rami Profile picture
Product Security Engineer, reformed Security Consultant. opinions my own (he/him) @rami@infosec.exchange
Jun 5 4 tweets 1 min read
🚒More fallout from the Mini Shai-Hulud campaign

49 Microsoft, Azure, and Azure-Samples GitHub repos were removed at 16:00 UTC for Terms of Service violations

This is linked to news this morning that attackers had regained access, after the previous durabletask compromise Image Shout out @adnanthekhan for flagging the initial signs of infection, and Graham Gold for flagging the removal!

Oct 15, 2025 6 tweets 2 min read
Finally disclosing the critical supply chain attack I've spent the last 6 months preventing:

🧵 🪲Attackers first started introducing malware to the VSCode Marketplace in February.

I decided to find novel examples, but got dramatically side tracked with this much more critical issue: publishers have been leaking secrets en masse!

It gets worse ...