Posts

PhantomSub Campaign:Malicious npm Packages Silently Hijack WhatsApp Accounts

Image
Security researchers at OX Security, SafeDep, and Xygeni have uncovered a widespread supply-chain campaign dubbed PhantomSub. Attackers published at least 101 malicious software packages to the official npm registry—downloaded nearly 500,000 times. These packages trick developers into connecting their personal or business WhatsApp accounts (usually to build automated chatbots) and then secretly force those accounts to join WhatsApp channels, enter group chats, and broadcast unauthorized marketing links without the owner's knowledge or consent. Clear Explanation: How the Attack Works Developers often build WhatsApp automation tools or chatbots using an open-source library named Baileys. Attackers created deceptive copies (typosquatting and forks) of this original library, such as @nexustechpro/baileys or ourin-baileys. When a developer installs one of these malicious packages and scans the QR code to authenticate their WhatsApp session, the package acts normally on the surface. Howe...
Image
🐧 Linux Filesystem Demystified – From / to /var Every Linux journey starts at ( / ) the root of it all. From there, the hierarchy branches into essential directories: /bin → everyday commands /etc → system configs /home → user space /var → logs & dynamic data Think of it as the city map of Linux: each directory has its own role, and knowing the layout makes troubleshooting and system mastery way easier. /tmp is like a hotel room — don’t leave valuables there, it gets cleaned out! :) hashtag # Linux hashtag # SysAdmin hashtag # DevOps hashtag # OpenSource hashtag # FileSystem hashtag # Nepal

Case Study | Transparent Tribe (APT36) RAT Attack

Image
Transparent Tribe (APT36) RAT Attack Analyzed APT36's remote access Trojan (RAT) attacks targeting Windows users, including government and academic sectors. This case highlights the evolving tactics of state-sponsored cyber espionage and the importance of proactive threat detection and defense. More about ... #CyberSecurity #APT36 #RATAttack #ThreatAnalysis #DigitalForensics#WindowsSecurity #CyberAwareness #Nepal #Infosec #Ethical Hacking

Welcome to My Cybersecurity Research Blog

 Hello! I’m Kabin Khadka , a cybersecurity student and researcher from Nepal. On this blog I share: Ethical hacking practice Bug bounty methodology TryHackMe writeups Linux and networking tutorials Digital forensics notes Security awareness articles My goal is to learn responsibly, document my progress, and contribute to a safer digital community. — Kabin Khadka