Articles tagged "Malware"

Found 827 articles

A significant supply-chain attack has compromised 440 software packages in under four hours, with researchers identifying a variant of Mini Shai-Hulud malware linked to the hacking group TeamPCP. This malware is self-replicating, posing a serious risk to organizations that use these affected packages. The incident raises concerns about the security of software supply chains, as attackers can exploit vulnerabilities to distribute malicious code widely. Companies relying on these packages need to assess their systems and consider implementing stronger security measures to prevent similar attacks in the future. The rapid nature of this breach highlights the urgent need for vigilance in monitoring software dependencies.

Read Original

Recently, researchers uncovered a series of malicious npm packages specifically designed to target developers using Alibaba tools. These packages contain a cross-platform remote access trojan (RAT), which allows attackers to gain unauthorized access to infected systems. The threat primarily affects developers working within the Alibaba ecosystem, raising significant security concerns for users who might inadvertently download and execute these harmful packages. This incident underscores the ongoing risks associated with open-source software repositories and highlights the importance of vigilance when managing dependencies. Developers are advised to verify the integrity of the packages they use to avoid falling victim to such attacks.

Read Original
Actively Exploited

Roblox players are being targeted by fake installers for a tool called Xeno Executor, which is used for executing scripts in the game. These counterfeit installers are actually malware that can give attackers remote access to users' devices and steal sensitive information. This situation poses a significant risk to the personal data of unsuspecting players, especially younger users who may not be as cautious about downloading software. Users should be wary of unofficial downloads and only obtain software from trusted sources to protect themselves from these malicious attacks. Keeping security software updated and being vigilant about what is installed on their devices is crucial for players to avoid falling victim to these scams.

Read Original

A new variant of the XCSSET malware has emerged, specifically targeting macOS developers by exploiting compromised Xcode projects and GitHub repositories. This malware is designed to infiltrate the development environment, potentially affecting thousands of users who download these compromised projects. Researchers have identified that the malware can steal sensitive information, including user credentials and private data, which poses a significant risk to both developers and their end users. As this malware spreads, it raises concerns about the security of development tools and the integrity of software supply chains. Developers are urged to be vigilant about the sources of their code and to implement security measures to protect their environments.

Read Original
Critical
Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

The Shai-Hulud npm worm has resurfaced, infecting over 1,280 npm packages that collectively receive around 2 billion downloads each month. This malware is designed to steal sensitive credentials from various platforms, including npm, GitHub, cloud services, and continuous integration (CI) tools, in real-time. The worm spreads through Keyv and other related packages, posing a significant risk to developers and organizations that rely on these tools for their software development processes. With the potential for widespread credential theft, users need to be vigilant and consider enhancing their security measures to protect their accounts. The incident serves as a reminder of the vulnerabilities that can arise within popular development ecosystems.

Read Original
Actively Exploited

A recent supply chain attack known as Keyv has affected over 400 npm packages, potentially putting numerous developers and projects at risk. This attack is believed to be linked to a group or technique referred to as Mini Shai-Hulud. The compromised packages could allow attackers to inject malicious code into applications that rely on these libraries, creating vulnerabilities that could be exploited in various ways. As npm is a widely used package manager in the JavaScript ecosystem, the scale of this attack raises significant concerns for developers and companies that depend on these packages for their applications. The incident underscores the ongoing challenges in securing software supply chains and the need for vigilance among developers to ensure their dependencies are safe.

Read Original

A new self-propagating malware called 'ChainDrop' has infected over 1,300 packages in the Node Package Manager (npm) registry, which collectively see around 2 billion downloads each month. This attack allows the malware to spread rapidly across various software projects that rely on npm packages. Developers and companies using these compromised packages are at risk of introducing vulnerabilities into their applications. The incident raises significant concerns about supply chain security, as it demonstrates how a single attack can impact a vast number of users and systems. Those affected should take immediate steps to identify and remove the compromised packages from their projects to mitigate potential damage.

Read Original

A credential-stealing worm linked to the npm package 'keyv' has spread to hundreds of packages since it was first identified on August 4, 2026. This malware has affected at least 868 packages according to Aikido, with SafeDep confirming 353 poisoned versions across 79 package names in the npm registry. The worm is designed to steal user credentials and has also incorporated hooks for the Claude code and Visual Studio Code environments. This incident raises serious concerns for developers and organizations using these packages, as compromised libraries can lead to significant security breaches and data loss. Users are urged to audit their dependencies and ensure they are using safe versions of affected packages.

Read Original

A new Russian malware delivery service known as DOUBLECUP is utilizing a technique called ClickFix to infect users. This method involves embedding malware within PNG images that are stored in victims' browser caches. Once the PNG is loaded, it extracts hidden data and executes two types of malware: CountLoader and a new remote access trojan (RAT) called DeviceManager. This approach allows attackers to bypass traditional security measures and effectively deliver their payloads without raising immediate alarms. Users who fall victim to this scheme could face significant security risks, as the RATs can provide attackers with extensive control over infected devices.

Read Original
Actively Exploited

In a recent interview, Brian Hill, Field CISO at BlackCloak, discussed the growing risks that CEOs face from cyber attacks targeting their personal lives. He detailed an incident where a draft report was found in an executive’s unsecured personal email, leading to traders acting on inside information before it was publicly released. Hill also pointed out vulnerabilities stemming from an open home network after a technician’s visit and malware risks from hotel Wi-Fi connections. This conversation emphasizes the need for companies to implement strong digital security measures around their executives, as these personal vulnerabilities can have significant implications for business operations and market integrity.

Read Original

A new malware threat targeting Roblox players has emerged, disguised as a fake Xeno Executor installer. This malicious software not only grants attackers remote access to victims' systems but also steals sensitive information. Players looking to enhance their gaming experience are falling victim to this trap, putting their personal data at risk. The malware is particularly concerning as it exploits the popularity of Roblox, a platform widely used by younger audiences. Users need to be vigilant about the sources from which they download software to avoid becoming targets of such attacks.

Read Original

Researchers have identified a series of malicious npm packages that are specifically targeting users of Alibaba developer tools. This attack involves a cross-platform remote access trojan (RAT) and is part of a broader software supply chain attack aimed at Chinese-speaking environments. One notable package among those discovered is 'lib-mtop,' which shares its name with a private Alibaba package, suggesting a deliberate attempt to deceive users. The implications of this attack are significant, as it could allow attackers to gain unauthorized access to sensitive systems and data. Users of Alibaba tools should be particularly vigilant and consider reviewing their package dependencies to ensure they are not using any compromised versions.

Read Original

South Korean authorities have issued a warning about phishing attacks linked to nation-state actors. These attacks involve individuals posing as job applicants who send resumes embedded with malicious links. In some cases, attackers impersonate recruiters and send password-protected ZIP files that contain malware. This tactic puts job seekers and companies at risk, as malicious actors exploit the trust associated with job applications to deliver harmful software. Organizations and users need to be vigilant and cautious with unsolicited job-related communications, especially those requesting personal information or containing unexpected attachments.

Read Original
Actively Exploited

Researchers from Flare have examined the underground market for BTMOB, a type of Android malware. Their analysis revealed a complex network of resellers, vendors offering source code, and various customized versions of the malware being sold across different platforms. This fragmentation indicates that the malware operation has evolved significantly, with multiple players now involved in its distribution and refinement. The implications are serious, as this could lead to more widespread attacks on Android users, putting sensitive data at risk. Understanding this ecosystem is crucial for cybersecurity professionals who need to combat the increasing sophistication of mobile threats.

Read Original
Actively Exploited

A Russian cyber group known as Storm-2945 has been targeting travelers by hijacking hotel captive portals. These portals, which are the web pages that guests see when trying to access the internet in hotels, have been manipulated to deliver fake updates. When users attempt to connect to the Wi-Fi, they are prompted to download these updates, which actually steal their session tokens. This attack affects anyone using hotel Wi-Fi, putting personal information at risk. Users need to be cautious when connecting to public networks and avoid downloading software from unverified sources, as this method can lead to credential theft and unauthorized access to accounts.

Read Original
PreviousPage 8 of 56Next