Image 1 — I built a Firefox add-on that changes the browser identity websites see
Image 2 — I built a Firefox add-on that changes the browser identity websites see

I built a Firefox add-on that changes the browser identity websites see

Websites can read more than your IP, including your user agent, language, timezone, screen size, and device properties.

I built Spoof Me to let Firefox users switch these signals together as one browser identity.

It includes ready-made profiles, custom profiles, and a warning badge when a website accesses fingerprint-related properties.

It does not change your IP address or promise complete anonymity. The add-on does not collect browsing data and is MIT licensed.

Firefox Add-ons:

https://addons.mozilla.org/en-GB/firefox/addon/spoof-me/

Project website:
https://spoof-me.com/

I’d appreciate feedback on the profile consistency, permission explanations, and any fingerprint signals that should be added.

u/kryakrya_it — 14 days ago

I built a Firefox add-on that lets you switch the browser identity websites see

Firefox already includes fingerprinting protection, but I wanted more control over the browser profile that individual websites see.

So I built Spoof Me.

It lets you choose a ready-made browser identity or create your own, changing signals such as user agent, language, timezone, screen size, and device properties together.

It also displays a warning badge when a website accesses fingerprint-related properties.

It does not change your IP address or claim to make you anonymous.

Firefox Add-on:

https://addons.mozilla.org/en-US/firefox/addon/spoof-me/

Project page:

https://spoof-me.com/

I would appreciate honest feedback, especially about the available profiles and whether the permission explanations are clear.

u/kryakrya_it — 14 days ago

I built an extension that lets you change what your browser reveals about you

I built Spoof Me, a free browser extension that lets you switch between consistent browser fingerprint profiles.

It can modify signals such as user agent, timezone, language, screen size, canvas, and device properties. You can use ready-made profiles or create your own.

It also shows when websites try to access fingerprint-related signals.

I would appreciate feedback on the interface, available profiles, and any signals that should be added.

https://spoof-me.com/

u/kryakrya_it — 14 days ago
▲ 13 r/AntiDetectGuides+2 crossposts

I built a Chrome extension for testing browser fingerprint spoofing

I built a small Chrome extension called Spoof Me for inspecting and changing common browser fingerprinting signals.

The basic idea is that a VPN changes your IP, but your browser can still expose things like user agent, timezone, language, screen size, canvas, WebGL, and other values that can make sessions easier to link.

I’m not claiming this gives perfect anonymity. I built it more as a practical testing tool to see what the browser exposes and what happens when those values are changed.

I’d appreciate feedback from people who build Chrome extensions or understand browser privacy:

What fingerprinting signals are actually worth spoofing?

Which ones usually make the fingerprint more unique instead of less unique?

Are there any Chrome extension permission/security issues I should think about?

Link for full: https://audits.blockhacks.io/audit/spoof-me-extension-for-privacy

u/kryakrya_it — 1 month ago
▲ 2 r/de_IT+3 crossposts

Prüft ihr eigentlich npm-Pakete, bevor ihr sie installiert?

Ich bin in letzter Zeit wieder öfter über Fälle mit kompromittierten npm-Paketen gestolpert und frage mich, wie ihr das im Alltag handhabt.

npm audit zeigt ja eher bekannte CVEs, aber nicht unbedingt, ob ein Paket komische Install-Skripte hat, obfuskierten Code enthält oder irgendwas mit Tokens, API Keys oder .env-Dateien macht.

Schaut ihr euch neue Dependencies vorher irgendwie an, oder installiert ihr meistens einfach, wenn Downloads, GitHub und Maintainer halbwegs seriös aussehen?

Gibt es bei euch in der Firma feste Regeln dafür, oder ist das am Ende Bauchgefühl?

reddit.com
u/kryakrya_it — 2 months ago
▲ 55 r/npm+5 crossposts

TanStack npm packages compromised in supply-chain attack targeting developer and CI secrets

Summary:

A recent npm supply-chain incident affected multiple u/tanstack/* packages. Malicious versions were published to npm, and the payload reportedly executed during install.

The main risk is not only runtime usage. If a developer machine or CI runner installed an affected version, secrets available to the install process may have been exposed.

Reported targets included:

- cloud credentials

- GitHub tokens

- npm tokens

- SSH keys

- CI/deployment secrets

Practical things to check:

- lockfile versions for u/tanstack/*

- npm/pnpm/yarn install logs

- package manager cache

- CI runs during the affected publish window

- GitHub/npm/cloud audit logs

- whether lifecycle scripts were enabled during install

For affected environments, the safer assumption is that exposed credentials should be rotated and dependencies should be reinstalled from a clean lockfile after moving to patched versions.

Primary advisory:

https://github.com/TanStack/router/security/advisories/GHSA-g7cv-rxg3-hmpx

Public tracking issue:

https://github.com/TanStack/router/issues/7383

I also maintain NPMScan and put the affected versions, IOCs, and mitigation notes into one page here:

https://npmscan.com/vulnerability/GHSA-g7cv-rxg3-hmpx

Recent npm vulnerability feed:

https://npmscan.com/latest-vulnerabilities

The bigger question: should Node.js CI pipelines disable install scripts by default, or is that still too impractical for real projects?

npmscan.com
u/kryakrya_it — 3 months ago

[SELLING] 14k MAU Dev Audience (Security Tool) | High-Intent Traffic | Ad Slots from $157/mo

Selling ad space on a developer-focused security tool:

🔗 https://npmscan.com/

About the site:

  • Scans npm packages for malicious behavior (wallet drainers, suspicious scripts, etc)
  • Used by developers before installing packages (high-intent traffic)
  • Focused on Node.js / security-aware audience

Traffic:

  • ~14,000 monthly active users
  • ~150,000 developers reached
  • Growing steadily

Audience:

  • Developers (Node.js, Web3, backend)
  • Security-conscious users
  • High intent (users actively checking packages before install)

Ad placements available:

  • Homepage
  • Tool / scan pages
  • Dedicated sponsor sections

Pricing:

  • Starting from $157/month per slot (fixed pricing, not CPM)

Looking for:

  • Dev tools
  • Security products
  • APIs / infrastructure
  • Relevant software/services

Notes:

  • Prefer long-term sponsors
  • Limited slots (keeping placements clean and non-spammy)

👉 Details & contact: https://npmscan.com/advertise

DM me if interested.

u/kryakrya_it — 5 months ago