Skip to main content

Tag: malware operations

629 articles

Developer workstation with laptop, coding environment, notes, and coffee cups, with daylight and cityscape in background.

Malware Targets TanStack npm Packages in Supply Chain Attack

Malware attackers have infiltrated the TanStack npm packages, modifying 84 artifacts in a supply chain attack that could compromise major developer ecosystems. The malicious code, aimed at stealing credentials, was published across 42 packages on May 11, with some, like @tanstack/react-router, downloaded over 12 million times weekly.

Analyst 207
Smartphone on cluttered cafe table with blurred screen and scattered receipts.

TrickMo Trojan Exploits TON Network for Android Pivots

Meet TrickMo C, a sneaky new variant of the Android banking trojan that's turning infected devices into programmable network pivots, allowing hackers to intercept sensitive data from banking and cryptocurrency wallet users in France, Italy, and Austria. This malicious software is packed with powerful tools, including reconnaissance, SSH tunnelling, and SOCKS5 proxying capabilities.

Analyst 207
Modern office network closet with equipment racks, patch panels, and computer workstations.

Cybercriminals Leverage ClickFix with PySoxy for Persistent Attacks

Cybercriminals are using a potent combination of ClickFix and PySoxy to launch persistent attacks, with experts warning that their deliberate preparation shows a sinister intent for continued access. This sophisticated tactic allows attackers to survive removal attempts and endpoint blocks, making it a major threat.

Analyst 207
Dimly lit development workspace with laptop and empty GitHub repositories or terminal windows.

Shai Hulud Campaign Targets Developers with Malicious npm Packages

Malicious actors have unleashed a barrage of 84 tainted versions of popular software packages, cleverly disguising them with legitimate credentials to deceive developers. The Shai Hulud campaign, linked to the TeamPCP threat group, has been wreaking havoc on the software supply chain since September.

Analyst 207
Dimly lit laptop screen shows blurred software repository page with cursor over suspicious package.

Hugging Face Repository Exploits Typosquatting to Spread Infostealer Malware

Security researchers have uncovered a cunning malware attack on Hugging Face, where a fake repository mimicked a popular AI project, racking up over 244,000 downloads and 667 likes in just 18 hours. The malicious repository used a classic typosquatting trick to deceive users searching for the genuine project.

Analyst 207
Cluttered tech workspace with laptop and development tools on a desk.

Mini Shai-Hulud Worm Targets Multiple AI, Dev Packages

Meet the Mini Shai-Hulud worm, a sneaky new malware that's infiltrating AI and development packages through a clever supply-chain attack. This malicious code can steal sensitive data from cloud providers, cryptocurrency wallets, and even popular dev tools like GitHub Actions.

Analyst 207
Blurred laptop screen on cluttered desk with scattered papers and office supplies.

Gentlemen Ransomware Group Hit by Data Breach

A recent data breach has exposed the inner workings of the notorious Gentlemen ransomware group, revealing a treasure trove of sensitive information, including chats, images, and operational practices. This rare glimpse into the ransomware ecosystem could provide valuable insights for cybersecurity experts and researchers.

Analyst 207
Developer workstation with laptop, code editor, and cluttered desk in a bright office.

Malware Exploits Chromium Interface to Steal Dev Secrets

Malware is masquerading as a legitimate software installer, tricking developers into spilling their secrets by exploiting the Chromium interface. A simple search ad has become the conduit for this malicious campaign, leading unsuspecting devs down a path of deceit.

Analyst 207
Technicians walk through a server room with rows of computer equipment and storage systems near a workstation with a laptop.

cPanel Flaw Exploited to Deploy Filemanager Backdoor

Over 2,000 attacker source IPs worldwide are currently involved in automated attacks exploiting a critical cPanel vulnerability, CVE-2026-41940, which allows remote attackers to gain elevated control and deploy malicious backdoors. This flaw has been targeted by multiple actors for a range of malicious outcomes, including cryptocurrency mining and ransomware.

Analyst 207
Developers' workstation with laptop, code editor, notes, and coffee cups in a bright office setting.

PowerShell Stealer Targets Devs via Fake Claude Code Pages

Developers beware: a sneaky PowerShell Stealer is targeting you through fake Claude Code pages, putting your organization's most sensitive assets at risk. Clicking on innocent-looking sponsored search results could be the first step in a devastating cyberattack.

Analyst 207
Rack-mounted Linux server in a data center with a blank screen.

Ivanti, Palo Alto Networks Flaws Exploited in Active Attacks

Meet Quasar Linux RAT, a sneaky malware that combines remote access, evasion, and data theft capabilities, making it a potent threat to Linux systems. This powerful tool lets hackers secretly control infected hosts, harvest sensitive info, and even create a network of compromised devices that communicate with each other.

Analyst 207
Dimly lit smartphone screen on a cluttered nightstand shows a faint, abstract pattern, with a cityscape at dusk visible…

TrickMo Malware Adopts TON Blockchain for Covert Command-and-Control

Meet Trickmo.C, a sneaky new variant of the TrickMo Android banker that's been hiding in plain sight as a TikTok or streaming app, targeting unsuspecting users in France, Italy, and Austria since January. This cunning malware has evolved to use the TON blockchain for covert command-and-control, making traditional domain takedowns a thing of the past.

Analyst 207
Laptop, smartphone, and notebook arranged on a desk in a tidy workspace.

Malicious Repo Exploits OpenAI Model to Deliver Info Stealer

A malicious repository disguised as OpenAI's legitimate Privacy Filter model racked up 244,000 downloads and became the #1 trending project on Hugging Face, but actually hid a sneaky Rust-based information stealer targeting Windows machines. The fake repository, Open-OSS/privacy-filter, expertly impersonated OpenAI's release, even copying the official model card to gain users' trust.

Analyst 207
Mac laptop on a desk with a Terminal window open, in a blurred office setting.

Hackers Exploit Google Ads, AI Chats to Spread Mac Malware

Malicious hackers are exploiting Google ads and AI chat platforms to trick Mac users into downloading malware, using a sneaky tactic that involves fake installation guides and Terminal commands. Clicking on what seems to be a legitimate ad can lead to a malware-ridden surprise, thanks to a vulnerability in Claude's shared-chat feature.

Analyst 207
Laptop screen displays compromised website in home office setting.

JDownloader Site Compromised to Spread Python RAT Malware

A Reddit user recently raised the alarm after Microsoft Defender flagged a JDownloader download on their new PC, uncovering a sinister plot to spread Python RAT malware through the popular download manager's compromised website. The JDownloader site was hacked between May 6-7, 2026, allowing attackers to swap legitimate downloads with malicious payloads.

Analyst 207
Brazilian bank interior with customers and staff, smartphone in foreground.

TCLBANKER Trojan Targets Brazil's Financial Sector via WhatsApp Worms

A new Brazilian banking trojan, dubbed TCLBANKER, is targeting the country's financial sector via WhatsApp worms, marking a significant evolution in the threat landscape. This malware can compromise 59 banking, fintech, and cryptocurrency platforms, making it a major player in the region.

Analyst 207
Dimly lit network closet with disarrayed cables and equipment.

Malware Worm Eliminates Rival, Seizes Control

Meet the malware worm with a ruthless streak - it not only eliminates rival malware from infected systems, but also seizes control and claims the compromised credentials for itself. This cunning worm is taking over, leaving other malicious operators with nothing.

Analyst 207
Cluttered developer workstation with laptop and devices, screens blank.

Linux RAT Quasar Exploits Developer Credentials for Supply Chain Compromise

Meet QLNX, a sneaky Linux malware that's targeting developers and DevOps teams to gain control of the software supply chain by stealing sensitive credentials. This stealthy threat operates from memory, masquerading as a harmless system process while secretly exfiltrating data and awaiting commands from its controllers.

Analyst 207
Server racks and cloud storage units in a data center with a hint of disruption.

PCPJack Disrupts TeamPCP's Cloud Footprint with Credential Theft

Meet PCPJack, a sneaky new credential theft framework that's wreaking havoc on TeamPCP's cloud operations by stealing sensitive credentials and clearing out the competition. This malicious tool is quietly moving through cloud environments, leaving a trail of compromised systems in its wake.

Analyst 207
Busy office scene with people in background, laptop in foreground displaying signs of malware breach.

TCLBanker Malware Spreads Rapidly via WhatsApp, Outlook

Beware of a rapidly spreading malware, TCLBanker, that's infecting 59 major banking, fintech, and cryptocurrency platforms through sneaky WhatsApp and Outlook attacks. This sneaky trojan uses a fake Logitech AI Prompt Builder installer to wreak havoc on your digital security.

Analyst 207
Rows of computer servers and storage equipment in a neutral-colored data center with industrial flooring and cable…

PCPJack Credential Stealer Exploits CVEs to Spread Across Cloud Systems

Meet PCPJack, a sneaky credential stealer that's exploiting vulnerabilities to spread rapidly across cloud systems, swiping sensitive info from services like cloud, finance, and productivity tools. Its operators are after one thing: illicit financial gain.

Analyst 207
Rows of computer servers and storage equipment in a data center with a single unoccupied Linux terminal in the foreground.

PCPJack Worm Targets Cloud Infrastructure, Steals Credentials

A fresh malware campaign, dubbed PCPJack, is targeting cloud infrastructure, stealing credentials and wreaking havoc on Linux-based systems with a sophisticated framework that installs hidden working directories and establishes persistence. This alarming attack bears striking similarities to earlier TeamPCP/PCPCat campaigns, raising concerns about its potential impact.

Analyst 207
Person sitting at laptop in office setting with blurred screen.

Australia Warns of ClickFix Malware Attacks Spreading Vidar Stealer

Beware of ClickFix malware attacks that trick you into executing commands, allowing hackers to bypass security and steal your info. The Australian Cyber Security Center has warned of a new campaign using WordPress-hosted sites to spread the Vidar Stealer malware.

Analyst 207
Students work on laptops in a dimly lit university computer lab with scattered papers and blurred screens.

MicroStealer Targets Education, Telecom with Credential Theft FTC Cracks Down on Kochava's Location Data Practices Proton Mail Adds Quantum-Safe Encryption Supply Chain Hardened with pnpm 11 Release Meta Deploys AI for Underage Enforcement North Korea-Linked Cybercrime Case Upheld ICS Security Flaws Disclosed in Eclipse BaSyx MOVEit Automation Exposes Critical Vulnerability VECT Ransomware Encryption Flaws Discovered Oracle Accelerates Patching with

MicroStealer malware is on the loose, targeting education and telecom sectors with a sneaky credential theft attack that's harvesting sensitive data, including browser credentials, cryptocurrency wallets, and system info. This stealthy threat uses a multi-stage delivery chain to quickly swipe valuable info and send it to hackers.

Analyst 207