Miasma Worm Goes Open Source: What's Actually Inside It. Complete Analysis
(thecybersecguru.com)
from WPSteam@lemmy.world to cybersecurity@infosec.pub on 09 Jun 19:56
https://lemmy.world/post/47962936
from WPSteam@lemmy.world to cybersecurity@infosec.pub on 09 Jun 19:56
https://lemmy.world/post/47962936
cross-posted from: lemmy.world/post/47960526
The Miasma supply chain worm just went open source. Here’s an analysis of it… Initial observations - 5-layer obfuscation, GitHub-as-C2, AI tool config hijacking, dead-man switches, and a self-perpetuating PAT flywheel.
threaded - newest
Very interesting read! One thing I don’t understand is this:
Does it mean we should not use Semver when referring to the actions? We should be using the action hash instead?
Or maybe the Semver with a version including the patch level?