HNHacker News
TopNewBestAskShowJobs

varunsharma07

683 karma · joined July 3, 2021

Founder of StepSecurity (https://www.stepsecurity.io)
submissionscomments

Immobiliarelabs NPM packages have been compromised

github.com·2 pts·varunsharma07·
0

Codfish/semantic-release-action GitHub Action has been compromised

stepsecurity.io·4 pts·varunsharma07·
0

Multiple mastra NPM packages compromised

github.com·4 pts·varunsharma07·
1

Ongoing NPM supply chain attack uses binding.gyp to spread like a worm

github.com·6 pts·varunsharma07·
0

Laravel-Lang Supply Chain Attack

github.com·3 pts·varunsharma07·
1

NX VS Code extension compromised again

github.com·4 pts·varunsharma07·
0

Actions-cool/issues-helper GitHub Action Compromised

github.com·3 pts·varunsharma07·
0

Malicious node-IPC Versions Published to NPM

github.com·6 pts·varunsharma07·
2

Postmortem: TanStack NPM supply-chain compromise

tanstack.com·1097 pts·varunsharma07·
465

Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push

stepsecurity.io·5 pts·varunsharma07·
1

Show HN: Scan your dev machine for AI agents, MCP servers, and IDE extensions

github.com·9 pts·varunsharma07·
0

Xygeni/xygeni-action GitHub Action is compromised – poisoned tag is still live

stepsecurity.io·2 pts·varunsharma07·
0

Hackerbot-Claw: AI Bot Exploiting GitHub Actions – Microsoft, Datadog Hit So Far

stepsecurity.io·27 pts·varunsharma07·
4

GitHub Actions is left vulnerable to supply chain attacks: Datadog Report

datadoghq.com·4 pts·varunsharma07·
0

Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw

stepsecurity.io·12 pts·varunsharma07·
1

Harden Runner Detected the SHA1-Hulud Supply Chain Attack in CNCF's Backstage

stepsecurity.io·1 pts·varunsharma07·
1

Popular Nx Build System NPM Package Compromised with Data Stealing Malware

stepsecurity.io·10 pts·varunsharma07·
2

Suspicious Tag Change in AWS's GitHub Action: What Happened and Why It Matters

stepsecurity.io·3 pts·varunsharma07·
1

Num2words PyPI Package Compromised

stepsecurity.io·22 pts·varunsharma07·
6

eslint-config-prettier npm package compromised

stepsecurity.io·74 pts·varunsharma07·
11

Grafana GitHub Actions Security Incident

stepsecurity.io·10 pts·varunsharma07·
0

Tj-actions/changed-files GitHub Action Compromised – used by over 23K repos

stepsecurity.io·273 pts·varunsharma07·
298

CI/CD supply chain attack on Azure Karpenter Provider open-source project

stepsecurity.io·3 pts·varunsharma07·
2

Security Breach in Stripe Repo: A Deep Dive into the "Pwn Request" Vulnerability

stepsecurity.io·7 pts·varunsharma07·
0

An Obscure Actions Workflow Vulnerability in Google's Flank

adnanthekhan.com·20 pts·varunsharma07·
1

Show HN: GitHub Actions Advisor – View security scores of GitHub Actions you use

app.stepsecurity.io·3 pts·varunsharma07·
0

How Google secures their GitHub Actions workflows with StepSecurity

stepsecurity.io·3 pts·varunsharma07·
0

Protect Against CI/CD Attacks That Poison GitHub Actions Workflows

infosecwriteups.com·3 pts·varunsharma07·
0

Celebrating Success of 500 Open Source Projects Using StepSecurity's Platform

stepsecurity.io·1 pts·varunsharma07·
1

Show HN: AI-CodeWise – Transforming Code Reviews with AI-Powered Analysis

github.com·2 pts·varunsharma07·
0
Page 1 of 2Next →