FireAnt Metakit Software Platform
FireAnt Metakit is a popular software platform used by stock investors in Vietnam. It was compromised in a supply chain attack by…
FireAnt Metakit is a popular software platform used by stock investors in Vietnam. It was compromised in a supply chain attack by…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
A campaign tracked by Sonatype as Atomic Arch (Sonatype-2026-003775) hijacked over 400 AUR packages to deploy a Rust-based credential stealer and optional…
The npm package atomic-lockfile@1.4.2 was used in the Atomic Arch campaign to deliver the deps payload via a preinstall hook. It was…
The npm package js-digest was used in a second wave of the Atomic Arch attack, delivered via bun install. It contained a…
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way…
Packagist is the main package repository for PHP that was used to distribute malicious development versions of 10 packages associated with a…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
TrustPulse is a WordPress plugin for social proof notifications, owned by Awesome Motive. Its JavaScript was tampered with for about 25 minutes…
PushEngage is a WordPress plugin for push notifications, acquired by Awesome Motive. Its JavaScript files were tampered with to plant backdoors on…