Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
A new campaign has been discovered publishing nearly 800 malicious packages to the npm registry, designed to deliver a cross-platform remote access…
WEL1DROPPER is a downloader used in a campaign involving nearly 800 malicious npm packages. It identifies the host OS and architecture, then…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
TeamPCP is a cybercrime group alleged to have compromised open-source projects like Trivy, Checkmarx KICS, and LiteLLM in March 2026. The group…
Zbtlink is a Chinese router manufacturer whose firmware has been found to contain a factory-shipped backdoor (ENDLESSDOORS) across multiple models. The company…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Open VSX, an open-source marketplace for Visual Studio Code extensions, removed 77 malicious 'evil twin' extensions that exfiltrated developer data. The extensions…
Keyv is an npm package that was compromised in the August 2026 worm campaign. The malicious keyv@6.0.0 release included a preinstall script…
Pillar Security reported on August 4, 2026, that the ChainDrop npm worm planted malicious hooks in compromised repositories. The hooks trigger when…
Xanadu's photonic quantum computing Python library, mrmustard, was compromised with a poisoned version that ran an information stealer. The attack involved breaching…