How a Photo Hacked OpenAI's Kingdom
A single image file bypassed OpenAI's defenses, leading to a GitHub compromise. This attack reveals a silent vulnerability lurking in millions of applications, and your stack is likely next.
Tag
5 posts
A single image file bypassed OpenAI's defenses, leading to a GitHub compromise. This attack reveals a silent vulnerability lurking in millions of applications, and your stack is likely next.
The infamous Shai-Hulud worm has evolved, jumping from npm to the Go ecosystem. It's no longer hiding in your dependencies—it's weaponizing your VS Code and Claude configs to steal secrets the moment you open a project.
Supply chain attacks are hitting Node.js projects weekly, but you can harden your setup in minutes. These battle-tested strategies for npm, pnpm, and Bun will stop most attacks before they start.
Developer laptops are the new frontier for supply chain attacks, cluttered with risky packages and configs. Perplexity just open-sourced Bumblebee, a read-only scanner that finds these threats without triggering them.
A simple `npm install` triggered a sophisticated attack, siphoning cloud secrets from SAP developers in just two hours. This is the story of the 'Mini Shai-Hulud' hack and why your projects are at risk.