Ax Sharma's profile photo

Ax Sharma

Canada, India, United Kingdom

Tech Reporter and Security Researcher at Bleeping Computer

Tech Reporter and Security Researcher at Security Boulevard

Infosec Researcher, Journalist | 📰 Bylines + seen on 📸 BBC, BleepingComputer, Channel 5, WaPo, TechCrunch, WIRED | Member @The_BAJ @CAJ | ✉️ Tips? [email protected]

Articles

  • 1 week ago | bleepingcomputer.com | Ax Sharma

    Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and Jira Product Discovery are among the impacted products. Jira is a popular project management and issue tracking software solution used by workplaces to plan, track and manage workflows, specifically among Agile software development teams.

  • 4 weeks ago | sonatype.com | Ax Sharma

    Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers. However, our automated malware detection systems detected that the latest versions of each of these packages were laden with obfuscated scripts, raising alarms.

  • 4 weeks ago | securityboulevard.com | Ax Sharma

    Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers

  • 2 months ago | securityboulevard.com | Ax Sharma

    A counterfeit ‘Truffle for VS Code’ extension, published on the npmjs registry, abuses the ConnectWise ScreenConnect remote desktop utility, allowing threat actors to compromise Windows systems that install the package. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/fake-vs-code-extension-on-npm-uses-altered-screenconnect-utility-as-spyware

  • 2 months ago | sonatype.com | Ax Sharma

    A counterfeit 'Truffle for VS Code' extension, published on the npmjs registry, abuses the ConnectWise ScreenConnect remote desktop utility, allowing threat actors to compromise Windows systems that install the package. The real Truffle for VS Code extension on the Microsoft Visual Studio Marketplace has been installed around 80,000 times and also has its source code available on GitHub. The official GitHub repository also contains a private npm component called 'truffle-vscode'.

Contact details

Socials & Sites

Try JournoFinder For Free

Search and contact over 1M+ journalist profiles, browse 100M+ articles, and unlock powerful PR tools.

Start Your 7-Day Free Trial →

X (formerly Twitter)

Followers
5K
Tweets
3K
DMs Open
Yes
Ax Sharma
Ax Sharma @Ax_Sharma
26 Feb 25

RT @hackerfantastic: North Korea stole $1.4billion by injecting JavaScript through an AWS S3 bucket to spoof the UI interface during a tran…

Ax Sharma
Ax Sharma @Ax_Sharma
7 Feb 25

Fake VS Code extension on npm uses altered ScreenConnect utility as spyware h/t @SnifferNandez @sonatype https://t.co/5MmyH4qTRG

Ax Sharma
Ax Sharma @Ax_Sharma
6 Feb 25

RT @BleepinComputer: Google Play, Apple App Store apps caught stealing crypto wallets - @billtoulas https://t.co/FbVY5q8cJD https://t.co/F…