Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ashishbijlani
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
ashishbijlani
2mo ago
I've been building an OSS tool to detect software supply-chain attacks: https://github.com/ossillate-inc/packj Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., sp
2.
▲
by
ashishbijlani
4mo ago
Built Packj [1] to audit dependencies easily from CLI. 1. Packj ( https://github.com/ossillate-inc/packj ) detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses stat
3.
▲
by
ashishbijlani
5mo ago
Built Packj [1] to do exactly this. 1. Packj ( https://github.com/ossillate-inc/packj ) detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code ana
4.
▲
by
ashishbijlani
8mo ago
This is a great initiative. Thanks for sharing! I will use it to create my personal cache of package registries (beyond obvious advantages of caching, it can also mitigate typo-squatting attacks). BTW, if there's an interest, I'd
5.
▲
by
ashishbijlani
1y ago
I’m extending Packj sandbox for agentic code execution [1]. You can specify allowlist for network/fs. 1. https://github.com/ossillate-inc/packj/blob/main/packj/sandb...
6.
▲
by
ashishbijlani
1y ago
Plug: I've been building a tool to detect software supply-chain cyberattacks: https://github.com/ossillate-inc/packj Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.
7.
▲
by
ashishbijlani
1y ago
Packj [1] detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH keys, network comm
8.
▲
by
ashishbijlani
1y ago
Plug: I've been building a similar tool: https://github.com/ossillate-inc/packj Packj uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of shell, use of SSH key
9.
▲
by
ashishbijlani
2y ago
Hi Abhishek, the backtracking feature looks super useful. Congrats on launching!
10.
▲
by
ashishbijlani
2y ago
Not for contributions only, but developing ExtFUSE [1] got me a lot of offers and consulting work. 1. https://github.com/extfuse/extfuse optimizes FUSE with eBPF
11.
▲
by
ashishbijlani
2y ago
> If the tech is open-sourced, then an attacker can keep trying in private until they find an exploit, and then use it. So you'd rather assume that if something is obscure, it is secure?
12.
▲
by
ashishbijlani
2y ago
We scan PyPI packages regularly for malware to provide a private registry of vetted packages. The tech is open-sourced: Packj [1]. It uses static+dynamic code/behavioral analysis to scan for indicators of compromise (e.g., spawning of
13.
▲
by
ashishbijlani
2y ago
This is exactly why I'm building Packj audit [1]. It detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g.,
14.
▲
by
ashishbijlani
2y ago
Good to see Packj[1] as one of the malware scanners used. 1. https://github.com/ossillate-inc/packj Packj detects malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses sta
15.
▲
by
ashishbijlani
2y ago
Plug: I’ve been building Packj [1] to detect malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, us
16.
▲
by
ashishbijlani
3y ago
I’ve been building Packj [1] to detect malicious PyPI/NPM/Ruby/PHP/etc. dependencies using behavioral analysis. It uses static+dynamic code analysis to scan for indicators of compromise (e.g., spawning of shell, use of S
17.
▲
by
ashishbijlani
3y ago
I’ve been building Packj [1] to detect such attacks. Packj can flag malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP dependencies. We use static, dynamic, & metadata analysis to scan for
18.
▲
by
ashishbijlani
3y ago
I’ve been building an open-source tool Packj [1] to detect publicly malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/me
19.
▲
by
ashishbijlani
3y ago
> For how to know you can trust a dependency, I'm afraid there is no solution: no theorem prover nor isolation, cryptography nor layerizarion can save you. I'm taking a stab at addressing this problem with Packj [1]. It carries
20.
▲
by
ashishbijlani
3y ago
Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawnin
21.
▲
by
ashishbijlani
3y ago
Cool project! Are you fetching app metadata from Google Playstore in real-time or you've cached data of all Android apps on your server already?
22.
▲
by
ashishbijlani
3y ago
Creator of Packj [1] here. How do you envision sandboxing/security policies will be specified? Per-lib policies when you've hundreds of dependencies will become overwhelming. Having built an eBPF-based sandbox [2], I anticipate th
23.
▲
by
ashishbijlani
3y ago
I’ve been building Packj [1] to detect publicly UNKNOWN dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadat
24.
▲
by
ashishbijlani
3y ago
Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata analysis to look for "suspicious” attributes such as spawnin
25.
▲
by
ashishbijlani
3y ago
Good to see more attempts at analyzing dependencies for malware. Plug: we've been building Packj [1] to detect malicious Python/NPM/Ruby/Rust/Java/PHP packages. It carries out static/dynamic/metadata
26.
▲
by
ashishbijlani
3y ago
I've been building Packj [1] to detect exactly such attacks. It can flag dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages by carrying out static
27.
▲
by
ashishbijlani
3y ago
I've been building Packj [1] to detect dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis a
28.
▲
by
ashishbijlani
3y ago
Thanks! We need more such efforts to improve supply-chain security of open-source software. Packj detects typo-squatting (impersonation) as well.
29.
▲
by
ashishbijlani
3y ago
I've been building Packj [1] to detect dummy, malicious, abandoned, typo-squatting, and other "risky" PyPI/NPM/Ruby/PHP/Maven/Rust packages. It carries out static/dynamic/metadata analysis a
30.
▲
by
ashishbijlani
3y ago
Makes sense. When I read your notes, it appeared that you wanted to run untrusted code on a backend server.
More ›