ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Malware families, payloads, loaders, ransomware and related tooling.
Huntress researchers have uncovered a new ClickFix-style attack campaign targeting macOS users with a Go-based stealer malware capable of stealing cryptocurrency, browser…
Atomic Stealer is a macOS information stealer that has been observed in ClickFix campaigns using look-alike domains and server-side browser fingerprinting to…
Remus is a 64-bit variant of the Lumma Stealer malware, distributed via fake websites offering cracked software and pirated games through SEO…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
WEL1DROPPER is a downloader used in a campaign involving nearly 800 malicious npm packages. It identifies the host OS and architecture, then…
Sliver, an open-source command-and-control (C2) framework, is deployed as the final payload on Linux systems in the malicious npm campaign. The Linux…
Flooding Dropper is the moniker used by Sonatype for the campaign involving nearly 800 malicious npm packages. The campaign delivers cross-platform malware…
Moika is a dependency confusion campaign observed in April that published over 250 malicious npm packages to steal environment information and deliver…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
Kamikaze is a wiper malware used by TeamPCP to wipe all nodes in a Kubernetes cluster. It is deployed via a DaemonSet…