frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Tool to detect malware left behind after patching CVE-2025-55182

3•Just_Clive•15h ago
I'm Clive, a developer from South Africa. Four days ago, Eduardo Borges posted about getting hacked through CVE-2025-55182 (the React Server Components RCE). His server was patched, but the malware stayed, crypto miners, fake services named "nginxs" and "apaches", cron jobs for persistence. CPU at 361%. Part of a 415-server botnet.

That's when I realized: patching removes the vulnerability, but not the infection.

I built NeuroLint originally as a deterministic code transformation tool for React/Next.js (no AI, just AST-based fixes). When this CVE dropped, I added Layer 8: Security Forensics.

It scans for 80+ indicators of compromise: - Suspicious processes (high CPU, random names, fake services) - Malicious files in /tmp, modified system binaries - Persistence mechanisms (cron jobs, systemd services, SSH keys) - Network activity (mining pools, C2 servers) - Docker containers running as root with unauthorized changes - Crypto mining configs (c.json, wallet addresses)

Try it: npm install -g @neurolint/cli neurolint security:scan-breach . --deep

No signup required. Works on Linux/Mac. Takes ~5 minutes for a deep scan.

What's different from manual detection: - AST-based code analysis (detects obfuscated patterns) - 80+ behavioral signatures vs. 5-10 manual grep commands - Automated remediation (--fix flag) - Timeline reconstruction showing when breach occurred - Infrastructure-wide scanning (--cidr flag for networks)

The tool is deterministic (not AI). Same input = same output every time. Uses Babel parser for AST transformation with fail-safe validation - if a transformation fails syntax checks, it reverts.

Built it in 3 days based on Eduardo's forensics and other documented breaches. Already found dormant miners in test environments.

GitHub: https://github.com/Alcatecablee/Neurolint-CLI NPM: https://www.npmjs.com/package/@neurolint/cli

If you were running React 19 or Next.js 15-16 between Dec 3-7, run the scanner even if you already patched. Especially if you already patched.

Happy to answer questions about the detection logic, AST parsing approach, or the CVE itself.

Show HN: AlgoDrill – Interactive drills to stop forgetting LeetCode patterns

https://algodrill.io
92•henwfan•4h ago•58 comments

Show HN: I built a system for active note-taking in regular meetings like 1-1s

https://withdocket.com
125•davnicwil•17h ago•103 comments

Show HN: Gemini Pro 3 Hallucinates the HN Front Page 10 Years from Today

https://dosaygo-studio.github.io/hn-front-page-2035/news
2•keepamovin•50m ago•1 comments

Show HN: A 3-Tool ETL Pipeline for CSV/TSV/Excel/Parquet in Go

2•mimixbox•52m ago•0 comments

Show HN: I made a nice Anki-app for iOS

https://apps.apple.com/us/app/funky-flashcards/id6755683572
4•quantized_state•55m ago•0 comments

Show HN: I got tired of switching AI tools, so I built an IDE with 11 of them

https://hivetechs.io
2•hivetechs•1h ago•0 comments

Show HN: Fanfa – Interactive and animated Mermaid diagrams

https://fanfa.dev/
129•bairess•5d ago•30 comments

Show HN: A TSP game I wanted for 10 years - built in 4 hours

https://www.graphhopper.com/blog/2025/12/08/a-tsp-game-10-years-in-the-making-built-in-4-hours/
3•oblonski•1h ago•0 comments

Show HN: OpenDataLoader – Safe, Open, High-Performance PDF Loader for AI

https://opendataloader.org/
2•Julia_Katash•2h ago•0 comments

Show HN: Free Logo API – logos for any company or domain

https://logos.apistemic.com/
7•lorey•3h ago•3 comments

Show HN: DuckDB for Kafka Stream Processing

https://sql-flow.com/docs/tutorials/intro/
70•dm03514•22h ago•13 comments

Show HN: I got 50% of my traffic from ChatGPT instead of Google

https://localpdf.online/
6•ulinycoin•4h ago•3 comments

Show HN: Vieta Space, a visual LaTeX math editor

https://docs.vietaspace.com/guide/features
3•liamhawtin•5h ago•1 comments

Show HN: Lockenv – Simple encrypted secrets storage for Git

https://github.com/illarion/lockenv
99•shoemann•1d ago•33 comments

Show HN: Octopii, a runtime for writing distributed applications in Rust

https://github.com/octopii-rs/octopii
14•puterbonga•15h ago•0 comments

Show HN: I built a website that runs itself. Roast my AI-generated content

https://www.stvck.dev
2•since•6h ago•3 comments

Show HN: I replaced Markov Chains with Biomechanics to predict word transitions

https://github.com/Professor-Sam-Sepi0l/biomechanical-linguistics-poc
3•Sam_Sep10l•6h ago•2 comments

Show HN: ReadyKit – Superfast SaaS Starter with Multi-Tenant Workspaces

https://readykit.dev/
120•level09•1w ago•35 comments

Show HN: DeChecker – Detect AI-generated text

https://dechecker.ai
2•GrammarChecker•7h ago•0 comments

Show HN: Diesel-guard – Lint Diesel migrations for unsafe PostgreSQL patterns

https://github.com/ayarotsky/diesel-guard
16•ayarotsky•22h ago•0 comments

Show HN: Zonformat– 35–60% fewer LLM tokens using zero-overhead notation

https://zonformat.org
2•ronibhakta•8h ago•2 comments

Show HN: Persistent memory for Claude Code sessions

https://github.com/TonyStef/Grov
20•tonyystef•6d ago•13 comments

Show HN: Cdecl-dump - represent C declarations visually

https://github.com/bbu/cdecl-dump
35•bluetomcat•1d ago•12 comments

Show HN: A "bank of my parents" for my young kids

https://www.bankofmyparents.com
3•aintitthetruitt•12h ago•1 comments

Show HN: Spotify Wrapped but for LeetCode

https://github.com/collinboler/leetcodewrapped
27•collinboler2•1d ago•11 comments

Show HN: Tool to detect malware left behind after patching CVE-2025-55182

3•Just_Clive•15h ago•0 comments

Show HN: Kraa – Writing App for Everything

https://kraa.io/about
127•levmiseri•5d ago•73 comments

Show HN: Web app that lets you send email time capsules

https://resurf.me
44•walrussama•1d ago•28 comments

Show HN: Onlyrecipe 2.0 – I added all features HN requested – 4 years later

https://onlyrecipeapp.com/?url=https://www.allrecipes.com/turkish-pasta-recipe-8754903
201•AwkwardPanda•5d ago•157 comments

Show HN: RamScout – Search eBay RAM Listings by Price per GB (US/UK)

https://www.ramscout.com/
5•chinskee•17h ago•1 comments