Tag: malware
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
Menlo Security Extends MARS to Protect AI Assistants and Coding Agents
Menlo Security has expanded Menlo Agent Runtime Security, or MARS, with controls aimed at protecting AI assistants and coding agents from prompt injection, malware and data loss as they browse the web, use applications and process files. The company is highlighting the update at Black Hat USA 2026. MARS is a cloud-based capability in Menlo’s..…
-
Google Blogger locks hundreds of blogs in malware false positive
Google has locked hundreds of Blogger websites after a false positive claimed they violated its “Malware and Similar Malicious Content” policy, with some sites deleted from the platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
An agent running Anthropic’s Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project during a cyber evaluation by the UK’s AI Security Institute.When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and…
-
Ransomware Hackers Are Hiding Malware Command Servers Inside Ethereum Smart Contracts
Ransomware operators are now abusing Ethereum smart contracts as stealthy command”‘and”‘control resolvers, with a Gentlemen ransomware affiliate using the EtherRAT backdoor to pull rotating C2 domains directly from the blockchain instead of hardcoding them in the malware. The toolkit shows a clear progression: scheduled tasks that bootstrap PowerShell, privileged account creation (“support2” with Supp0rt2@2026!). LSASS…
-
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/
-
Massive supply-chain attack compromises 440 packages under four hours
Researchers from multiple security firms observed a variant of Mini Shai-Hulud, self-replicating malware linked to TeamPCP, in all the affected packages. First seen on cyberscoop.com Jump to article: cyberscoop.com/supply-chain-attack-malware-mini-shai-hulud-teampcp/
-
Microsoft Warns Russian Hackers Use Hotel Wi-Fi to Steal Credentials
Microsoft warns Russian hackers are exploiting hotel Wi-Fi to deliver malware, steal credentials, and compromise corporate travelers’ cloud accounts worldwide. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-microsoft-russian-hackers-hotel-wifi/
-
New Google Password Manager Attacks Can Hijack Synced Passkeys
Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/
-
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects/
-
GitHub Account Breach Fuels Shai-Hulud npm Supply Chain Attack
A compromised GitHub account fueled a supply chain attack, spreading credential-stealing malware across hundreds of packages. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/github-account-breach-fuels-shai-hulud-npm-supply-chain-attack/
-
Massive ChainDrop npm supply-chain attack infects hundreds of packages
Self-propagating malware named ‘ChainDrop’ has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-chain-attack-infects-hundreds-of-packages/
-
Shai-Hulud Supply Chain Attack Compromises Keyv and Hundreds of npm Packages
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has affected Keyv and several related caching libraries, with a combined monthly installation reach in the billions. Aikido Security reported that…
-
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/midnight-blizzard-hotel-wi-fi-networks-hacking/
-
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.”The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the…
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
-
New Passkey attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
-
Travelers Beware: Russian Intel Hacking Hotel Wi-Fi
Russian Intelligence Hackers Capture Captive Portals. Hackers are using hotel Wi-Fi networks across the United States, India and Saudi Arabia to steal credentials, exfiltrate data and spread malware onto personal devices, according to Microsoft and ReliaQuest. Microsoft’s threat intelligence arm began tracking the threat in early May. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/travelers-beware-russian-intel-hacking-hotel-wi-fi-a-32405
-
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
-
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
Inside the Underground Business of the Android BTMOB RAT malware
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
-
Inside the Underground Business of BTMOB RAT
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
-
Roblox-Cheater werden selbst zu Betrogenen
Tags: malwareGamer recherchieren gerne nach unerlaubten Hilfsmitteln, um ihre Spielerkarriere voranzutreiben. Gefragt sind als ‘undetected” beworbene Geheimtools, um angeblich exklusive Spielfunktionen zu nutzen, die Spielstärke zu verbessern oder um Anti-Cheat-Systeme zu umgehen. Auf der Suche danach werden die Roblox-Täuscher dann selbst Opfer von Malware mit bisweilen weitreichenden Folgen. Das zeigt die Analyse der Bitdefender-Labs-Experten einer laufenden…
-
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers’ login credentials and infect devices with espionage malware, Microsoft said. First seen on therecord.media Jump to article: therecord.media/russian-wifi-hackers-hotels
-
Microsoft warnt: Russische Hacker verbreiten Malware über öffentliche WLANs
Die Angreifer haben wohl WLAN-Netze von Hotels, Flughäfen und anderen Einrichtungen infiltriert, um Daten abzugreifen und Malware zu verbreiten. First seen on golem.de Jump to article: www.golem.de/news/microsoft-warnt-russische-hacker-verbreiten-malware-ueber-oeffentliche-wlans-2608-211540.html

