Back to Feed

Tag

Malware

50 items tagged #malware

Articles

Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects

Malicious postinstall hooks discovered across 700+ GitHub repos targeting PHP and Node.js packages via Packagist.

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Megalodon attack compromises 5,561 GitHub repos via malicious CI workflows in six hours.

Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days

Microsoft patches two exploited Defender zero-days allowing privilege escalation and DoS attacks.

GitHub links repo breach to TanStack npm supply-chain attack

GitHub breach of 3,800 repos linked to malicious Nx Console extension in TanStack npm supply-chain attack

GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension

TeamPCP steals 3,800 GitHub repositories via poisoned VS Code extension, demands $95K

Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks

Banana RAT malware targets 16 Brazilian banks via fake invoices, stealing data with QR code fraud.

GitHub confirms they were compromised after an employee device involving a poisoned VS Code exten...

GitHub confirms employee device compromise via malicious VS Code extension.

Microsoft shares mitigation for YellowKey Windows zero-day

Microsoft releases mitigation for YellowKey BitLocker zero-day disclosed by Nightmare Eclipse.

New Shai-Hulud malware wave compromises 600 npm packages

Shai-Hulud campaign injects malware into 600+ npm packages to steal developer credentials.

INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers

INTERPOL Operation Ramz arrests 200+ individuals, seizes 53 malware and phishing servers across MENA region.

SHub macOS infostealer variant spoofs Apple security updates

SHub macOS infostealer variant 'Reaper' spoofs Apple security updates via AppleScript to steal data and install

New Reaper Malware Uses Fake Microsoft Domain to Steal macOS Passwords

Reaper malware bypasses macOS Tahoe security to steal passwords and install backdoor via fake Microsoft domain.

Leaked Shai-Hulud malware fuels new npm infostealer campaign

Leaked Shai-Hulud malware deployed in four malicious npm packages by threat actor.

First Shai-Hulud Worm Clones Emerge

Shai-Hulud worm clones emerge days after source code release on GitHub.

RDP Stealer with Windows Defender Bypass https://t.co/4jNuZxUJMZ

RDP stealer malware discovered with Windows Defender evasion capability.

PoC Code Published for Critical NGINX Vulnerability

PoC code published for critical NGINX heap buffer overflow vulnerability (CVE-2026-42945).

Funnel Builder WordPress plugin bug exploited to steal credit cards

Funnel Builder WordPress plugin vulnerability exploited to inject payment card skimmers.

Hackers Use PyInstaller and AMSI Patching to Deliver XWorm RAT v7.4

Hackers deploy XWorm RAT v7.4 via PyInstaller with AMSI patching to bypass Windows security.

OpenAI Hit by TanStack Supply Chain Attack

OpenAI hit by TanStack supply chain attack; credentials stolen from code repositories.

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

CalPhishing campaign exploits Outlook invites and device code phishing to steal M365 tokens and bypass MFA.

TeamPCP Ups the Game, Releases Shai-Hulud Worm’s Source Code

TeamPCP releases Shai-Hulud worm source code on GitHub, fueling supply chain attacks with monetary rewards.

Daily Dose of Dark Web Informer - May 14th, 2026

Daily dark web threat intelligence digest reporting multiple breaches, CVEs, and exposed credentials across global

OpenAI confirms security breach in TanStack supply chain attack

OpenAI confirms two employee devices breached in TanStack supply chain attack via Mini Shai-Hulud malware.

Fake Job Interview Apps Drop JobStealer Malware on Windows and macOS

JobStealer malware spreads via fake job interview apps on Windows and macOS targeting crypto wallets.

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

Stealer backdoor discovered in 3 node-ipc npm package versions targeting developer credentials.

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

Ghostwriter targets Ukrainian government with geofenced PDF phishing delivering Cobalt Strike.

FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit

FamousSparrow targeted Azerbaijani oil and gas firm via ProxyNotShell exploit across three attack waves.

KongTuke hackers now use Microsoft Teams for corporate breaches

KongTuke IAB now exploits Microsoft Teams for social engineering, delivering ModeloRAT in under five minutes.

Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns

Salt Typhoon and Twill Typhoon expand targeting with updated backdoors across Azerbaijan, Asia-Pacific regions.

Foxconn Attack Highlights Manufacturing's Cyber Crisis

Nitrogen ransomware hits Foxconn North American facilities amid 600 attacks on manufacturers this year.

Kimsuky targets organizations with PebbleDash-based tools

Kimsuky deploys PebbleDash-based tools linked to AppleSeed malware cluster

China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage

China-linked Twill Typhoon uses fake Apple and Yahoo CDN sites with FDMTP malware to spy on Asia-Pacific organizations.

FrostyNeighbor: Fresh mischief and digital shenanigans

ESET reports FrostyNeighbor cyberespionage group updates toolset targeting Ukrainian government.

TeamPCP and BreachForums Launch $1,000 Contest for Supply Chain Attacks

TeamPCP and BreachForums launch $1,000 contest rewarding supply chain attacks on open source packages.

TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack

TeamPCP claims to sell 5GB of Mistral AI repositories after Mini Shai-Hulud supply chain attack.

Daily Dose of Dark Web Informer - May 13th, 2026

Dark Web Informer daily digest reports multiple breaches, ransomware hits, and supply chain attacks across global

Security advisories | Mistral Docs

TanStack supply chain attack compromises Mistral AI SDK packages on npm and PyPI

‼️🇫🇷 Mistral AI has confirmed they were impacted by the recent TanStack supply chain attack. h...

Mistral AI confirms impact from TanStack supply chain attack.

Iranian hackers targeted major South Korean electronics maker

Iran-linked MuddyWater targets South Korean electronics maker and 8+ orgs in espionage campaign.

Attackers Weaponize RubyGems for Data Dead Drops

Threat actors publish malicious RubyGems packages with scrapers targeting UK government servers.

Windows BitLocker zero-day gives access to protected drives, PoC released

Researcher releases PoC exploits for YellowKey BitLocker bypass and GreenPlasma privilege escalation zero-days.

📢 Breached and TeamPCP announce supply chain attack competition with $1,000 USD prize and open-s...

Breached and TeamPCP announce $1K prize competition for largest supply chain attack.

TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages

TeamPCP poisoned 400+ npm and PyPI packages with Mini Shai-Hulud self-propagating worm via hijacked OIDC tokens.

LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly

LatAm Vibe threat campaigns use AI agents to generate custom hacking tools targeting Mexico and Brazil.

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

Chinese-linked FamousSparrow exploited Microsoft Exchange repeatedly at Azerbaijani oil/gas firm from Dec 2025–Feb 2026.

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

GemStuffer campaign abuses 150+ RubyGems packages to exfiltrate U.K. council portal data.

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

RubyGems suspends new registrations after 500+ malicious packages uploaded in attack.

Daily Dose of Dark Web Informer - May 12th, 2026

Dark Web Informer daily digest reports multiple breaches, ransomware claims, and threat actor activity.

‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack

Mini Shai-Hulud malware compromises hundreds of open-source packages across major registries in supply-chain attack.

Canvas Hackers ShinyHunters Say Their Official Domain Was Suspended

ShinyHunters' clearnet domain suspended after Canvas LMS attacks; group relocates to dark web.