RSS Bot@lemmy.bestiver.seBM to Hacker News@lemmy.bestiver.seEnglish · 28 days agoI found a malware hiding in my TailwindCSS config fileinfosecwriteups.comexternal-linkmessage-square7linkfedilinkarrow-up14arrow-down13file-text
arrow-up11arrow-down1external-linkI found a malware hiding in my TailwindCSS config fileinfosecwriteups.comRSS Bot@lemmy.bestiver.seBM to Hacker News@lemmy.bestiver.seEnglish · 28 days agomessage-square7linkfedilinkfile-text
minus-squarepotatO_0linkfedilinkEnglisharrow-up1·26 days agoThe underlying investigation is genuine. Here’s the trail if you want to verify: Reddit (r/AskNetsec) - the specific forensic questions I’m trying to answer, macOS + Copilot agent angle Security.StackExchange - detailed technical post on the git identity spoofing and infection timeline GitHub repo - IOCs and detection scripts, actively updated Trend Micro report - the published research this maps to I’ve also reached out to Lucas Silva at Trend Micro directly with my specific IOCs.
The underlying investigation is genuine. Here’s the trail if you want to verify:
Reddit (r/AskNetsec) - the specific forensic questions I’m trying to answer, macOS + Copilot agent angle
Security.StackExchange - detailed technical post on the git identity spoofing and infection timeline
GitHub repo - IOCs and detection scripts, actively updated
Trend Micro report - the published research this maps to
I’ve also reached out to Lucas Silva at Trend Micro directly with my specific IOCs.