#credentialstealer — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #credentialstealer, aggregated by home.social.
-
Malicious MemTensor Packages Spread sckit Credential Stealer via npm and PyPI
Beware: compromised MemTensor packages on npm and PyPI are spreading a sneaky credential stealer called sckit, which can steal your sensitive info. Malicious actors have hijacked these packages to secretly install the sckit malware, putting your credentials at risk.
#MalwareOperations #CredentialStealer #Sckit #Memtensor #Npm
-
A new npm supply chain attack hijacked keyv and dozens of packages, spreading Shai-Hulud malware that steals cloud and CI/CD secrets. Rotate keys now.
#npm #SupplyChainAttack #ShaiHulud #keyv #CredentialStealer #Malware #DevSecOps #CICD #CyberSecurity #InfoSec
-
Arch Linux AUR Packages Targeted in Credential Stealer Campaign
Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.
-
Arch Linux AUR Packages Targeted in Credential Stealer Campaign
Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.
-
Arch Linux AUR Packages Targeted in Credential Stealer Campaign
Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.
-
Arch Linux AUR Packages Targeted in Credential Stealer Campaign
Malicious actors have hijacked over 400 Arch Linux AUR packages, quietly altering their build scripts to deploy a sneaky Rust credential stealer in a campaign dubbed Atomic Arch. By targeting abandoned packages and preserving their original names and histories, the attackers cleverly evaded detection.
-
Malicious Laravel-Lang Packages Deliver Cross-Platform Credential Stealer
A massive wave of malicious Laravel-Lang packages, with over 700 versions released in just two days, has been used to spread a sneaky cross-platform credential stealer. Security researchers warn that multiple PHP packages from the Laravel-Lang organization were compromised, hinting at a large-scale breach of the organization's…
#MalwareOperations #Laravel #CredentialStealer #Php #SupplyChain
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
#SupplyChain-Angriff auf #TanStack: 42 Pakete kompromittiert | Developer https://www.heise.de/news/Supply-Chain-Angriff-auf-TanStack-42-Pakete-kompromittiert-11290715.html #npm #MiniShaiHulud #Patchday #CredentialStealer
-
Mini Shai-Hulud Worm Targets Multiple AI, Dev Packages
Meet the Mini Shai-Hulud worm, a sneaky new malware that's infiltrating AI and development packages through a clever supply-chain attack. This malicious code can steal sensitive data from cloud providers, cryptocurrency wallets, and even popular dev tools like GitHub Actions.
#SupplyChain #MalwareOperations #CredentialStealer #AiSecurity #Devsecops
-
PCPJack Credential Stealer Exploits CVEs to Spread Across Cloud Systems
Meet PCPJack, a sneaky credential stealer that's exploiting vulnerabilities to spread rapidly across cloud systems, swiping sensitive info from services like cloud, finance, and productivity tools. Its operators are after one thing: illicit financial gain.
#CredentialStealer #CloudSecurity #EmergingThreats #MalwareOperations #CredentialTheft
-
Malware Worm Exploits npm Packages to Hijack Developer Tokens
Meet CanisterSprawl, a sneaky self-propagating worm that's compromising npm packages and using stolen developer tokens to spread its reach. This malware goes beyond just stealing credentials, turning one infected environment into a web of additional package compromises.
#NpmMalware #SupplyChain #MalwareWorm #CredentialStealer #Canistersprawl
-
Oh no. Here we go again! Another wave of compromised #npm packages. Check your dependencies! This time it even deletes your home directory, if it does not find any secrets 😱
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
And it appears that the worm is quite successful again: https://github.com/search?q=sha1-hulud&type=repositories
#ShaiHulud #Malware #CredentialStealer #SupplyChain #SupplyChainAttack #InfoSec
-
Oh no. Here we go again! Another wave of compromised #npm packages. Check your dependencies! This time it even deletes your home directory, if it does not find any secrets 😱
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
And it appears that the worm is quite successful again: https://github.com/search?q=sha1-hulud&type=repositories
#ShaiHulud #Malware #CredentialStealer #SupplyChain #SupplyChainAttack #InfoSec
-
Oh no. Here we go again! Another wave of compromised #npm packages. Check your dependencies! This time it even deletes your home directory, if it does not find any secrets 😱
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
And it appears that the worm is quite successful again: https://github.com/search?q=sha1-hulud&type=repositories
#ShaiHulud #Malware #CredentialStealer #SupplyChain #SupplyChainAttack #InfoSec
-
Oh no. Here we go again! Another wave of compromised #npm packages. Check your dependencies! This time it even deletes your home directory, if it does not find any secrets 😱
https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
And it appears that the worm is quite successful again: https://github.com/search?q=sha1-hulud&type=repositories
#ShaiHulud #Malware #CredentialStealer #SupplyChain #SupplyChainAttack #InfoSec
-
Here’s how potent Atomic credential stealer is finding its way onto Macs - Ads prominently displayed on search engines are impersonatin... - https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/ #credentialstealer #malvertising #security #biz #atomic #apple #macos #amos
-
Here’s how potent Atomic credential stealer is finding its way onto Macs - Ads prominently displayed on search engines are impersonatin... - https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/ #credentialstealer #malvertising #security #biz #atomic #apple #macos #amos
-
Here’s how potent Atomic credential stealer is finding its way onto Macs - Ads prominently displayed on search engines are impersonatin... - https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/ #credentialstealer #malvertising #security #biz #atomic #apple #macos #amos
-
Here’s how potent Atomic credential stealer is finding its way onto Macs - Ads prominently displayed on search engines are impersonatin... - https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/ #credentialstealer #malvertising #security #biz #atomic #apple #macos #amos
-
Here’s how potent Atomic credential stealer is finding its way onto Macs - Ads prominently displayed on search engines are impersonatin... - https://arstechnica.com/security/2025/09/potent-atomic-credential-stealer-can-bypass-gatekeeper/ #credentialstealer #malvertising #security #biz #atomic #apple #macos #amos
-
Rhadamanthys Stealer has it's own web, I had missed that completely.
Yet another sign that the Stealer market is growing, maturing and getting increasingly professional and an important part of the ecosystem.
-
Rhadamanthys Stealer has it's own web, I had missed that completely.
Yet another sign that the Stealer market is growing, maturing and getting increasingly professional and an important part of the ecosystem.
-
Rhadamanthys Stealer has it's own web, I had missed that completely.
Yet another sign that the Stealer market is growing, maturing and getting increasingly professional and an important part of the ecosystem.
-
Rhadamanthys Stealer has it's own web, I had missed that completely.
Yet another sign that the Stealer market is growing, maturing and getting increasingly professional and an important part of the ecosystem.
-
Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?
Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.
Any hot takes?
-
Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?
Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.
Any hot takes?
-
Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?
Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.
Any hot takes?
-
Any thoughts on how many Credential Stealer families rely on using the Telegram API Bot endpoint for exfiltrating / copying information from infected devices?
Trying to assess the potential for leveraging that observation for some simple detection rules of potential stealer infections.
Any hot takes?