npm Packages Poisoned by TeamPCP
npm was one of the ecosystems targeted by TeamPCP. Malicious packages like keyv and cacheable were poisoned in August 2026.
Cybersecurity products, tools, platforms and software categories.
npm was one of the ecosystems targeted by TeamPCP. Malicious packages like keyv and cacheable were poisoned in August 2026.
Used by Rapid7 to publish indicators of compromise (IOCs) for the campaign.
Google Chrome is a Chromium-based browser whose credentials were targeted by the StubMaker stealer via abe_payload.dll.
Chrome extensions are browser add-ons that the RAT targets to collect data, highlighting risks to developer tools.
The phishing campaign downloads a legitimate Node.js v24.13.0 runtime from nodejs.org to execute the TonRAT implant in user space.
Python was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
PowerShell was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
SHEETCORD uses a Visual Basic Script in the Windows Startup folder to establish persistence on infected systems.
Nuitka is a Python compiler used to compile Python extension modules (*.pyd) that implement the RAT's capabilities.
SEC535: Offensive AI – Attack Tools and Techniques was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is…