Tag: malware
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU architecture.”…
-
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/
-
Homer dichtet Malware
Hacker nutzen Fake-Angebote für Christopher Nolans Odysseus-Film, um Malware mit Lummastealer auszuspielen. Laut der renommierten Althistorikerin Mary Beard hat Christopher Nolan in seiner aktuellen Odysseus-Verfilmung von 2026 Erotik und Witz zugunsten von Gewalt weggekürzt. Hacker transportieren ihrerseits aktuell illegal die Lummastealer-Malware zum Informationsdiebstahl als Angebot vermeintlicher Downloads des Films. Die Experten der Bitdefender Labs beobachten…
-
Google Begins Restoring Blogger Sites After False Malware Alerts
Google is restoring Blogger sites wrongly flagged for malware after hundreds of publishers reported locked or unavailable blogs and false-positive alerts. The post Google Begins Restoring Blogger Sites After False Malware Alerts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-blogger-malware-false-positive/
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
ClickFix attack pushes macOS infostealer for crypto theft attacks
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostealer-for-crypto-theft-attacks/
-
How Agentic AI Scales Cybercrime
Google’s Hultquist on Autonomous Attacks and Behavioral Defense. Cybercriminals are using agentic AI to automate intrusions, rewrite malware and scale operations with stolen access to artificial intelligence services. Google’s John Hultquist explains why signature-based defenses are losing ground and how behavioral detection can help security teams respond. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-agentic-ai-scales-cybercrime-a-32449
-
250+ ClickFix Domains Hide macOS Malware From Security Scanners
A ClickFix campaign uses browser fingerprinting across more than 250 domains to hide macOS infostealer lures from scanners and security researchers. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-clickfix-domains-browser-fingerprinting-macos-malware/
-
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an infection back to a fake CAPTCHA scam known as ClickFix. The incident came to light during a retrospective threat hunt in June 2026, when a Huntress analyst discovered remnants of a Mac-specific…
-
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links.We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison pages.…
-
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python”‘based, cross”‘platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller”‘packed executable to harvest browser passwords, crypto wallet data, Discord tokens, gaming accounts, VPN configs, and sensitive documents. Vanta Stealer exemplifies the current shift toward Python for modular, easily maintainable malware, while abusing commercial protection frameworks like PyArmor…
-
Blogger: Google sperrt Hunderte Blogs mit falscher Malware-Warnung
Bei Googles Bloggingdienst Blogger löst die Malware-Erkennung reihenweise Fehlalarme aus. Hunderte von Blogs wurden unverhofft gesperrt. First seen on golem.de Jump to article: www.golem.de/news/blogger-google-sperrt-mit-falscher-malware-warnung-hunderte-blogs-2608-211651.html
-
Neue Shai Hulud-Variante befällt Hunderte npm-Pakete
Tags: malwareIm npm-Ökosystem ist eine neue Angriffswelle aufgetaucht. Die Schadsoftware trägt den Namen “Chaindrop” und gehört zur Familie der Shai-Hulud-Malware, die Sicherheitsforschern bereits seit längerer Zeit bekannt ist. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/neue-shai-hulud-variante-npm
-
South Korea’s government overtakes telcos as top cyber attack target
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647735/South-Koreas-government-overtakes-telcos-as-top-cyber-attack-target
-
Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
Hackers are abusing an Ethereum smart contract as a dead”‘drop resolver to dynamically steer victims’ browsers to rotating command”‘and”‘control (C2) infrastructure in a new Remus infostealer campaign that weaponizes fake cracked software lures and Turkish”‘language SEO poisoning. In this campaign, Remus no longer relies on a static C2 domain or legacy dead-drop platforms like Steam…
-
Sicherheitstest mit Mythos 5 – KI-Agent wollte Malware in Open-Source-Projekt einschleusen
Bei einem Sicherheitstest versuchte ein auf Mythos 5 basierender Agent, Malware in ein echtes Open-Source-Projekt einzuschleusen. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/sicherheitstest-mit-mythos-5-ki-agent-wollte-malware-in-open-source-projekt-einschleusen.98721
-
Blogger: Google sperrt mit falscher Malware-Warnung Hunderte Blogs
Bei Googles Bloggingdienst Blogger löst die Malware-Erkennung reihenweise Fehlalarme aus. Hunderte von Blogs wurden unverhofft gesperrt. First seen on golem.de Jump to article: www.golem.de/news/blogger-google-sperrt-mit-falscher-malware-warnung-hunderte-blogs-2608-211651.html
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/anthropics-ai-used-fake-identities-malware-in-rogue-attack-on-github-project/
-
Stairwell Launches Backstory to Map Malware Blast Radius Beyond the First Alert
Stairwell has launched Backstory, an agentic investigation platform designed to trace related malware variants, identify affected systems and map an incident’s full blast radius. The platform was announced July 29 as Stairwell prepared to showcase it at Black Hat USA 2026. Backstory is built to answer what happened, where an incident spread and what needs..…
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software…
-
Menlo Security Extends MARS to Protect AI Assistants and Coding Agents
Menlo Security has expanded Menlo Agent Runtime Security, or MARS, with controls aimed at protecting AI assistants and coding agents from prompt injection, malware and data loss as they browse the web, use applications and process files. The company is highlighting the update at Black Hat USA 2026. MARS is a cloud-based capability in Menlo’s..…
-
Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites deleted from the platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute.When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and…
-
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS…
-
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/

