Malicious
- REVIEWS
A look at slopsquatting, a supply chain attack where threat actors create malicious packages on indexes using AI-hallucinated names resembling popular libraries (Bill Toulas/BleepingComputer)
Featured Podcasts Lenny’s Podcast: Everyone’s an engineer now: Inside v0’s mission to create a hundred million builders | Guillermo Rauch…
Read More » - APPLICATIONS
Malicious npm Package Targets Atomic Wallet, Exodus Users by Swapping Crypto Addresses
î ‚Apr 10, 2025î „Ravie LakshmananMalware / Cryptocurrency Threat actors are continuing to upload malicious packages to the npm registry so as…
Read More » - APPLICATIONS
UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine
The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed a new set of cyber attacks targeting Ukrainian institutions with…
Read More » - APPLICATIONS
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
î ‚Apr 05, 2025î „Ravie LakshmananMalware / Supply Chain Attack The North Korean threat actors behind the ongoing Contagious Interview campaign are…
Read More » - APPLICATIONS
Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data
î ‚Apr 05, 2025î „Ravie LakshmananMalware / Supply Chain Attack Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI)…
Read More » - APPLICATIONS
Malicious npm Package Modifies Local ‘ethers’ Library to Launch Reverse Shell Attacks
î ‚Mar 26, 2025î „Ravie LakshmananSupply Chain Attack / Malware Cybersecurity researchers have discovered two malicious packages on the npm registry that…
Read More » - APPLICATIONS
Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates
î ‚Mar 21, 2025î „Ravie LakshmananRansomware / BYOVD The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a…
Read More » - APPLICATIONS
New ‘Rules File Backdoor’ Attack Lets Hackers Inject Malicious Code via AI Code Editors
î ‚Mar 18, 2025î „Ravie LakshmananAI Security / Software Security Cybersecurity researchers have disclosed details of a new supply chain attack vector…
Read More » - APPLICATIONS
Malicious PyPI Packages Stole Cloud Tokens—Over 14,100 Downloads Before Removal
î ‚Mar 15, 2025î „Ravie Lakshmanan Malware / Supply Chain Security Cybersecurity researchers have warned of a malicious campaign targeting users of…
Read More »