Skip to main content

Tag: opensourcemalware

3 articles

Laptop and code editor on a minimalist desk with npm package docs nearby.

npm Packages Deliver WeaselBiscuit Stealer to Harvest Chrome Data

Meet WeaselBiscuit, a sneaky new malware that's small but packs a punch, stealing Chrome data by masquerading as harmless npm packages. This stripped-down stealer is designed to evade detection, and it's being spread through 13 infected npm packages.

Analyst 207
Cluttered software development workspace with computer screens and terminals, one central laptop lid slightly ajar.

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

North Korean hackers have unleashed a massive wave of malware, publishing 108 malicious packages and web browser extensions across popular platforms like npm, Packagist, Go, and Google Chrome as part of their sneaky PolinRider campaign. This ongoing operation has already produced 162 malicious release artifacts and compromised thousands of systems worldwide.

Analyst 207
GitHub repository page on laptop screen with error message and blurred software development workspace background.

Miasma Worm Targets Microsoft GitHub Repositories in Supply Chain Attack

GitHub has taken swift action, disabling access to 73 Microsoft repositories across four organizations after a sneaky supply chain attack by the Miasma Worm compromised code on the platform. The disruption was triggered when the malware targeted Microsoft's GitHub repositories, prompting site-wide warnings and restricted access.

Analyst 207