cursor_ai has been a game changer for me to be able to crank out fast and mostly polished POCs. Today, I'm gonna showcase some of of these!
1
3
21
3,132
1aN0rmus retweeted
NPM Malware > - Obfuscated postinstall hook (.prepare.cjs) uses char-code arrays to hide sensitive variable names - Credential harvesting targeting AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN - Exfiltration endpoint at open[.larksuite[.com (Feishu bot webhook) acts as C2 - Explicit sandbox evasion logic checking for SANDYCLAW, OPENCLAW, PERMISO, CHAINRADAR env https[://www[.npmjs[.com/package/ash-claw/v/1.7.13 https[://sandyclaw[.permiso[.io/shared/5PVyO_QI-Y0ENhwni99JtULn_f8oVSMpqWXiYktq5E4 @TekDefense 😂
8
19
827
1aN0rmus retweeted
🤩 We just wrapped up 2 days of my training Practical AI for Threat Intel in Sydney! It was packed and the class was fantastic! If you want to step up your skills and learn faster from our latest research, the next session will be hosted at @BlackHatEvents in August! blackhat.com/us-26/training/…
3
29
2,018
I think I should be flattered! First ITW package that specifically tries to evade SandyClaw (unsuccessfully) sandyclaw.permiso.io/shared/… Great find @KirkDerpca ! npmjs.com/package/visa-respo…
2
2
13
1,508
1aN0rmus retweeted
// CI/CD sandbox detection (prefix-based, catches all SandyClaw/OpenClaw/Permiso variants) 🤷‍♂️ sandyclaw.permiso.io/shared/… (Malicious) https[://www[.npmjs[.com/package/visa-response/v/1.4.4-beta?activeTab=code
2
13
929
1aN0rmus retweeted
Great team over there 👇🏼
I’m hiring a sr principal threat researcher. When big things happen on the internet, you’ll lead the threat research to hunt across our vast telemetry & write the threat briefs. Senior role w/ strong comms & collab experience. jobs.paloaltonetworks.com/en…
1
9
3,033
1aN0rmus retweeted
🤓 This morning at @SLEUTHCON, I talked about how AI is being targeted and leveraged by cybercriminals. Which is beyond simply using models in their operations, attackers are also actively targeting AI environments themselves. That AI agent you trusted inside your organization is becoming a prime target because you don’t know what it is doing while it is running. And attackers know it. 💀
4
13
51
3,291
1aN0rmus retweeted
NPM Malware > 3 Packages, all malicious, multiple versions. "Security Research Honeypot" that wants to exfil your corp OneDrive var hasCorpOneDrive = !!env.ONEDRIVECOMMERCIAL; 🤷‍♂️ 46[.224.67.169:3000 https[://www[.npmjs[.com/~deathpoolxrs Sandbox: sendgrid-sdk@0.2.4: sandyclaw.permiso.io/package… twilio-sdk@0.2.4: sandyclaw.permiso.io/package… gpt-sdk@0.2.4: sandyclaw.permiso.io/package…

1
5
16
1,174
1aN0rmus retweeted
NPM Malware > Package itself is empty/benign but has a dependency listed in package.json to an external source... silently runs test.js collects data and ships it off too housecall-ui[.w74ghp3dc2o7gmsqrl4b6itmvd14vslga[.oastify.com https[://www[.npmjs[.com/package/housecall-ui Sandbox: sandyclaw.permiso.io/shared/…

1
2
7
738
1aN0rmus retweeted
Are you sick of waiting for the next attack? Tired of standing by while adversaries take the initiative? Become a GTIG Disruption Engineer and help us change the way we do defense. google.com/about/careers/app…
3
15
52
9,153
1aN0rmus retweeted
🤓 On Friday I will have the honor to present the keynote at @SLEUTHCON! Come say hi if you are around!
2
7
32
5,234
1aN0rmus retweeted
Big thanks to @thecyberwire for covering our recent ChatGPhish research from @SecEagleAnd1 in their recent episode. "Ahmeti demonstrated how attackers could insert fraudulent account warnings and malicious links into otherwise legitimate summaries. He also showed that embedded QR codes could redirect victims from their desktops to attacker-controlled websites on mobile devices, potentially bypassing browser-based security protections. The vulnerability stems from ChatGPT treating untrusted external content as trusted input during summarization." thecyberwire.com/podcasts/da…
2
3
148
1aN0rmus retweeted
Replying to @mattpocockuk
Oh no, please. For the love of software supply chain security, please do not encourage this. We need to get rid of lifecycle scripts. Pretty please? 😭
2
2
45
1,965
logger-active@3.2.0 intquery@1.1.3 deploys logger-active@3.2.0 (RAT payload) as a dependency
1
1
2
771
Morning coffee complete, think it is time to get back to my real job :)
1
94
1
1
72
I love it when attackers capture their own keylogs, even better when they screenshot their own computer while testing their malware. Our attacker (bink) videcoding their NPM malz with Cursor and Codex 5.3 ... More context in the previous thread. @ItsReallyNick , I think our Keylogs Chronicles book idea still has legs.
1
1
6
772