LARGEST SUPPLY CHAIN HACK IN HISTORY ZOMG!!!!111
Links referenced:
https://github.com/advisories/GHSA-8mgj-vmr8-frr6
https://www.linkedin.com/posts/advocatemack_malware-npm-supplychain-activity-7370829639537291264-jxZD/
https://news.ycombinator.com/item?id=45169657&trk=public_post_comment-text
https://npmdiff.dev/simple-swizzle/0.2.2/0.2.3/package/index.js/
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
https://www.securityalliance.org/news/2025-09-npm-supply-chain
https://x.com/InsiderPhD/status/1965110610972250550
https://x.com/WhichbufferArda/status/1965139425475907774
https://x.com/hackerfantastic/status/19651434915…
Watch on YouTube ↗
(saves to browser)
Playlist
Uploads from John Hammond · John Hammond · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
b00t2root CTF: cuz rsa is lub [RSA Cryptography]
John Hammond
b00t2root19 CTF: Scatter Me [3D Scatter Plots]
John Hammond
b00t2root19 CTF: Genetics [DNA Cryptography]
John Hammond
b00t2root19 CTF: Can You Read Me [Esoteric Languages]
John Hammond
b00t2root19 CTF: Treasure [GameBoy ROMs]
John Hammond
b00t2root19 CTF: Loopback [PCAP Forensics]
John Hammond
b00t2root19 CTF: EasyPHP [PHP Web Exploits]
John Hammond
SunshineCTF 2019: WelcomeCrypto [ROT47]
John Hammond
SunshineCTF 2019 | Brainmeat (Esoteric Languages)
John Hammond
SunshineCTF 2019 | CB1 (NATO Phonetic Alphabet)
John Hammond
SunshineCTF 2019 | Return to Mania (PWN) PIE
John Hammond
SunshineCTF 2019: Wrestler Book (Explicit SQL Injection)
John Hammond
SunshineCTF 2019: Wrestler Name Generator (XML XXE)
John Hammond
Python PIL: Recreating LSB in Stegsolve.jar
John Hammond
Checking IP Address in CIDR Subnet w/ Python
John Hammond
Cracking HSRP Passwords w/ John The Ripper
John Hammond
Facebook CTF - SQL Injection with Spaces (Products Manager)
John Hammond
Crypto: Classic RSA with a Twist (ParsonsCTF)
John Hammond
Finding Shared Libraries with LDD (ParsonsCTF)
John Hammond
HSCTF - Obfuscated JavaScript (JSF**k) [Verbose]
John Hammond
HSCTF - Hiding in ZIP Files (LockedUp)
John Hammond
HackTheBox - Help
John Hammond
HSCTF - Hunting Git Commits (Admin Pass)
John Hammond
HSCTF - Python Remote Code Execution (A Simple Conversation)
John Hammond
HSCTF - Hidden UTF-8 Encoding (Real Reversal)
John Hammond
HSCTF - XORing Data (Hidden Flag)
John Hammond
HSCTF - RSA Cryptography (Reverse Search Algorithm)
John Hammond
GOOGLE CTF 2019 HYPE
John Hammond
SANS GirlsGoCyberStart [01] I suck at CAPTCHA
John Hammond
SANS GirlsGoCyberStart [02] You Sneaky Dog
John Hammond
SANS GirlsGoCyberStart [03] Crypto Coffee
John Hammond
BAD USER INTERFACE / UI EXPERIENCE
John Hammond
TECHNICOLOR QR CODE (Prism) InnoCTF 2019
John Hammond
MITRE CTF 2019 HIGHLIGHTS
John Hammond
HACKERS REACT: Bad Hollywood Hacking Scenes
John Hammond
Windows PowerShell [01] Introduction
John Hammond
CSAW'19 - PWN - Ret2libc w/ PWNTOOLS (baby_boi)
John Hammond
BCACTF - LISP "Thspeaking" (with SinisterMatrix!)
John Hammond
BCACTF - Bruteforcing "Basic Pass" (with SinisterMatrix!)
John Hammond
100% OSCP: Offensive Security Certified Professional
John Hammond
BCACTF "For the NIght is Dark" (with SInisterMatrix!)
John Hammond
PicoCTF 2019 HYPE - LIVE NOW!
John Hammond
x86 Assembly: Hello World!
John Hammond
OSCP - Taking Notes & Resources
John Hammond
CVE-2019-14287 SUDO Bug [under 1.8.28]
John Hammond
PicoCTF 2019 [01] Glory of the Garden (Strings Challenge)
John Hammond
PicoCTF 2019 [02] Inspector (HTML, CSS, JavaScript)
John Hammond
PicoCTF 2019 [03] The Numbers (Python Script)
John Hammond
PicoCTF 2019 [04] Warmed Up + Bash Script
John Hammond
templeos.txt.mp4.wav.psd
John Hammond
PicoCTF 2019 [05] Handy Shellcode (Pwntools)
John Hammond
PicoCTF 2019 [06] Practice Run & SSH
John Hammond
PicoCTF 2019 [07] Unzip, RE & Rot13
John Hammond
PicoCTF 2019 [08] Caesar & Client Side
John Hammond
PicoCTF 2019 [09] Logon & Vaultdoor 1
John Hammond
PicoCTF 2019 [10] Robots.txt & Metadata
John Hammond
PicoCTF 2019 [11] What Lies Within & Extensions
John Hammond
PicoCTF 2019 [12] Shark On Wire 1
John Hammond
PicoCTF 2019 [13] More Client-Side & Flags
John Hammond
A Poor Man's Pentest: Automating the Manual - BsidesDE 2019
John Hammond
DeepCamp AI