NPM Crypto Malware "Cute Boi" Is Turning PC's Into XMRRigs

  Рет қаралды 77,462

Mental Outlaw

Mental Outlaw

2 жыл бұрын

In this video I discuss the Cute Boi malware campaign that is creating thousands of malware packages in NPM and tricking devs into mining Monero for the hacker.
Save money on VPS hosting with Vultr.
www.vultr.com/?ref=8791233
₿💰💵💲Help Support the Channel by Donating Crypto💲💵💰₿
Monero
45F2bNHVcRzXVBsvZ5giyvKGAgm6LFhMsjUUVPTEtdgJJ5SNyxzSNUmFSBR5qCCWLpjiUjYMkmZoX9b3cChNjvxR7kvh436
Bitcoin
3MMKHXPQrGHEsmdHaAGD59FWhKFGeUsAxV
Ethereum
0xeA4DA3F9BAb091Eb86921CA6E41712438f4E5079
Litecoin
MBfrxLJMuw26hbVi2MjCVDFkkExz8rYvUF
Dash
Xh9PXPEy5RoLJgFDGYCDjrbXdjshMaYerz
Zcash
t1aWtU5SBpxuUWBSwDKy4gTkT2T1ZwtFvrr
Chainlink
0x0f7f21D267d2C9dbae17fd8c20012eFEA3678F14
Bitcoin Cash
qz2st00dtu9e79zrq5wshsgaxsjw299n7c69th8ryp
Etherum Classic
0xeA641e59913960f578ad39A6B4d02051A5556BfC
USD Coin
0x0B045f743A693b225630862a3464B52fefE79FdB
Subscribe to my KZbin channel goo.gl/9U10Wz
and be sure to click that notification bell so you know when new videos are released.

Пікірлер: 261
@excidium_
@excidium_ 2 жыл бұрын
Would have been more interesting if the hacker was at least using some algorithm to generate misspelled names of major packages instead of just random strings
@dcode863
@dcode863 2 жыл бұрын
yea for sure
@sarcophiIus
@sarcophiIus 2 жыл бұрын
indeed
@shapelessed
@shapelessed 2 жыл бұрын
Don't give them ideas... ._.
@abrvalg321
@abrvalg321 2 жыл бұрын
Cute grill would have been better.
@purplevincent4454
@purplevincent4454 2 жыл бұрын
​@@shapelessed they don't need ideas, it's basic shit. Also this is likely just practice, random prank project, or other.
@thingsiplay
@thingsiplay 2 жыл бұрын
The bot didn't even try to hide it's a bot. Names are random letters for user and the project. And all project versions are the same. I am amazed at how much effort they gone through to do this and then fail on basic things like naming.
@dot.4069
@dot.4069 2 жыл бұрын
yeah, i thought the same. Maybe they had an easy way to get all these accounts, that would explain stupid mistakes
@pathikghugare
@pathikghugare 2 жыл бұрын
Maybe it's just some bunch of college students who learnt about selenium 🤭
@chargemannyn2918
@chargemannyn2918 2 жыл бұрын
might just be a proof of concept/stress test to see if it’s possible.
@AnotherSkyTV
@AnotherSkyTV 2 жыл бұрын
Yeah, wondering too... Why someone would install these packages?
@thingsiplay
@thingsiplay 2 жыл бұрын
@@chargemannyn2918 If that was the case, then why has it malicious code in it? I think this is more than just a concept or testing. Because once this is detected, then alarm goes on and they would make it much harder to do it properly next time.
@Metruzanca
@Metruzanca 2 жыл бұрын
Typescript developer here. I have no clue why anyone would install a random package. I can see mispellings being an issue, something like raect (Holy, thats a real package and its an innocent troll package that yells at you for mispelling react) Supply chain attacks are also a much bigger issue. But "huaerwghagiyu" seems a bit of a stretch. 41 downloads for the malware packages seems kinda scary that people are downloading it considering Raect is sitting at a very consistent 22.
@Nicolas-qc3jf
@Nicolas-qc3jf 2 жыл бұрын
Misspelling the package name is a reason why.
@luukvanoijen7082
@luukvanoijen7082 2 жыл бұрын
@@Nicolas-qc3jf is reading a little difficult for you by any chance? just wondering
@BakelitTV
@BakelitTV 2 жыл бұрын
Typescript developer here
@your-mom-irl
@your-mom-irl 2 жыл бұрын
@@BakelitTV i develop typescript btw
@pacifico4999
@pacifico4999 2 жыл бұрын
Those few downloads could just be mirrors, not real people.
@stage6fan475
@stage6fan475 2 жыл бұрын
Well we can celebrate youtube hasn't penalized Mental Outlaw in a while. Great content.
@erincarson8998
@erincarson8998 2 жыл бұрын
As far as we know.
@5555Jacker
@5555Jacker 2 жыл бұрын
If they ever do, there's always Odysee.
@ghoulbuster1
@ghoulbuster1 2 жыл бұрын
Mental did nothing wrong.
@Weasel_Squeezer
@Weasel_Squeezer 2 жыл бұрын
Reminds me of when I made a Selenium bot to snipe tickets on Eventbrite for personal use only because I wanted to go to popular events that sold out in seconds many years ago. I also built in a ReCaptcha solver using cheap services like DeathByCaptcha that employ real people to solve the captchas from the images and prompts you send them. It worked extremely well. Far better than I needed. I ended up securing spots for over a dozen tickets since I was running many instances in parallel, but I only bought 2 because I'm not a filthy scalper.
@da-voodoo-shuffle
@da-voodoo-shuffle 2 жыл бұрын
With great power comes great responsibility. Uncle Ben would be proud of you
@WitchMedusa
@WitchMedusa 2 жыл бұрын
EEEEEEE UNCLE BEN IS SO NICE
@celestialsylveon6453
@celestialsylveon6453 2 жыл бұрын
Apparently the malware isn't even configured right and the miner isn't active I read, so the attackers literally gain nothing other than maybe a testing stage
@ichigonixsun
@ichigonixsun 2 жыл бұрын
How is this even a serious threat? Like, who the fuck installs a package named "yqsduvkzbpcienfg", published 9 days ago by some sussy user, without any collaborators, literally linking to a cryptominer repository?
@stage6fan475
@stage6fan475 2 жыл бұрын
That was my question too.
@wrath_666
@wrath_666 2 жыл бұрын
The chances are low, bur never zero.
@da-voodoo-shuffle
@da-voodoo-shuffle 2 жыл бұрын
Bruh! That's my favourite package. Next to "dheusudhfdjhxs" which does a great job at rendering graphics
@no-better-name
@no-better-name 2 жыл бұрын
@@da-voodoo-shuffle it'll be doing some GPU work alright
@jamescrock2213
@jamescrock2213 2 жыл бұрын
when I was extremely high off pcp, the things that I managed to get on my pc through not have a frontal cortex was incredible. I believe i got my monero wallet hacked that way, which I used to purchase Goods, and when you are in deep yqsduvkzbpcienfg just makes sense
@user-pf2qm5je3r
@user-pf2qm5je3r 2 жыл бұрын
xmr getting free pen testing while also pushing hacking forward because it incentivizes people to find new and creative ways to turn systems into miners. what a chad coin
@gianni50725
@gianni50725 2 жыл бұрын
javascript and its consequences have been a disaster for the human race
@zyansheep
@zyansheep 2 жыл бұрын
Based
@nodge9671
@nodge9671 2 жыл бұрын
this happens with any package manager for multiple languages there's similar shit for python & even rust the thing with javascript is popularity.
@glory8500
@glory8500 2 жыл бұрын
@@nodge9671 python just sucks
@glory8500
@glory8500 2 жыл бұрын
javascript*, my brain is rotitng
@gianni50725
@gianni50725 2 жыл бұрын
@@nodge9671 yea i know, i just like shitting on it. it's attracted a pretty terrible community overall, though. you cant deny that JS has issues with its community rebuilding the wheel and packaging trivial things, which no other language community does to nearly the same extent. not to mention the language itself is horrendously designed, but theres been a lot of spilled ink regarding that already.
@aesthesia5023
@aesthesia5023 2 жыл бұрын
New and Rookie developers are going to be affected like this. By installing packages locally, keeping safe versioning and checking dependencies before deploying versions is enough to keep yourself safe. btw fuck Microsoft even more. Owning Github and npm and doing absolutely anything.
@paegr
@paegr 2 жыл бұрын
I wouldn’t be shocked to hear that a few Microsoft gnomes are directly profiting from this
@patterntrader690
@patterntrader690 2 жыл бұрын
How? Nobody’s going to install something like this. Unless he starts renaming the packages to something convincing
@CreativeBuilds
@CreativeBuilds 2 жыл бұрын
@@patterntrader690 there are bots which download new packages and test them, think its more likely the hacker is targeting these bots
@N.S.A.
@N.S.A. 2 жыл бұрын
They stole my burner account username.
@pencilcase8068
@pencilcase8068 2 жыл бұрын
Lucky, I am starting to use my burner accounts way more because I don't like spreading my personal accounts all over the internet. Only personal things like my university communications get those accounts now
@2DEKAY
@2DEKAY 2 жыл бұрын
Didn't you just dox your burner? 😱🤣
@Bwaitforitjones
@Bwaitforitjones 2 жыл бұрын
Thank God they didn't get mine "CuteBoi69"
@pencilcase8068
@pencilcase8068 2 жыл бұрын
@@2DEKAY doesn't matter, people usually have 3 burners
@downylithe
@downylithe 2 жыл бұрын
@@pencilcase8068 that's extremely specific Edit: I just realized I have 3 lol
@Darthborg
@Darthborg 2 жыл бұрын
I really like your content. More onion security etc videos and history is always my favorite topics and current exploits.
@TheDolphinTuna
@TheDolphinTuna 2 жыл бұрын
You should talk about how half of Canada's wireless internet coverage was down today (and is still down) because Rogers screwed something up. People even had problems calling emergency services and stuff. Crazy.
@kexec.
@kexec. 2 жыл бұрын
Canada was the country?
@wrath_666
@wrath_666 2 жыл бұрын
My condolences to the people that were unfortuneately born in Canada. 🇨🇦
@window.location
@window.location 2 жыл бұрын
mutahar will cover, probably Edit: he did
@purplep3466
@purplep3466 2 жыл бұрын
I smell Turdeau
@doooofus
@doooofus 2 жыл бұрын
on my feed it just showed "NPM Crypto Malware "Cute Boi" Is Turning PC's Into" and my brain just assumed with the thumbnail that thelast word would be "femboys" idek why lol
@wrath_666
@wrath_666 2 жыл бұрын
Help, my PC turned into a femboy!
@javaguru7141
@javaguru7141 2 жыл бұрын
femboys on the mind...
@somesalmon5694
@somesalmon5694 2 жыл бұрын
Thank you for your incredible coverage!
@KotleKettle
@KotleKettle 2 жыл бұрын
My favorite News anchorman
@pentestical8265
@pentestical8265 2 жыл бұрын
The packages aren't even really malicious, it's just a cloned cryptomining library which does nothing by itself.. Installing the package doesn't execute anything and you need to import and configure the cryptominers to mine for you and to an address you want... It's a mining library not malware itself, I have no idea why this is getting any attention.
@Sebastian-hg3xc
@Sebastian-hg3xc 2 жыл бұрын
4:00 I have to strongly disagree. Email verification codes aren't a security feature to prevent mass creation of accounts. You need email verification to prevent people from creating accounts on behalf of other people, to verify that this account's email address actually belongs to the email address owner.
@anon_y_mousse
@anon_y_mousse 2 жыл бұрын
In so far as it slows them down, it works, but it doesn't prevent them. You can still mass create email accounts and verify all day long with automation. It's just an extra step that maybe cuts their "productivity" in half.
@MagicGonads
@MagicGonads 2 жыл бұрын
very critical point!
@camelotenglishtuition6394
@camelotenglishtuition6394 2 жыл бұрын
Javascript, the gift that keeps on giving .
@williams4000
@williams4000 2 жыл бұрын
What I don’t understand is how these packages are even getting installed like who wants to download these weirdly named packages.
@wrath_666
@wrath_666 2 жыл бұрын
The chances are low, but never zero.
@kefpull6676
@kefpull6676 2 жыл бұрын
Probably those security bots that check packages for viruses, I guess
@rolodexter
@rolodexter 2 жыл бұрын
Awesome coverage !!
@mihaelkYeah
@mihaelkYeah Жыл бұрын
I like your usage of twink Wojak as an alternative for "Cute Boi".
@gnulifestyle7741
@gnulifestyle7741 2 жыл бұрын
Software is very vulnerable by itself. For example, I have a production app with ~12 dangerous vulnerabilities in packages according to npm audit. That makes me thinking like "oh, there must be a lot more vulnerabilities, but people don't know about them yet." That's scary :/
@0x007A
@0x007A 2 жыл бұрын
You should resolve those vulnerabilities prior to pushing the application to production.
@gnulifestyle7741
@gnulifestyle7741 2 жыл бұрын
@@0x007A yeah, but there are like ~10 users including myself and the app is going to die in a couple of month anyway, so this isn't worth fixing
@Dylyinyang
@Dylyinyang 2 жыл бұрын
6:04 got tagged as sponsored and skips. Thanks sponsorblock
@biggs.c249
@biggs.c249 2 жыл бұрын
best content creator rn dood
@llortaton2834
@llortaton2834 2 жыл бұрын
I have a display indicating at all time the amount of power used by all of my computers, this case scenario is impossible for me. I'm really happy with my UPS, like a sentinel watching my power usage.
@edwardtan1354
@edwardtan1354 2 жыл бұрын
this reminds me of the "store names" at lazada being just a random string of hexadecimal characters
@morphsuitmeele1171
@morphsuitmeele1171 2 жыл бұрын
Man seeing all these crypto malware's pop up really makes a guy want to jump into the hot market, ya know? So, how would one go about making these? asking for a friend.
@cat-le1hf
@cat-le1hf 2 жыл бұрын
Get a trojan. Add mining software. Done
@tissuepaper9962
@tissuepaper9962 2 жыл бұрын
You pay somebody else to write the malware and focus on the logistics and the not-getting-caught, which is the actual hard part.
@almaefogo
@almaefogo 2 жыл бұрын
​@@tissuepaper9962 This guy knows. Hey FBI its the guy in the black hoodie with the anonymous mask
@mntmntmnt
@mntmntmnt 2 жыл бұрын
@@almaefogo its the hacker called 4chan
@modables
@modables 2 жыл бұрын
@@mntmntmnt b4yuh later 6 3t TV eat t7yfiuhtg guygbrhh hedfhcing wild dude
@Nerdilicious
@Nerdilicious 2 жыл бұрын
"Free pen test" lmao
@sammyslepack
@sammyslepack 2 жыл бұрын
Adding on to what you said about temp mail services: people can also create something called a catchall domain. Basically, any email sent to that domain will be forwarded to another email. In my opinion this is like 3 times as powerful as a temp mail service. Edit: forgot to mention I have my own personal catchall domain which I use for myself.
@gridlocdev2023
@gridlocdev2023 2 жыл бұрын
2:49 Reddit does have a serious bot problem at the moment too if you're interested, basically there's a huge ring of bot accounts that repost highly upvoted things from the past on a subreddit (or even from related subreddits) and once they've accrued enough karma to be valuable are supposedly sold to buyers
@reverselunatic
@reverselunatic 2 жыл бұрын
I saw "rydlmepk" in the start of the package name and thought the bot had some clever algorithm to name everything a shorthand for "riddle me package" which would have been a pretty clever and cryptic series of fake package names. Then I saw the bot's name.
@owensthethird
@owensthethird 2 жыл бұрын
I’ve watched several ads just for this video to not load. KZbin has no problem pushing out an ad on a device or video that is unable to deliver. Anyway, enjoy the ad revenue.
@LoveBbyJay
@LoveBbyJay 2 жыл бұрын
The cat that walked across the keyboard is a pretty 'Cute Boi'
@Ginger_FoxxVT
@Ginger_FoxxVT 2 жыл бұрын
Thank you
@snowcloudshinobi
@snowcloudshinobi 2 жыл бұрын
here comes cuteboi, oh shit waddup.
@echo5394
@echo5394 2 жыл бұрын
based
@catcatcatcatcatcatcatcatcatca
@catcatcatcatcatcatcatcatcatca 2 жыл бұрын
Having your malware in a public repo seems like a way to hide your tracks. But if it then pulls the xmrig from elsewhere the utility seems limited. I assume this exists to bypass some poorly planned behavioural check
@Hyperboid
@Hyperboid 2 жыл бұрын
Can't wait for Fireship to make a video about ulfntrthgntashnnpekv
@evangelosraptis5486
@evangelosraptis5486 2 жыл бұрын
It seems like every other day a malicious package in npm is discovered
@tibettenballs4962
@tibettenballs4962 2 жыл бұрын
one of my first bots were built on selenium to scrape bestbuy gpus. worked flawlessly, but im a broke college student and profit went to weed and the script (java, btw) burned in hell like cartman when he ate chitty food from chitty city.
@Kakerate2
@Kakerate2 2 жыл бұрын
burned? wym? i could use that script tbh lol throw it my way
@tibettenballs4962
@tibettenballs4962 2 жыл бұрын
@@Kakerate2 lol, gpu prices are shvt. anyway, writing bots are really simple. as a special offer (in honor of lord Mental Outlaw), I will listen in on this chat, and will answer any questions pertinant to swift(uikit), java(ee/boot) and python. alot of youtuber sell their service ^. BUT i will be here, just for you. and perhaps M.O too. just.. do not ask me about .js.
@sultanhanga
@sultanhanga 3 ай бұрын
​@@tibettenballs4962what's is great project for student that is intrasted in this
@sultanhanga
@sultanhanga 3 ай бұрын
​@@tibettenballs4962python project?
@AntiWanted
@AntiWanted 2 жыл бұрын
Nice
@bren.r
@bren.r 2 жыл бұрын
Until we start using exact version numbers, it’s easy for things to leak in like this so easily. Don’t bother with the whole lock file argument. It always gets overwritten during merge conflicts and defeats the purpose of it in the first place.
@Sv5YpWTwd9otTA4So83f
@Sv5YpWTwd9otTA4So83f 2 жыл бұрын
I doubt any actual NPM users are installing these packages. It's probably just automated npm security testing tools installing this garbage. If that adds enough processing power to the pool to justify uploading the nonsense packages in the first place, then more power to them.
@justonefra
@justonefra 2 жыл бұрын
I think they are abusing some kind of automated repository testing service to make it run the monero mining rig on their servers instead of targeting end users
@theWebmasterify
@theWebmasterify 2 жыл бұрын
Honestly, this does not look like a serious attack, but more like a proof of concept. If anything, this just highlighted the naiveness of NPM by not implementing any form of captcha. It also shows to be always suspicious of packages and to ask oneself if the package is really needed. And for people who shit on NPM because „duh Microsoft“, this shit can happen to any central package registry like pip or cargo.
@draken5379
@draken5379 2 жыл бұрын
Very rarely happens with rails gems, if ever. Its the reason most ppl still use rails over all the new fancy backends.
@0x007A
@0x007A 2 жыл бұрын
There is absolutely no oversight by the corporate owner of the repository, namely Microsoft Corporation. I might return to vanilla JavaScript.
@nikos4677
@nikos4677 2 жыл бұрын
Honestly as i devi would not like to solve 100 caprchas just to install node modules froma repo. Capcthas are stupid
@0x007A
@0x007A 2 жыл бұрын
@@nikos4677 Agreed. Captchas do not solve a problem, they create another problem.
@MartijnMols
@MartijnMols 2 жыл бұрын
can you make a video on Samsung suddenly investing heavily in privacy (and marketing that). I got a lot of advertisements from Samsung about privacy the last couple days.
@phycodelix4209
@phycodelix4209 2 жыл бұрын
I'm early
@proxies
@proxies 2 жыл бұрын
You just need to just alias forwarding catchall with google domains. 10$ domain per year unlimited forwarding and no need to go thru hosting just 5 clicks
@hugohom2280
@hugohom2280 2 жыл бұрын
gotta give it to the for mining the third best crypto out there!
@tissuepaper9962
@tissuepaper9962 2 жыл бұрын
What are 1 and 2 by your estimation?
@hugohom2280
@hugohom2280 2 жыл бұрын
@@tissuepaper9962 1 btc 2 ergo 3 xmr and 4 ada
@FunctionGermany
@FunctionGermany 2 жыл бұрын
i don't understand this scheme. how would any developer download any of these packages?
@zackjohnston-watson4874
@zackjohnston-watson4874 2 жыл бұрын
Can you make a video on making your own email domain?
@gordonzar992
@gordonzar992 2 жыл бұрын
It is used likely for dependency injection ala node-ipc and the peacenotwar malware
@OneOfThePetes
@OneOfThePetes 2 жыл бұрын
XMR rig is legit. It's a shame that it get used this way.
@WitchMedusa
@WitchMedusa 2 жыл бұрын
At least the Monero network is becoming more secure, as long as their keeping the utilization down I don't think it matters as most people wont notice it & it helps us. If hundred hackers good made Monero mining botnets it could quickly outpace even the US governments ability to afford a 51% attack. So these hackers are at least doing the right thing for the wrong reasons.
@Tim_Apple
@Tim_Apple 2 жыл бұрын
No cap this is NOT bussin. Fr fr
@PenguinCrayon269
@PenguinCrayon269 2 жыл бұрын
Seriously, who's gonna install random named package. if it does name squatting it'd make sense.
@40nights40daystv
@40nights40daystv 2 жыл бұрын
So can I turn all the computers in my public library into XMR rigs?
@David-ck4ep
@David-ck4ep 2 жыл бұрын
Lmao
@piguyalamode164
@piguyalamode164 2 жыл бұрын
If I am to guess, the plan for these is to add them into dependencies for more legitimate looking packages.
@AnotherSkyTV
@AnotherSkyTV 2 жыл бұрын
Yeah, I was wondering about that too... Maybe? Makes more sense than someone just downloading this random letter crap directly
@errorhandler812
@errorhandler812 2 жыл бұрын
They can do same thing as pacman -V|base32|head-1 does in npm
@psps8030
@psps8030 2 жыл бұрын
cuteboi, fenboi.
@toofle
@toofle 2 жыл бұрын
uhooo twink malware lose all money!! :sob:
@draken5379
@draken5379 2 жыл бұрын
These sorts of things just keep putting the node etc ecosystems back years. JS devs keep giving ppl more reasons to keep using rails etc and other proven out ecosystems.
@guidobit
@guidobit 2 жыл бұрын
Give me one good reason to why this wouldn't be possible in any other ecosystem.
@nikos4677
@nikos4677 2 жыл бұрын
type script haters =🤓
@Kalphalus
@Kalphalus Ай бұрын
I agree that you could use XMR yourself, I used to use XMR, and I no longer do
@AnimeGIFfy
@AnimeGIFfy 2 жыл бұрын
how? how can someone willingly download a random package like that? maybe all the downloads are from the person who uploaded them
@noyukikun
@noyukikun 2 жыл бұрын
and they couldnt go after people actually mining crypto on there mining rigs this saddens me xD
@gaminggamingtm
@gaminggamingtm 2 жыл бұрын
Bogus
@gilgabro420
@gilgabro420 2 жыл бұрын
why would anyone Download thoes packages?
@AcidiFy574
@AcidiFy574 2 жыл бұрын
remember that the new devs crap on PHP & use NodeJS 🤣 well........ I was wondering if there was a "Monero's version" of Smart-Contracts & what do you guys think of "Ergo-cryptocurrency"
@chukwu_9
@chukwu_9 2 жыл бұрын
Yea u can make selenium look really human
@victorpinasarnault9135
@victorpinasarnault9135 2 жыл бұрын
Just after the 'crypto crash'.
@BobbyPhoenix
@BobbyPhoenix 2 жыл бұрын
How do these bad hackers have no morals, no ethics, no integrity? They're all going to rot in hell, and I will be cheering them on as they're burning. Just because you can do something does not mean you should do it.
@tissuepaper9962
@tissuepaper9962 2 жыл бұрын
"The software is provided AS-IS"
@BobbyPhoenix
@BobbyPhoenix 2 жыл бұрын
@@tissuepaper9962 what is that supposed to mean? No matter what software or hardware comes as is it's still up to user to be responsible and not do anything illegal or negative against other people. I'm not missing anything at all. Just because you can do something doesn't mean you should do something. I can knock on my neighbor's door and when they open the door I could force myself in and take all their stuff but I don't because it's not right. There's no difference with having computer code written in a way that can be taken advantage of. Just don't do it because it's not right.
@tissuepaper9962
@tissuepaper9962 2 жыл бұрын
@@BobbyPhoenix what it's supposed to mean is that it's your own friggin fault that you downloaded and ran malicious code without thinking about it or doing any investigation into whether it was legit. Don't use random packages that nobody else uses (and hardcode your version numbers), and then you won't have to worry about supply chain attacks. You don't just open your door without looking through the peephole, do you?
@BobbyPhoenix
@BobbyPhoenix 2 жыл бұрын
@@tissuepaper9962 I understand.
@anon_y_mousse
@anon_y_mousse 2 жыл бұрын
I couldn't get the video to play through the browser at all, just more FF bashing by YT as they still refuse to let me have 1080p. Chromium based browsers on the other hand get all kinds of options and no other site seems to treat FF like a second class citizen. In other words, I haven't found a single other site that has 1080p and prevents me from selecting that option.
@PartyhatRS
@PartyhatRS 2 жыл бұрын
Ashociated lmaoooooooo
@Cheatrunner
@Cheatrunner 2 жыл бұрын
First
@aryanmn1569
@aryanmn1569 2 жыл бұрын
it's scary how easy it is to make this wayyyy more effective, tbh, I have some good ideas for it 😂😂😂
@boner4098
@boner4098 2 жыл бұрын
Boy do be cute tho
@SmoltingWassie
@SmoltingWassie 2 жыл бұрын
How could your regular down in the dumps and desperate man take advantage of this and pull off the scam himself plz ser
@CoolGuy12_
@CoolGuy12_ 2 жыл бұрын
Huge darknet seller caught - Simon Barclay - please do a video
@just-mees
@just-mees 2 жыл бұрын
Hey~ I'm a pretty cute bo- *dies*
@mac1991seth
@mac1991seth 2 жыл бұрын
Installing random packages is one thing, installing this type of random packages is on another whole new level of stupid.
@CNWPlayer
@CNWPlayer 2 жыл бұрын
AHEM. It's one thousand (no and) twenty seven, not one thousand AND twenty seven.
@pelic9608
@pelic9608 2 жыл бұрын
Selenium? For this? Either China needed a PoC yesterday or this is some script kiddy. Using selenium to automate signups screams: "What are HTTP headers? That's too hard..." 😄
@kadensharpin2156
@kadensharpin2156 2 жыл бұрын
This is not an issue right now. No one would install shshdhdkkfeha and there's no README. However, I can see this being an issue in the future if they pair actual code with this miner.
@AnotherSkyTV
@AnotherSkyTV 2 жыл бұрын
Someone has been reading view/like botting threads on my fav spammer forum, apparently (hence the selenium, heheh)
@EasyMoney322
@EasyMoney322 2 жыл бұрын
You dont even need to pay for mail, since you only need it for registration. There are many free 1/5-min-mails and they are not even blocking these. Capchas are also already automated. Precautions: "Don't install random NPM packages with random symbols in name" - Are you seriosly thinking that NodeJS developer would install random packages without a reason and without reviewing its code?
@jawalo2kthelast140
@jawalo2kthelast140 2 жыл бұрын
Dont think end users downloading this is the end goal. just a payload vehicle to make it look legit.
@pioni2
@pioni2 2 жыл бұрын
How about adding a small payment when registering a new account? Having to pay $10 each time when creating these fake accounts would get costly really quickly.
@Cookiekeks
@Cookiekeks 2 жыл бұрын
Who would want to pay 10$ just to create an account
@flouride
@flouride 2 жыл бұрын
would you want to pay 10$ for every social media,
@kefpull6676
@kefpull6676 2 жыл бұрын
Unreasonable. One of the primary reasons this is being used is _because_ it’s free
@ammyvl1
@ammyvl1 2 жыл бұрын
serves em' right for using npm
@malcolmseigmiller1622
@malcolmseigmiller1622 2 жыл бұрын
Thank God I just use PHP
@XX-kq8kv
@XX-kq8kv 2 жыл бұрын
what is an npm package
@KlMJONG-UN
@KlMJONG-UN 2 жыл бұрын
Bro??
@XX-kq8kv
@XX-kq8kv 2 жыл бұрын
@@KlMJONG-UN i’m a noob be kind
@KlMJONG-UN
@KlMJONG-UN 2 жыл бұрын
@@XX-kq8kv Npm = node package manager Node is node.js Js is javascript Javascript is a language
@XX-kq8kv
@XX-kq8kv 2 жыл бұрын
@@KlMJONG-UN oh word ty
@blackneos940
@blackneos940 2 жыл бұрын
Good thing I use Visual Basic. Chumps.
@David-ck4ep
@David-ck4ep 2 жыл бұрын
Visual basic...
@dontbemadsunshine
@dontbemadsunshine 2 жыл бұрын
Wait, mental outlaw.... Did you know not Instagram bots exist? Go on any popular celebrity, their most recent post (in the last hour for example) will have a random bot saying something random totally unrelated to the post... But it will appear at the top because they'll have bots like it that post hahahaha. And on their profile it will have a link to phish 😁
@prawny12009
@prawny12009 4 ай бұрын
Why not just make a free game or something that utilises a % of system resources and declare what you are doing to the end user as a support/donation. If it becomes popular you get more compute power.
@maximus8905
@maximus8905 2 жыл бұрын
good thing I'm not a webshît dev
@immameme
@immameme 2 жыл бұрын
Imma1st
@Levi_OP
@Levi_OP 2 жыл бұрын
*PCs
@Ratzfourtyfour
@Ratzfourtyfour 2 жыл бұрын
lol's
@rtg5881
@rtg5881 2 жыл бұрын
Btw regarding phone numbers: I dont have a phone.r Ive been warning about them tracking you since nokia bricks where a thing. Sure, the best those could do was a very rough area from triangulating you in relation to a few towers... Buuuuut im a millenial, smartphones are for boomers cause they didnt grow up with a PC. If ive got a PC what do i need a smartphone for? If i dont have to be constantly reachable, what do i need a mobile phone for?
@smiley_1000
@smiley_1000 2 жыл бұрын
So was anyone actually affected by this? Looks like a complete nothing burger.
@SagaciousBoothe
@SagaciousBoothe 2 жыл бұрын
That's not a bot, it's just Welsh...
@regnadsivog8950
@regnadsivog8950 2 жыл бұрын
Imagine installing something on your computer programmed by Asians (china, India), the absolute state of this world.
@zweitekonto9654
@zweitekonto9654 2 жыл бұрын
Holy shit i started learning nodejs yesterday only.
@ansonx10
@ansonx10 2 жыл бұрын
XMRig = XMRRig LULW
The King Of Malware is Back
19:27
John Hammond
Рет қаралды 190 М.
3 Levels of WiFi Hacking
22:12
NetworkChuck
Рет қаралды 1,7 МЛН
Amazing weight loss transformation !! 😱😱
00:24
Tibo InShape
Рет қаралды 56 МЛН
Despicable Me Fart Blaster
00:51
_vector_
Рет қаралды 26 МЛН
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 17 МЛН
Bad OPSEC - How The Feds Traced a Monero User
13:55
Mental Outlaw
Рет қаралды 508 М.
Detect Hackers & Malware on your Computer (literally for free)
16:38
The EU's Pursuit of Digital Sovereignty
10:53
Mental Outlaw
Рет қаралды 131 М.
ROCKET that LITERALLY BURNS WATER as FUEL
19:00
Integza
Рет қаралды 1,5 МЛН
How do hackers hide themselves? - staying anonymous online
11:55
Grant Collins
Рет қаралды 1,4 МЛН
The Secret step-by-step Guide to learn Hacking
14:42
LiveOverflow
Рет қаралды 3,3 МЛН
How Tor Users Get Caught By Saying Too Much
13:41
Mental Outlaw
Рет қаралды 457 М.
Best Virus Removal Tools: Cleaning a deeply infected system
8:31
The PC Security Channel
Рет қаралды 844 М.
Why Certs Are Better Than Degrees For Working in IT
11:34
Mental Outlaw
Рет қаралды 143 М.
Stop Using Tor With VPNs
11:41
Mental Outlaw
Рет қаралды 795 М.
Cheapest gaming phone? 🤭 #miniphone #smartphone #iphone #fy
0:19
Pockify™
Рет қаралды 4,3 МЛН
BEKMOBILDA Tecno Camon 30 smartfoni🔥🤩 #bekmobil
1:01
Bekmobil shorts
Рет қаралды 2,3 МЛН
Копия iPhone с WildBerries
1:00
Wylsacom
Рет қаралды 7 МЛН