Tag: Malicious
-
Malicious Hugging Face Models Could Trigger Remote Code Execution
A flaw in Hugging Face Transformers could allow malicious AI models to execute code, exposing credentials and highlighting AI supply chain …
-
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor …
-
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of …
-
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. …
-
Malicious VS Code Extension Allegedly Opens Door To Massive GitHub Repository Breach
Attackers claiming to be TeamPCP allege they breached GitHub through a malicious Visual Studio Code extension, exposing nearly 4,000 …
-
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to …
-
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages …
-
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the …
-
Malicious Open Source npm Packages Breach OpenAI Employee Devices
OpenAI said no customer data was compromised after attackers used malicious open-source TanStack npm packages to target employee devices in …
-
Malicious Hugging Face Repository Typosquats OpenAI
Security researchers have uncovered covert infostealer malware hidden in one of the top-ranking repositories on Hugging Face, in another …
-
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub …
-
Malicious trading website drops malware that hands your browser to attackers
During our threat hunting, we found a campaign using the same malware loader from our previous research to deliver a different threat: …
●●●
