I know it's been said thousands of times before, but as a software developer I've never felt a greater sense of job security than I do right now. The amount of work it's going to take to clean up all this slop is going to be monumental. Unfortunately, that kind of work is also soul-deadening.
post
Thanks for this write-up, I just saw the advisory and didn't realize just how dumb the entire thing was.
absolutely appalling figuring it out, it really was "it can't be this stupid, I must be understanding it wrong"
then I got to the bash injection
and the proud "Generated by Claude Code"
and welp
The malware stole a lot of people’s login keys and, apparently, their crypto wallets.
Seinfeld "Shame".gif
A pull request is when someone submits new code to a software project. On 21 August, NX added some configuration to look at the titles of pull requests and check they were correctly formatted.
I find it immensely hilarious that this security hole was blown open on my 25th birthday. Its almost poetic.
don't wanna read this, did they vibe code a crypto investment platform and deposited their own money in it?
It's like a one-and-a-half-page article that also comes in audio and video form, don't be lazy.
spoiler
They vibe coded a bash injection vulnerability in their devops code, which was used to gain access to the repo and push out a release with malicious code, which prompted any installed LLM wrappers like cursor to gather anything that looked like a configuration or text file in the infected machine and presumably leak them to the attacker.
Have a LLM summarize it for you. That fits with the article context quite nicely ;)
all 23 comments