HNHacker News
TopNewBestAskShowJobs

ashishbijlani

220 karma · joined July 8, 2015

PhD in Cybersecurity/Operating Systems from Georgia Tech

Building https://packj.dev - a security firewall for your open-source dependencies to protect against typo-squatting, dependency confusion, and Solarwinds-like supply-chain attacks: https://github.com/ossillate-inc/packj

Creator of ExtFUSE (eBPF + FUSE) and SandFS [available for consulting]: https://github.com/extfuse/extfuse https://github.com/sandfs/sandfs.github.io

https://twitter.com/ashishbijlani https://www.linkedin.com/in/ashishbijlani/

first.last@<popular-google-service.com>

submissionscomments
ashishbijlani··on Keyv and friends compromised in active Shai-Hulud supply chain attack
I've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj

Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).

ashishbijlani··on Malicious npm packages detected across Red Hat Cloud Services
Built Packj [1] to audit dependencies easily from CLI.

1. Packj (https://github.com/ossillate-inc/packj) detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

ashishbijlani··on Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
Built Packj [1] to do exactly this.

1. Packj (https://github.com/ossillate-inc/packj) detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

ashishbijlani··on Show HN: Artifact Keeper – Open-Source Artifactory/Nexus Alternative in Rust
This is a great initiative. Thanks for sharing! I will use it to create my personal cache of package registries (beyond obvious advantages of caching, it can also mitigate typo-squatting attacks).

BTW, if there's an interest, I'd love to collaborate and integrate Packj [1] audit for malware scans.

1. Packj (https://github.com/ossillate-inc/packj) detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

ashishbijlani··on Cloudflare Sandbox SDK
I’m extending Packj sandbox for agentic code execution [1]. You can specify allowlist for network/fs.

1. https://github.com/ossillate-inc/packj/blob/main/packj/sandb...

ashishbijlani··on Show HN: Tips to stay safe from NPM supply chain attacks
Plug: I've been building a tool to detect software supply-chain cyberattacks: https://github.com/ossillate-inc/packj

Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).

ashishbijlani··on NPM debug and chalk packages compromised
Packj [1] detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Show HN: Pipask – safer pip without compromising convenience
Plug: I've been building a similar tool: https://github.com/ossillate-inc/packj

Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).

ashishbijlani··on Show HN: Arrakis – Open-source, self-hostable sandboxing service for AI Agents
Hi Abhishek, the backtracking feature looks super useful. Congrats on launching!
ashishbijlani··on Ask HN: Have you ever been hired because of open-source contributions?
Not for contributions only, but developing ExtFUSE [1] got me a lot of offers and consulting work.

1. https://github.com/extfuse/extfuse optimizes FUSE with eBPF

ashishbijlani··on Analysis of supply-chain attack on Ultralytics
> If the tech is open-sourced, then an attacker can keep trying in private until they find an exploit, and then use it.

So you'd rather assume that if something is obscure, it is secure?

ashishbijlani··on Analysis of supply-chain attack on Ultralytics
We scan PyPI packages regularly for malware to provide a private registry of vetted packages.

The tech is open-sourced: Packj [1]. It uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect impersonating packages (typo squatting).

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Ultralytics AI model hijacked to infect thousands with cryptominer
This is exactly why I'm building Packj audit [1]. It detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

1. https://github.com/ossillate-inc/packj

ashishbijlani··on A Study of Malware Prevention in Linux Distributions
Good to see Packj[1] as one of the malware scanners used.

1. https://github.com/ossillate-inc/packj

Packj detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

ashishbijlani··on Cybercriminals pose as "helpful" Stack Overflow users to push malware
Plug: I’ve been building Packj [1] to detect malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

1. https://github.com/ossillate-inc/packj

ashishbijlani··on XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable."
I’ve been building Packj [1] to detect malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc). It also checks for several metadata attributes to detect bad actors (e.g., typo squatting).

1. https://github.com/ossillate-inc/packj

ashishbijlani··on PyPI halted new users and projects while it fended off supply-chain attack
I’ve been building Packj [1] to detect such attacks. Packj can flag malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP dependencies. We use static, dynamic, & metadata analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network communication, use of decode+eval, etc.) OR presence of vulnerabilities.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Over 100k Infected Repos Found on GitHub
I’ve been building an open-source tool Packj [1] to detect publicly malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis and scans for 40+ attributes such as spawning of shell, use of SSH keys, network communication, use of decode+eval, etc. to flag risky packages.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on A cautionary tale about software dependencies during major geopolitical events
> For how to know you can trust a dependency, I'm afraid there is no solution: no theorem prover nor isolation, cryptography nor layerizarion can save you.

I'm taking a stab at addressing this problem with Packj [1]. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawning of shell, invalid/expired email (i.e., no 2FA), use of files, network communication, use of decode+eval, mismatch of GitHub code vs packaged code, and several more.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Ledger's NPM account has been hacked
Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawning of shell, invalid/expired email (i.e., no 2FA), use of files, network communication, use of decode+eval, mismatch of GitHub code vs packaged code, and several more.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Show HN: Unofficial Google Play Store API
Cool project! Are you fetching app metadata from Google Playstore in real-time or you've cached data of all Android apps on your server already?
ashishbijlani··on Rust without crates.io
Creator of Packj [1] here. How do you envision sandboxing/security policies will be specified? Per-lib policies when you've hundreds of dependencies will become overwhelming. Having built an eBPF-based sandbox [2], I anticipate that accuracy will be another challenge here: too restrictive will block functionality, too permissive defeats the purpose.

1. https://github.com/ossillate-inc/packj flags malicious/risky NPM/PyPI/RubyGems/Rust/Maven/PHP packages by carrying out static+dynamic+metadata analysis.

2. Sandboxing file system w/o superuser privileges: https://github.com/sandfs/sandfs.github.io

ashishbijlani··on Rust without crates.io
I’ve been building Packj [1] to detect publicly UNKNOWN dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis and scans for 40+ attributes such as num funcs/files, spawning of shell, use of SSH keys, network communication, use of decode+eval, etc. to flag risky packages. Packj Github action [2] can alert if a risky dependency is pulled into your build.

1. https://github.com/ossillate-inc/packj 2. https://github.com/ossillate-inc/packj-github-action

ashishbijlani··on We've learned nothing from the SolarWinds hack
Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawning of shell, use of files, network communication, use of decode+eval, mismatch of GitHub code vs packaged code, and several more.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on Making Rust supply chain attacks harder with Cackle
Good to see more attempts at analyzing dependencies for malware.

Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawning of shell, use of files, network communication, use of decode+eval, mismatch of GitHub code vs packaged code, and several more.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on A Deep Dive into 70 Layers of Obfuscated Info-Stealer Malware
I've been building Packj [1] to detect exactly such attacks. It can flag dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages by carrying out static/dynamic/metadata analysis.

It scans for 40+ attributes such as num funcs/files, spawning of shell, use of SSH keys, network communication, use of decode+eval, etc. to flag risky packages. Packj Github action [2] can alert if a risky dependency is pulled into your build.

1. https://github.com/ossillate-inc/packj 2. https://github.com/ossillate-inc/packj-github-action

ashishbijlani··on The Bogus CVE Problem
I've been building Packj [1] to detect dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis and scans for 40+ attributes such as num funcs/files, spawning of shell, use of SSH keys, network communication, use of decode+eval, etc. to flag risky packages. Packj Github action [2] can alert if a risky dependency is pulled into your build.

1. https://github.com/ossillate-inc/packj 2. https://github.com/ossillate-inc/packj-github-action

ashishbijlani··on A study of malicious code in PyPI ecosystem
Thanks! We need more such efforts to improve supply-chain security of open-source software.

Packj detects typo-squatting (impersonation) as well.

ashishbijlani··on A study of malicious code in PyPI ecosystem
I've been building Packj [1] to detect dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis and scans for 40+ attributes such as num funcs/files, spawning of shell, use of SSH keys, network communication, use of decode+eval, mismatch of GitHub code vs packaged code (provenance), change in APIs across versions, etc. to flag risky packages.

1. https://github.com/ossillate-inc/packj

ashishbijlani··on A study of malicious code in PyPI ecosystem
Makes sense. When I read your notes, it appeared that you wanted to run untrusted code on a backend server.
Page 1 of 4Next →