QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese…
Fortinet FortiGuard Labs has disclosed a long-standing supply chain attack targeting QuickFox, a VPN and network acceleration tool popular among overseas Chinese…
QuickFox is a VPN and network acceleration tool for overseas Chinese users. Its Windows installer was trojanized in a supply chain attack,…
QuickFox VPN is a virtual private network and network acceleration tool designed for overseas Chinese users. It was the target of a…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Cybersecurity researchers have uncovered a sophisticated software supply chain attack targeting users of Alibaba developer tools with a cross-platform remote access trojan…
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
STARDUST CHOLLIMA is another alias for the North Korean threat group also known as Sapphire Sleet and UNC1069, involved in cryptocurrency theft…
Alluring Pisces is a North Korean threat actor known for social engineering and supply chain attacks, linked to the Sapphire Sleet cluster.
debug is a popular npm package for logging, with millions of weekly downloads. It was hijacked in September 2025 via a maintainer…