A campaign distributing nearly 800 malicious npm packages with typo-squatted AI-generated names delivers a powerful RAT and infostealer targeting Windows, Mac, and Linux environments, posing a significant threat to developers and enterprises using npm packages.
The ChainDrop malware has compromised over 1,300 npm packages, impacting software supply chain security with billions of downloads monthly.
Talos analyzed prompt logs from various AI applications used by threat actors to understand their evolving tactics, revealing increased sophistication in leveraging cloud-based AI for malicious activities.
The DOUBLECUP loader uses ClickFix attacks to embed malware within PNG images cached by browsers on Windows and macOS, complicating detection.
A suspected Chinese-speaking threat actor has targeted Central Asian government organizations with OctLurk and SilkLurk malware since January 2025, impacting healthcare, research, and government sectors.
The Russian threat group Midnight Blizzard's Storm-2945 sub-cluster has compromised hospitality sign-in portals worldwide since May 2026, delivering malware and stealing traveler credentials.
North Korean threat actors have launched a sophisticated macOS malvertising campaign using fake update prompts to deliver crypto-stealing malware as part of the ongoing Contagious Interview operation.
Iranian state-backed group Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers in attacks across the Middle East, Africa, and South Asia, enhancing stealth and covert activity.
CERT-UA has identified a campaign where a fake Notepad++ plugin delivers MATCHBOIL.V2 malware, linked to the Russia-aligned UAC-0099 threat group targeting Windows systems.
Nearly 7,600 malicious GitHub repositories were discovered distributing the SmartLoader malware, leveraging cloned projects and fake profiles to deceive users.
North Korean threat actors linked to the Contagious Interview campaign employ steganography within SVG flag images in fake coding challenges to deliver multi-stage OTTERCOOKIE-aligned malware.
Seven malicious npm packages in the Vite ecosystem use a four-tier blockchain-based command-and-control infrastructure to deploy RAT malware, expanding the ChainVeil supply chain threat.
The OkoBot malware framework deploys more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data, posing a notable threat to individuals and enterprises.
Researchers revealed TuxBot v3 Evolution, an IoT botnet framework apparently developed with help from a large language model, highlighting emerging AI-assisted malware creation risks.
A malicious version of the Jscrambler npm package containing infostealer malware was published and downloaded nearly 1,500 times, posing risks to developers and users of this client-side security tool.
Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets.
Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines.
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data.
Threat actors are impersonating IT support via Microsoft Teams voice calls to trick employees into installing EtherRAT malware, compromising corporate networks. This tactic enables attackers to gain initial access and conduct further intrusion.