MemTensor Package Compromise Exposes Developers To Cross Platform Credential Stealer
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Security researchers identify compromised MemTensor npm and PyPI packages delivering sckit malware designed to steal developer credentials and sensitive cloud data.
Trezor disclosed that a ShipMonk breach exposed data of 67,000 U.S. customers, including names, emails, phone numbers, addresses, and order details.
Cybersecurity researchers discovered 14 npm packages hiding RedC2 4.0 Linux backdoor with AI assisted C2 capabilities, enabling post exploitation activities.
CloudSEK has revealed that malicious LiteLLM releases linked to the Trivy supply chain attack may have exposed more than 2,100 organizations by stealing cloud credentials, API keys, and other sensitive secrets.
Researchers have identified a new modular Cavern command and control framework used by an Iran linked hacking group to target government and IT organizations through supply chain attacks, advanced malware, and post exploitation techniques.
Security researchers have uncovered malicious npm packages posing as PostCSS tools that deploy a Windows remote access trojan, highlighting ongoing software supply chain threats targeting developers and open source ecosystems.
Researchers have uncovered a supply chain attack targeting the Mastra npm ecosystem, where more than 140 packages were compromised through a hijacked contributor account and a malicious dependency designed to steal cryptocurrency wallet data and sensitive credentials.
Cybersecurity researchers uncover North Korea linked campaigns abusing GitHub repositories and Visual Studio Code projects to distribute malware targeting developers across multiple industries.
Trusted JavaScript files linked to PushEngage, OptinMonster, and TrustPulse were tampered with in a supply chain attack, potentially exposing over 1.2 million WordPress sites to hidden backdoors.
More than 400 Arch Linux AUR packages were hijacked in a supply chain attack that deployed an infostealer and optional eBPF rootkit targeting developer credentials and sensitive systems.