Log inSign up
Log inSign up
Charles Neill
7,633 posts
Charles Neill profile banner
@ccneill

Charles Neill

@ccneill
Risky business
Austin, TX
techiavellian.com
Joined July 2012
1,191 Following
607 Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • @ccneill
    Charles Neill
    @ccneill
    Jul 19
    Concerning report from @huggingface here: > A malicious dataset abused two code-execution paths in our dataset processing... The campaign was run by an autonomous agent framework... executing many thousands of individual actions across a swarm of short-lived sandboxes...
    1
  • @ccneill
    Charles Neill
    @ccneill
    Jul 5
    Happy 4th, everyone 🎇🇺🇸🦅🫡🎆
  • @ccneill
    Charles Neill
    @ccneill
    Mar 31
    Reset the counter to 0 days since the last Python/JS supply chain attack...
    @feross
    Feross
    Socket
    @feross
    Mar 31
    🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest [email protected] now pulls in [email protected], a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios
  • @ccneill
    Charles Neill
    @ccneill
    Feb 23
    Funny watching articles spread like wildfire on X now. You already know what article I'm talking about without me describing it at all I can't decide if this is an algo artifact or if people are just using AI to summarize them now, speeding up their Time To Hot Take Reply
    1
  • @ccneill
    Charles Neill
    @ccneill
    Feb 21
    This is the gnarliest npm worm I've seen so far, and these will only get worse - appears this might still be in the testing phase Persistence via git global config to poison future repos, CI jobs to grab new creds, even malicious MCP server injection Amazing write-up - read!
    @SocketSecurity
    Socket
    @SocketSecurity
    Feb 20
    🚨 Active supply chain attack New Shai-Hulud–like npm worm (19+ packages, 2 aliases) stealing dev/CI secrets, injecting GitHub workflows, poisoning AI toolchains, and harvesting LLM API keys. Details → socket.dev/blog/sandworm-… #NodeJS #JavaScript