ViteVenom: Malicious npm Campaign Targeting Vite Developers
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Ravie LakshmananJul 17, 2026Malware / Threat Intelligence Cybersecurity researchers have attributed the…
Sodinokibi is the malware variant associated with the REvil ransomware group, used in attacks from April 2019 to July 2021. It is…
SugarLocker is a ransomware variant developed by the Shtazi-IT dev shop, linked to the sanctioned Aleksandr Ermakov. It was sold with a…
QuarksDumpLocalHash is a tool used to extract local account password hashes from the SAM registry hive. It was deployed in the GoSerpent…
Stowaway is a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based…
TmcLoader is a C++ loader module that contains an encrypted payload called TmcPayload. It was used in the GoSerpent campaign to exfiltrate…
TmcPayload is an encrypted payload deployed by TmcLoader to exfiltrate stored sensitive data from victim machines. It was part of the evolved…
McMx RAT is a basic Go-based proxy and remote access tool that is a lightweight version of GoSerpent. It includes capabilities such…