HNHacker News
TopNewBestAskShowJobs

abhisek

844 karma · joined May 1, 2012

Dabbling into open source software supply chain security

github.com/safedep/pmg

submissionscomments

Why does mathmain need an encrypted loader?

safedep.io·138 pts·abhisek·
43

Malicious Rust crate Arrayref runs a build-time payload

safedep.io·554 pts·abhisek·
511

OpenAI’s accidental attack against Hugging Face is science fiction that happened

simonwillison.net·587 pts·abhisek·
450

Show HN: PMG, open source package firewall

github.com·4 pts·abhisek·
2

Jscrambler 8.14.0 Compromised with Credential Stealer

safedep.io·3 pts·abhisek·
0

Claude Mythos and Cybersecurity

schneier.com·4 pts·abhisek·
0

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

cloud.google.com·1 pts·abhisek·
0

Step by Step Analysis of Malicious NPM Package

safedep.io·1 pts·abhisek·
0

OpenClaw bot calls out maintainer when its PR got rejected

crabby-rathbun.github.io·1 pts·abhisek·
0

Show HN: Gryph – Audit Trail for AI Coding Agents (Claude Code, Cursor, Gemini)

github.com·1 pts·abhisek·
0

Agent Skills Threat Model

safedep.io·3 pts·abhisek·
0

Catching malicious package releases using a transparency log

blog.trailofbits.com·3 pts·abhisek·
0

CVE-2025-66491: Traefik's "Verify=on" Turned TLS Off

aisle.com·1 pts·abhisek·
0

DarkGPT: Malicious Visual Studio Code Extension Targeting Developers

safedep.io·2 pts·abhisek·
0

Exposing and Exploiting Incomplete Branch Predictor Isolation in Cloud

comsec.ethz.ch·1 pts·abhisek·
0

KnownSec breach: What we know so far

substack.com·1 pts·abhisek·
0

Buying browser extensions for fun and profit

secureannex.com·3 pts·abhisek·
1

Curious Case of Embedded Executable in a Newly Introduced Transitive Dependency

safedep.io·4 pts·abhisek·
0

NPM Supply Chain Malware with Self-Replicating Behaviour

safedep.io·2 pts·abhisek·
0

Tensorflow.js Typosquatting Attack: Malicious Package Targeting AI/ML Developers

safedep.io·2 pts·abhisek·
0

Secure Vibe Coding with AI Agents

safedep.io·2 pts·abhisek·
0

ESLint-config-prettier: How NPM Package with 30M Downloads Spread Malware

safedep.io·1 pts·abhisek·
0

Scavenger Malware Distributed via ESLint-Config-Prettier NPM Package Hack

invokere.com·1 pts·abhisek·
0

Near Real-Time Stream of Open Source Packages Published to Public Registries

vetpkg.dev·2 pts·abhisek·
0

Critical RCE Vulnerability in Anthropic MCP Inspector – CVE-2025-49596

oligo.security·5 pts·abhisek·
1

Ask HN: HN: Why do we code review?

2 pts·abhisek·
2

The PostgreSQL Locking Trap That Killed Our Production API (and How We Fixed It)

root.sigsegv.in·2 pts·abhisek·
0

Show HN: Xbom – Generate AI and SaaS-Aware SBOMs from Code Using Static Analysis

github.com·3 pts·abhisek·
0

Vet MCP: Software Composition Analysis for AI Code Editors

github.com·1 pts·abhisek·
0

Catching the Silent Threat: How Dynamic Analysis Revealed an NPM Attack Chain

safedep.io·2 pts·abhisek·
0
Page 1 of 2Next →