
Ax Sharma
Tech Reporter and Security Researcher at Bleeping Computer
Tech Reporter and Security Researcher at Security Boulevard
Infosec Researcher, Journalist | 📰 Bylines + seen on 📸 BBC, BleepingComputer, Channel 5, WaPo, TechCrunch, WIRED | Member @The_BAJ @CAJ | ✉️ Tips? [email protected]
Articles
-
1 week ago |
bleepingcomputer.com | Ax Sharma
Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and Jira Product Discovery are among the impacted products. Jira is a popular project management and issue tracking software solution used by workplaces to plan, track and manage workflows, specifically among Agile software development teams.
-
4 weeks ago |
sonatype.com | Ax Sharma
Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers. However, our automated malware detection systems detected that the latest versions of each of these packages were laden with obfuscated scripts, raising alarms.
-
4 weeks ago |
securityboulevard.com | Ax Sharma
Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers
-
2 months ago |
securityboulevard.com | Ax Sharma
A counterfeit ‘Truffle for VS Code’ extension, published on the npmjs registry, abuses the ConnectWise ScreenConnect remote desktop utility, allowing threat actors to compromise Windows systems that install the package. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/fake-vs-code-extension-on-npm-uses-altered-screenconnect-utility-as-spyware
-
2 months ago |
sonatype.com | Ax Sharma
A counterfeit 'Truffle for VS Code' extension, published on the npmjs registry, abuses the ConnectWise ScreenConnect remote desktop utility, allowing threat actors to compromise Windows systems that install the package. The real Truffle for VS Code extension on the Microsoft Visual Studio Marketplace has been installed around 80,000 times and also has its source code available on GitHub. The official GitHub repository also contains a private npm component called 'truffle-vscode'.
Try JournoFinder For Free
Search and contact over 1M+ journalist profiles, browse 100M+ articles, and unlock powerful PR tools.
Start Your 7-Day Free Trial →X (formerly Twitter)
- Followers
- 5K
- Tweets
- 3K
- DMs Open
- Yes

RT @hackerfantastic: North Korea stole $1.4billion by injecting JavaScript through an AWS S3 bucket to spoof the UI interface during a tran…

Fake VS Code extension on npm uses altered ScreenConnect utility as spyware h/t @SnifferNandez @sonatype https://t.co/5MmyH4qTRG

RT @BleepinComputer: Google Play, Apple App Store apps caught stealing crypto wallets - @billtoulas https://t.co/FbVY5q8cJD https://t.co/F…