This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…
Flooding Dropper is the moniker used by Sonatype for the campaign involving nearly 800 malicious npm packages. The campaign delivers cross-platform malware…
Moika is a dependency confusion campaign observed in April that published over 250 malicious npm packages to steal environment information and deliver…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Six npm packages use the NullReceiver technique, fetching next-stage payloads via Ethereum transactions linked to North Korean threat actors, evolving from EtherHiding.
A cluster of 77 malicious extensions on the Open VSX marketplace has been discovered impersonating legitimate developer tools while exfiltrating sensitive information…