tuckner (@tuckner) 's Twitter Profile
tuckner

@tuckner

Finding bad browser extensions at secureannex.com

ID: 14849912

calendar_today20-05-2008 23:27:16

3,3K Tweet

1,1K Followers

794 Following

b-bot (@b_b0t) 's Twitter Profile Photo

โš ๏ธ Came across something eye opening right now, and you should probably audit all installed extensions in your IDE. I was searching packages in Cursor and found one that is impersonating the official Tailwind CSS extension. ๐Ÿงต

โš ๏ธ Came across something eye opening right now, and you should probably audit all installed extensions in your IDE. I was searching packages in <a href="/cursor_ai/">Cursor</a> and found one that is impersonating the official <a href="/tailwindcss/">Tailwind CSS</a> extension. ๐Ÿงต
zodomo/ (๐ŸŒ,๐Ÿ’ป) (@0xzodomo) 's Twitter Profile Photo

Is there a malicious solidity VSCode extension? It seems the version from `juan-blanco` has more downloads/better reviews, despite being new. The version from `juanblanco` has bad reviews, less downloads, but longer history. The newer version DID NOT WORK, so I looked further. ๐Ÿงต

Is there a malicious solidity VSCode extension? It seems the version from `juan-blanco` has more downloads/better reviews, despite being new. The version from `juanblanco` has bad reviews, less downloads, but longer history. The newer version DID NOT WORK, so I looked further. ๐Ÿงต
Daniel Stinson (@shellcromancer) 's Twitter Profile Photo

๐Ÿ†• YARA module this week: Chrome extension bundles! Would be pretty cool to add Mandiant's Permission Hash to the module's output for pivoting fun! Secure Annex exposes Permhash's in their UI/API so this would be a nice CLI format

๐Ÿ†• YARA module this week: Chrome extension bundles! 

Would be pretty cool to add Mandiant's Permission Hash to the module's output for pivoting fun! <a href="/secureannex/">Secure Annex</a>  exposes Permhash's in their UI/API so this would be a nice CLI format
tuckner (@tuckner) 's Twitter Profile Photo

More energized than ever after a week in Vegas Got the opportunity to give my first talk at summer camp which checks a box on my bucket list. Thankful for everyone I met, folks I got to catch up with, and the discussions that were had!

More energized than ever after a week in Vegas Got the opportunity to give my first talk at summer camp which checks a box on my bucket list. Thankful for everyone I met, folks I got to catch up with, and the discussions that were had!
tuckner (@tuckner) 's Twitter Profile Photo

Another Open VSX extension removed today. Same code and same callback endpoint. ethfoundry.solidityethereum app.secureannex.com/extensions/seaโ€ฆ

Another Open VSX extension removed today. Same code and same callback endpoint.

ethfoundry.solidityethereum

app.secureannex.com/extensions/seaโ€ฆ
Secure Annex (@secureannex) 's Twitter Profile Photo

Knows which extensions are malware but won't display it in Google admin or remove them from the web store. What does that tell you?