Skip to content

This open-source project tracks RED-LILI's activity over time as there are evidence the actor is still active. All information provided here is intended for research purposes.

Notifications You must be signed in to change notification settings

GuyNachshon/red-lili

This branch is 7 commits ahead of, 2 commits behind Checkmarx/red-lili:master.

Folders and files

NameName
Last commit message
Last commit date

Latest commit

49391ca · Sep 28, 2022

History

30 Commits
Apr 22, 2022
May 9, 2022
Apr 18, 2022
Apr 22, 2022
May 9, 2022
Apr 16, 2022
Apr 16, 2022
Apr 16, 2022
May 9, 2022
May 24, 2022
Apr 16, 2022
Apr 16, 2022
May 9, 2022
May 9, 2022

Repository files navigation

illustration

RED-LILI is a software supply chain threat actor which has published over 1500 malicious packages. As Checkmarx uncovered, this attacker has demonstrated new techniques that power him with automated NPM account creation.

This open-source project tracks RED-LILI's activity over time as there are evidence the actor is still active. All information provided here is intended for research purposes.

Visit https://red-lili.info

Sample files

The original package evidence sample files as they were originally published to NPM included with related metadata are available in the ./samples directory. Make sure to read the README.md file before usage.

About

This open-source project tracks RED-LILI's activity over time as there are evidence the actor is still active. All information provided here is intended for research purposes.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Vue 97.6%
  • JavaScript 1.1%
  • Other 1.3%