Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into…
Tag: MALWARE
Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Malvertising Campaign Uses Fake Crypto Websites to Build Malware Directly in Browser Memory
A major malvertising campaign targets crypto investors and traders with fake Solana, Luno and TradingView sites offering to install malicious JavaScript…
Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID
A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to…
Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan…
Google Begins Restoring Blogger Sites After False Malware Alerts
Google is restoring Blogger sites wrongly flagged for malware after hundreds of publishers reported locked or unavailable blogs and false-positive alerts.
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to…
250+ ClickFix Domains Hide macOS Malware From Security Scanners
A ClickFix campaign uses browser fingerprinting across more than 250 domains to hide macOS infostealer lures from scanners and security researchers.
China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
Researchers linked the latest malicious activity to a Chinese company, after one of the spyware’s operators placed an order with KFC using their real name…
Hackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise Endpoints
A novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS), the trusted patch-management architecture widely deployed…
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an…
Hackers Turn Ethereum Smart Contract Into Dead-Drop Resolver for Remus Malware
Hackers are abusing an Ethereum smart contract as a dead‑drop resolver to dynamically steer victims’ browsers to rotating command‑and‑control (C2)…
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a…
Google Blogger Locked Legitimate Websites After Mistaking Them for Malware
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP…
Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP…
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems,…
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation.