ModHeader Browser Extension Removed After Hidden Collector Discovery
ModHeader, a popular header-editing browser extension with 1.6 million installs, was removed from Chrome and Edge web stores after researchers found a…
ModHeader, a popular header-editing browser extension with 1.6 million installs, was removed from Chrome and Edge web stores after researchers found a…
Google and Microsoft have removed the ModHeader browser extension from their respective web stores after security researchers discovered a dormant browsing-history collector…
Shai-Hulud is a known npm worm family that has been active in past supply chain attacks. The recent ChainDrop campaign shows tradecraft…
Checkmarx, a software security company, confirmed that credentials obtained through the Trivy attack enabled unauthorized access to its GitHub repositories and the…
PyPI was used to distribute backdoored LiteLLM releases. The malicious builds were removed from the index but still accessible via direct URLs.
ChocoPoC is a remote access trojan that hides in Python dependencies of fake PoC exploit repositories on GitHub. It steals credentials, cookies,…
MUT-1244 is a campaign that used fake PoC repositories to steal SSH keys and cloud credentials from red teamers and researchers, similar…
Visual Studio Code, a popular code editor, was targeted by malicious extensions on the Open VSX marketplace that exfiltrated developer data. The…
A cluster of malicious packages that use fake .woff2 font files to conceal JavaScript payloads. Tactically overlaps with TaskJacker and PolinRider, using…
A remote code execution vulnerability in React applications, used as a lure in the ChocoPoC campaign.