home.social

#credentialstealer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #credentialstealer, aggregated by home.social.

  1. Oh no. Here we go again! Another wave of compromised #npm packages. Check your dependencies! This time it even deletes your home directory, if it does not find any secrets 😱

    aikido.dev/blog/shai-hulud-str

    And it appears that the worm is quite successful again: github.com/search?q=sha1-hulud

    #ShaiHulud #Malware #CredentialStealer #SupplyChain #SupplyChainAttack #InfoSec

  2. Rhadamanthys Stealer has it's own web, I had missed that completely.

    Yet another sign that the Stealer market is growing, maturing and getting increasingly professional and an important part of the ecosystem.

    #ThreatIntelligence #Stealer #CredentialStealer #Malware

  3. Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?

    Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.

    Any hot takes?

    [ #ThreatIntel #DetectionEngineering #CredentialStealer ]