- PowerShell execution via Invoke-Expression cmdlet
- Shai-HuludCredential-stealing worm
iseekaigogo[.]comCommand-and-control (C2) endpoint
The cybersecurity landscape continues to face persistent threats across multiple attack vectors, from supply chain compromises to sophisticated phishing infrastructure and hardware vulnerabilities. Today's threat intelligence reveals coordinated campaigns targeting cryptocurrency users, developer ecosystems, and critical infrastructure sectors globally.
Cybersecurity researchers have uncovered a cluster of 16 malicious Mozilla Firefox extensions designed to harvest cryptocurrency wallet recovery phrases and private keys from unsuspecting users. These extensions masquerade as legitimate wallet portals, desktop utilities, and browser tools, but their underlying code intercepts sensitive recovery phrases and private keys during wallet import flows and attempts to exfiltrate those secrets to attacker-controlled infrastructure. The campaign demonstrates the ongoing sophistication of cryptocurrency-focused threat actors who exploit user trust in browser extension ecosystems.
Source: The Hacker News
The npm package "tensorlake," a TypeScript software development kit for Tensorlake applications and cloud services, has been compromised as part of a ChainDrop and Shai-Hulud supply chain attack campaign. Malicious version 0.5.144 contains obfuscated malware capable of harvesting credentials, exfiltrating secrets, establishing persistence mechanisms, and executing remotely supplied code on affected systems. This supply chain compromise poses significant risk to developers who rely on the package, as the malware can propagate through development environments and potentially affect downstream applications and services.
Source: The Hacker News
A new phishing kit called Wazza has been identified by ANY.RUN targeting banking, manufacturing, and government organizations across the United States, Europe, and Australia. Modern phishing infrastructure has evolved beyond simple login page replicas, with attackers now integrating filtering, session management, and traffic controls directly into the delivery infrastructure itself. This sophistication allows threat actors to bypass traditional security detection mechanisms and harvest credentials from high-value targets across critical sectors.
Source: The Hacker News
TP-Link router vulnerabilities have attracted significant regulatory attention as several US states have filed lawsuits against the company. SEC Consult has published technical details regarding the vulnerabilities cited in the state complaints, bringing heightened scrutiny to the security posture of widely deployed ISP routers. The vulnerabilities present a critical concern for both consumer and enterprise networks that depend on TP-Link infrastructure for connectivity and network management.
Source: SecurityWeek
Today's threat landscape reflects a diversified attack strategy targeting users at multiple levels: individual cryptocurrency holders face sophisticated wallet-stealing malware, developers encounter supply chain compromises in trusted repositories, organizations face advanced phishing campaigns, and network infrastructure itself remains vulnerable to exploitation. Security teams must maintain vigilance across all these attack surfaces while implementing defense-in-depth strategies that address threats from browser extensions, package managers, phishing infrastructure, and hardware vulnerabilities simultaneously.
Source articles and extracted indicators (defanged where appropriate).
iseekaigogo[.]comboegl-krysl.eubeacon-surge-sync.workers.dev