📣 Introducing the all new OpenHack TUI - an open source terminal interface for security tasks, codebase scanning and pentesting.
Connect any model. Scan & auto verify vulnerabilities. Pentest any app. No Guardrails.
Live on openhack.com
Yesterday, OpenHack found 37 npm packages engaging in typosquatting to distribute infostealer malware, in 26 seconds.
All 37 packages are now gone from npm, but the GitHub-hosted payload remains downloadable.
Full breakdown:
🚨BREAKING: OpenHack has detected an infostealer malware campaign on npm capitalizing on typosquatting.
At this time, the package downloads a malicious exe file on windows as soon as one of the following packages is installed. The infostealer is downloaded from:
This is exactly why we built OpenHack. Model restrictions slow down our ability to find and defend against vulnerabilities; gating them behind cyber use-case forms.
First month of OpenHack Pro is free btw, code "DEFCON34".
> got approved for Anthropic Cyber Program in April
> somehow got removed (?)
> claude refusals across the board
> applied again today
> approved in 20 mins
> claude refusals still across the board
everyday i become even more bullish on open source models