Example Usage
┌─────────────────────────────────────────────────────────────────┐ │ ATTACK FLOW DIAGRAM │ ├─────────────────────────────────────────────────────────────────┤ │ │ │ 1. npm install 2. preinstall hook 3. Download │ │ ───────────────► ─────────────────────► ──────────────────► │ │ setup_bun.js Bun runtime │ │ │ │ 4. Execute payload 5. Credential theft 6. Exfiltrate │ │ ───────────────────► ──────────────────► ─────────────────► │ │ bun_environment.js TruffleHog scan GitHub repos │ │ │ │ 7. Self-propagate 8. Create runner 9. Destroy │ │ ────────────────────► ─────────────────► ─────────────────► │ │ Infect 100+ pkgs "SHA1HULUD" Wipe on failure │ │ │ └─────────────────────────────────────────────────────────────────┘
See also
Interactsh
Open Source
Out-of-band interaction gathering server. Generates unique collaboration URLs for detecting blind vu…
UltimateCMSWordlists
Open Source
📚 An ultimate collection wordlists of the best-known CMS…
BurpAPISecuritySuite
Open Source
Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzi…
cbrutekrag
Open Source
Penetration tests on SSH servers using brute force or dictionary attacks. Written in C.…
AD-Attacks-by-Service
Open Source
Active Directory Penetration Testing for Red Teams…
A-Red-Teamer-diaries
Free
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional enga…