Tag: marketplace
-
77 malicious extensions found on Open VSX marketplace
First seen on scworld.com Jump to article: www.scworld.com/brief/77-malicious-extensions-found-on-open-vsx-marketplace
-
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed.The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been…
-
77 Open VSX extensions found harvesting developer info
77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-developer-info/
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
Mit Drogen-Marktplatz: Deutscher soll im Darknet 20 Millionen Euro erlangt haben
Der 31-Jährige soll einen riesigen Darknet-Marktplatz betrieben und am Drogenhandel mitverdient haben. Jetzt muss er sich vor Gericht verantworten. First seen on golem.de Jump to article: www.golem.de/news/mit-drogen-marktplatz-deutscher-soll-im-darknet-20-millionen-euro-erlangt-haben-2608-211565.html
-
Malicious AI agent skills can slip past the scanners built to stop them
Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/malicious-ai-agent-skills-scan/
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher accounts and confirmed 247,693 installations. The campaign combined typosquatting, ranking manipulation, and multi-stage payload delivery…
-
More Malicious OpenClaw Skills Threaten AI Supply Chain
OpenClaw removed five packages from ClawHub, its skills marketplace, that bypassed security checks even though they included infostealers and other threats. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/malicious-openclaw-skills-clawhub-threaten-ai-supply-chain
-
Algerian national accused of running cybercrime marketplaces extradited to US
An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/algerian-cybercrime-marketplace-operator-extradited-to-us/
-
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
lso Tuesday, the Treasury Department took action against the same Cambodian company, Huione Group, and affiliates. First seen on cyberscoop.com Jump to article: cyberscoop.com/doj-huione-group-cybercrime-seizure/
-
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts.Every skill security scanner the firm tested it against marked it safe. The payload was harmless by design: it collected the user’s email address…
-
Algerian man charged with running two cybercrime marketplaces
Abdellah Belmili allegedly ran two black-market websites selling stolen financial credentials and custom-built phishing kits targeting major American banks, federal prosecutors say. First seen on cyberscoop.com Jump to article: cyberscoop.com/algerian-man-charged-cybercrime-marketplaces/
-
Bösartige Plugins stehlen KISchlüssel von Entwicklern
Mindestens 15 Plugins im JetBrains Marketplace exfiltrieren heimlich API-Schlüssel für KI-Dienste. Rund 70.000 Installationen sind betroffen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/plugins-stehlen-ki-api-schluessel
-
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.”Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,”…
-
Fifteen JetBrains Marketplace Plugins Found Stealing API Keys
Aikido Security has discovered at least 15 IDE plugins on the JetBrains Marketplace First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fifteen-jetbrains-marketplace/
-
JetBrains Plugin Security Alert: 70,000+ Installs Linked to AI Key Theft
A coordinated supply chain attack targeting JetBrains IDE users has exposed over 70,000 developers to silent credential theft. The campaign involves at least 15 malicious plugins distributed via the JetBrains Marketplace, masquerading as AI-powered coding assistants built on models such as DeepSeek. While these plugins function as advertised, offering features like code review, chat, and…
-
Malicious JetBrains Marketplace plugins steal AI API keys from developers
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/
-
Securebasierter Workspace für KMUs
Island und Pax8, der globale KI- und Cloud-Marketplace für kleine und mittlere Unternehmen (KMU), haben <> im Pax8-Marketplace eingeführt. Damit steht Island nun Managed-Service-Provider (MSP) -Partnern und deren KMU-Kunden weltweit zur Verfügung. Die Zusammenarbeit vereint zwei Unternehmen, die Technologie für den Mittelstand vereinfachen wollen. Island für KMU ist eine einheitliche, sichere, browserbasierte Plattform. […] First…
-
Securebasierter Workspace für KMUs
Island und Pax8, der globale KI- und Cloud-Marketplace für kleine und mittlere Unternehmen (KMU), haben <> im Pax8-Marketplace eingeführt. Damit steht Island nun Managed-Service-Provider (MSP) -Partnern und deren KMU-Kunden weltweit zur Verfügung. Die Zusammenarbeit vereint zwei Unternehmen, die Technologie für den Mittelstand vereinfachen wollen. Island für KMU ist eine einheitliche, sichere, browserbasierte Plattform. […] First…
-
Cybercriminals Exploit Chinese Guarantee Markets to Sell Stolen Credentials
Chinese-language “guarantee” marketplaces hosted mainly on Telegram have become a core conduit for buying, selling, and laundering stolen credentials and a wide range of criminal services. These platforms modeled explicitly on consumer escrow systems such as Alipay’s æ‹…ä¿äº¤æ˜“ (dÄnbÇŽo jiÄoyì) operate as third-party guarantors: the marketplace operator holds buyer funds in escrow, releases them only…
-
Fake document marketplace aiding migrant smuggling dismantled in Spain
Tags: marketplaceFirst seen on scworld.com Jump to article: www.scworld.com/brief/fake-document-marketplace-dismantled-in-spain-aiding-migrant-smuggling
-
Police dismantles fake ID marketplace used by migrant smugglers
French and Spanish authorities took down an online marketplace selling fake identity documents to migrant smuggling rings operating within the European Union. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/police-dismantles-fake-id-marketplace-used-by-migrant-smugglers/
-
OAuth marketplace apps keep access after publishers vanish
Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/
-
GitHub Breach Traced to Malicious ‘Nx Console’ VS Code Extension
A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/github-breach-nx-console-vs-code/
-
Most dark web activity revolves around a handful of topics
Dark web activity often becomes visible during marketplace seizures, major data leaks, or sudden spikes in criminal activity. Those events can create an impression of an … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/05/21/dark-web-activity-research/
-
Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free
Carding forum B1ack’s Stash claims to have released millions of stolen CVV2 payment card records for free after suspending sellers. B1ack’s Stash, one of the most active stolen card marketplaces on the dark web, has released 4.6 million credit card records for free, not because of a law enforcement action or a system compromise, but…
-
Qualys erhält FedRAMP-Zulassung der Stufe ‘High” für <> und bietet nun Schutz von Cloud-Workloads für Behörden
Qualys gibt bekannt, dass seine <>-Lösung die FedRAMP-High-Zulassung erhalten hat, die von der US-Drogenbekämpfungsbehörde (DEA) gefördert wird. Dieser Meilenstein erweitert den FedRAMP-High-Status der Qualys-Government-Platform um die Cloud-Native-Application-Protection-Platform (CNAPP). Qualys-Totalcloud ist nun im FedRAMP-Marketplace gelistet, sodass Bundesbehörden, Lieferanten und stark regulierte Branchen die umfassenden Cloud-Sicherheitsfunktionen nutzen können. Die FedRAMP-High-Zulassung stellt die strengste Compliance-Stufe innerhalb des Federal-Risk…
-
Illicit Enterprise: An Anatomy of the Modern Underground Phishing Marketplace
Intel 471 analysts examined the evolving ecosystem of cybercriminal phishing marketplaces. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/illicit-enterprise-an-anatomy-of-the-modern-underground-phishing-marketplace/
-
Thieves unlock stolen iPhones using cheap tools sold on Telegram
Helping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/05/15/stolen-iphone-unlocking-tools-telegram-groups/
-
US charges suspected Dream Market admin arrested in Germany
The alleged main administrator of Dream Market Incognito Market, one of the largest dark web marketplaces before its shutdown, has been indicted in the United States on money laundering charges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-charges-suspected-dream-market-admin-arrested-in-germany/

