Threat Intelligence — Page 20

Booby-trapped jscrambler npm release runs infostealer the moment you install it
Version 8.14.0 of a popular JavaScript protection package shipped with a hidden payload that fires during install, no code changes required from the developer.

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm
A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

DHS Database Breached, Adobe Speeds Up Patches, and Canada Shuts Down Ransomware Groups
A busy week in security news brought a breach at a US government agency, a faster fix schedule from a major software maker, and a Canadian crackdown on ransomware criminals. Here is what you need to know.

Silver Fox's New MODBEACON Trojan Hides Inside Fake Software Installers
The China-linked group is using booby-trapped downloads to plant a Rust-built remote-control tool that talks to its handlers over encrypted channels.

Cybercrime Crew Leaves Its Own Server Wide Open, Exposing 1.4 Million Website Target List
A misconfigured server ran unprotected for three weeks, handing researchers a rare look inside a mass WordPress hacking operation now tracked as WP-SHELLSTORM.

GigaWiper: The Swiss Army Knife of Destructive Malware
A newly named piece of malicious software has been quietly spreading for over eight months, combining spying tools, file destroyers, and fake-ransomware tricks inside a single package.

Microsoft Exposes GigaWiper, a New Malware That Spies on Victims Before Destroying Them
A newly discovered backdoor called GigaWiper quietly watches infected computers for months, then wipes or encrypts everything on command, with no way to recover the data.

Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware
A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

Ghanaian Influencer Extradited to US Over $8 Million Romance Scam Targeting Elderly Americans
Frederick Kumi, known online as Abu Trica, allegedly used AI-generated fake identities to defraud older Americans out of more than $8 million. His extradition is now the subject of a constitutional dispute in Ghana.

Your Business Is Not Too Small to Be an Iranian Hacker's Next Target
Groups linked to Iran's intelligence services are not hand-picking victims. They are scanning the internet for any door left unlocked, and a GPS company and a medical-device maker have already paid the price.

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours
A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

Microsoft Pulls Apart 'GigaWiper', a Windows Backdoor That's Really Three Old Wreckers in a Trench Coat
The malware lets its operator pick how to trash a machine: wipe the disk, kill the Windows drive, or fake a ransomware attack with a key that's thrown away.

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies
Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

Helix: the new extortion crew phoning staff to raid SharePoint files
Researchers at ReliaQuest say the group impersonates managers on the phone, tricks staff into a login trap, then hoovers up company documents from Microsoft SharePoint.