Ian Kretz
ikretz.bsky.social
Ian Kretz
@ikretz.bsky.social
Security Research @ Datadog
My colleagues and I at @securitylabs.datadoghq.com did a deep-dive on some recently discovered malicious VS Code extensions targeting Solidity developers.

Check it out here: securitylabs.datadoghq.com/articles/mut...
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions
securitylabs.datadoghq.com
May 21, 2025 at 7:41 PM
My colleague, Sebastian Obregoso, and I had the privilege of writing a guest post for OpenSSF's blog on how we detect malicious open source packages at @securitylabs.datadoghq.com using GuardDog.

Check it out here: openssf.org/blog/2025/03...
GuardDog: Strengthening Open Source Security Against Supply Chain Attacks – Open Source Security Foundation
openssf.org
April 1, 2025 at 10:14 AM
Reposted by Ian Kretz
Interested in malicious software packages? Our open-source dataset just hit over 5,000 samples of malicious npm and PyPI packages!

github.com/DataDog/mali...
March 4, 2025 at 9:06 AM