#codeinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #codeinjection, aggregated by home.social.
-
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.
Pulse ID: 6a6a0753fc3cdb9a380c795d
Pulse Link: https://otx.alienvault.com/pulse/6a6a0753fc3cdb9a380c795d
Pulse Author: AlienVault
Created: 2026-07-29 13:59:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault
-
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.
Pulse ID: 6a6a0753fc3cdb9a380c795d
Pulse Link: https://otx.alienvault.com/pulse/6a6a0753fc3cdb9a380c795d
Pulse Author: AlienVault
Created: 2026-07-29 13:59:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault
-
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.
Pulse ID: 6a58813c09a76d1819c69bb0
Pulse Link: https://otx.alienvault.com/pulse/6a58813c09a76d1819c69bb0
Pulse Author: AlienVault
Created: 2026-07-16 06:59:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault
-
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.
Pulse ID: 6a58813c09a76d1819c69bb0
Pulse Link: https://otx.alienvault.com/pulse/6a58813c09a76d1819c69bb0
Pulse Author: AlienVault
Created: 2026-07-16 06:59:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault
-
#NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. https://venturebeat.com/security/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code?AIagents.at #AIagent #AI #ML #NLP #LLM #GenAI
-
#NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. https://venturebeat.com/security/nanoclaw-and-jfrog-launch-immune-system-to-block-ai-agents-from-downloading-malicious-code?AIagents.at #AIagent #AI #ML #NLP #LLM #GenAI
-
GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension
A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.
#Github #VsCode #SupplyChain #CodeInjection #ExtensionVulnerability
-
SAP Patches Critical Flaws in Commerce Cloud and S/4HANA
SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.
#SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity
-
GitHub swiftly patches flaw exposing millions of private repos
GitHub quickly squashed a massive security flaw, CVE-2026-3854, that could have let hackers access millions of private repositories with just one sneaky git push. The vulnerability allowed attackers to inject malicious code by exploiting how GitHub handled user-supplied options during git push operations.
#Github #Cve20263854 #SupplyChain #CodeInjection #EmergingThreats
-
Apache ActiveMQ Vulnerability Exploited, Hits 6,400 Servers
More than 6,400 publicly accessible Apache ActiveMQ servers are under attack, thanks to a high-severity code injection vulnerability that's being actively exploited. Is your server among them?
#ApacheActivemq #CodeInjection #VulnerabilityExploitation #EmergingThreats #ServerSecurity
-
🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
https://mariozechner.at/posts/2024-07-20-macos-code-injection-fun/ #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated -
🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
https://mariozechner.at/posts/2024-07-20-macos-code-injection-fun/ #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated -
🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! https://radar.offseq.com/threat/cve-2026-27497-cwe-94-improper-control-of-generati-7583bd72 #OffSeq #n8n #CodeInjection #Infosec
-
W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?
StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....
-
W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?
StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....
-
Why Names Break Systems - Web systems are designed to be simple and reliable. Designing for the everyday per... - https://hackaday.com/2025/08/05/why-names-break-systems/ #securityhacks #codeinjection #sqlinjection #apostrophe #webdesign #unicode #ascii
-
Why Names Break Systems - Web systems are designed to be simple and reliable. Designing for the everyday per... - https://hackaday.com/2025/08/05/why-names-break-systems/ #securityhacks #codeinjection #sqlinjection #apostrophe #webdesign #unicode #ascii
-
🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
https://boostsecurity.io/blog/weaponizing-dependabot-pwn-request-at-its-finest #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated -
🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
https://boostsecurity.io/blog/weaponizing-dependabot-pwn-request-at-its-finest #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated -
Developers and gamers, listen up! Hackers are now using trusted tools and platforms to sneak in malicious code and clever scams. How are your projects staying secure in this evolving threat landscape?
#cybersecurity
#infosectrends
#codeinjection
#socialengineering
#gamerssecurity -
Someone copied our GitHub project, added stars, and injected malicious code
https://old.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/
#HackerNews #GitHub #Security #CodeInjection #MaliciousCode #OpenSource #Community
-
Someone copied our GitHub project, added stars, and injected malicious code
https://old.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/
#HackerNews #GitHub #Security #CodeInjection #MaliciousCode #OpenSource #Community
-
Malicious NuGet Campaign Tricking Developers To Inject Malicious Code https://gbhackers.com/malicious-nuget-campaign-code-injection/ #supplychainattacks #CVE/vulnerability #CyberSecurityNews #CodeInjection #NuGetSecurity #CyberAttack #Malware
-
Malicious NuGet Campaign Tricking Developers To Inject Malicious Code https://gbhackers.com/malicious-nuget-campaign-code-injection/ #supplychainattacks #CVE/vulnerability #CyberSecurityNews #CodeInjection #NuGetSecurity #CyberAttack #Malware
-
Attack Using Fake Python Infrastructure
A sophisticated attack campaign was uncovered targeting the software supply chain and successfully exploiting multiple victims through account takeover, malicious code injection in repositories, and publishing of poisoned Python packages. The threat actors set up fake Python infrastructure to distribute malware that harvested sensitive data.
Pulse ID: 6602e45fbee5bc3d4c622ae3
Pulse Link: https://otx.alienvault.com/pulse/6602e45fbee5bc3d4c622ae3
Pulse Author: AlienVault
Created: 2024-03-26 15:06:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CodeInjection #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #SupplyChain #bot #AlienVault
-
Attack Using Fake Python Infrastructure
A sophisticated attack campaign was uncovered targeting the software supply chain and successfully exploiting multiple victims through account takeover, malicious code injection in repositories, and publishing of poisoned Python packages. The threat actors set up fake Python infrastructure to distribute malware that harvested sensitive data.
Pulse ID: 6602e45fbee5bc3d4c622ae3
Pulse Link: https://otx.alienvault.com/pulse/6602e45fbee5bc3d4c622ae3
Pulse Author: AlienVault
Created: 2024-03-26 15:06:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CodeInjection #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Python #SupplyChain #bot #AlienVault
-
The malware strategically injects a specialized script tag into the victim’s browser, leading to an external script, enhancing the attack’s stealth by avoiding detection as simple loader scripts often are.
#Cybersecurity #Trojan #CodeInjection #IBM #JavaScript #Banking
-
The malware strategically injects a specialized script tag into the victim’s browser, leading to an external script, enhancing the attack’s stealth by avoiding detection as simple loader scripts often are.
#Cybersecurity #Trojan #CodeInjection #IBM #JavaScript #Banking
-
The tagDiv plugin and the Newspaper theme are popular among WordPress users for their rich features and user-friendly design.
#WordPress #Cybersecurity #CodeInjection #Vulnerabilities #tagDiv #Plugins
https://cybersec84.wordpress.com/2023/10/10/new-balada-injector-attack-targets-wordpress-admins/
-
The tagDiv plugin and the Newspaper theme are popular among WordPress users for their rich features and user-friendly design.
#WordPress #Cybersecurity #CodeInjection #Vulnerabilities #tagDiv #Plugins
https://cybersec84.wordpress.com/2023/10/10/new-balada-injector-attack-targets-wordpress-admins/
-
📬 Twitter sammelt Nutzerdaten von über 70.000 Webseiten
#Datenschutz #Internet #Amazon #Audi #CodeInjection #ElonMusk #RestrictedDataUsage #Spotify #TwitterPixel #Volkswagen https://tarnkappe.info/artikel/datenschutz/twitter-sammelt-nutzerdaten-von-ueber-70-000-webseiten-260669.html -
📬 Twitter sammelt Nutzerdaten von über 70.000 Webseiten
#Datenschutz #Internet #Amazon #Audi #CodeInjection #ElonMusk #RestrictedDataUsage #Spotify #TwitterPixel #Volkswagen https://tarnkappe.info/artikel/datenschutz/twitter-sammelt-nutzerdaten-von-ueber-70-000-webseiten-260669.html -
Hey #infosec/#appsec peeps...
Ever wanted to work on #videogames? :) Cheat devs are using #hypervisor mods to do hard-to-detect #codeinjection and in-memory modification.
#Bungie needs a low-level security engineer to help develop strategies that can be implemented in game clients running on compromised hardware to detect, mitigate, and run psyops on cheaters and cheat devs.
If you like adversarial work, it's pretty awesome. Come talk to me :)
-
Nachdem das Problem bereits bei Facebook und Instagram aufgedeckt worden war, hat sich ein Sicherheitsforscher nun auch den chinesischen Videodienst angesehen.
Auch TikTok-App soll mit internem iPhone-Browser spionieren können -
Eine Schwachstelle der Luca-App hätte ganze Gesundheitsämter lahmlegen können. Nun kommt auch Kritik vom Bundesamt für Sicherheit in der Informationstechnik. BSI kritisiert ebenfalls Luca-App: "Angriffs-Szenario plausibel" -
Eine dem Anbieter bereits bekannte Sicherheitslücke der Luca-App kann ausgenutzt werden, um Schadcode einzuschleusen – und so Gesundheitsämter lahmzulegen. Gefahr für Gesundheitsämter: Luca-App ermöglicht Code Injection -
:firefox: Browser: Mozilla härtet Firefox gegen Code-Injection
📌 Das Security-Team von Mozilla will den Firefox-Browser besser gegen Code-Injection-Lücken härten, verzichtet dafür auf Inline-Aufrufe in den eigenen About-Seiten und hat die Nutzung der eval()-Funktion überarbeitet.
#Browser #Mozilla #Firefox #codeinjection #CodeInjectionLücken #Internet
https://www.golem.de/news/browser-mozilla-haertet-firefox-gegen-code-injection-1910-144413.html