Ax Sharma's profile photo

Ax Sharma

Canada, India, United Kingdom

Tech Reporter and Security Researcher at Bleeping Computer

Tech Reporter and Security Researcher at Security Boulevard

Infosec Researcher, Journalist | 📰 Bylines + seen on 📸 BBC, BleepingComputer, Channel 5, WaPo, TechCrunch, WIRED | Member @The_BAJ @CAJ | ✉️ Tips? [email protected]

Articles

  • 2 weeks ago | securityboulevard.com | Ax Sharma

    An illicit npm package called ‘crypto-encrypt-ts‘ may appear to revive the unmaintained but vastly popular CryptoJS library, but what it actually does is peek into your crypto wallet and exfiltrate your secrets to threat actors. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/revived-cryptojs-library-is-a-crypto-stealer-in-disguise

  • 2 weeks ago | sonatype.com | Ax Sharma

    An illicit npm package called 'crypto-encrypt-ts' may appear to revive the unmaintained but vastly popular CryptoJS library, but what it actually does is peek into your crypto wallet and exfiltrate your secrets to threat actors. Discovered by Sonatype's automated malware detection systems, the counterfeit 'crypto-encrypt-ts' has been downloaded more than 1,928 times already since its publication.

  • 4 weeks ago | bleepingcomputer.com | Ax Sharma

    Atlassian users are experiencing degraded performance amid an 'active incident' affecting multiple Jira products since morning hours today. Jira, Jira Service Management, Jira Work Management and Jira Product Discovery are among the impacted products. Jira is a popular project management and issue tracking software solution used by workplaces to plan, track and manage workflows, specifically among Agile software development teams.

  • 1 month ago | sonatype.com | Ax Sharma

    Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. Some of these packages have lived on npmjs.com for over 9 years, and provide legitimate functionality to blockchain developers. However, our automated malware detection systems detected that the latest versions of each of these packages were laden with obfuscated scripts, raising alarms.

  • 1 month ago | securityboulevard.com | Ax Sharma

    Sonatype has identified multiple npm cryptocurrency packages, latest versions of which have been hijacked and altered to steal sensitive information such as environment variables from the target victims. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers

Contact details

Socials & Sites

Try JournoFinder For Free

Search and contact over 1M+ journalist profiles, browse 100M+ articles, and unlock powerful PR tools.

Start Your 7-Day Free Trial →

X (formerly Twitter)

Followers
5K
Tweets
3K
DMs Open
Yes
Ax Sharma
Ax Sharma @Ax_Sharma
16 Apr 25

RT @BleepinComputer: Jira Down: Atlassian users experiencing degraded performance - @Ax_Sharma https://t.co/72TBFcG5nJ https://t.co/72TBFc…

Ax Sharma
Ax Sharma @Ax_Sharma
15 Apr 25

🎬 Another season out: Watch on-demand or online on Channel 5 UK. 📺 Scams: Don't Get Caught Out - Season 3 https://t.co/PjQehiqmoY

Ax Sharma
Ax Sharma @Ax_Sharma
26 Feb 25

RT @hackerfantastic: North Korea stole $1.4billion by injecting JavaScript through an AWS S3 bucket to spoof the UI interface during a tran…