#svg — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #svg, aggregated by home.social.
-
-
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
GAME BOY - GAME BOX TEMPLATE
I could not find a good file for game boy color box. So using a scan and some deduction I recreated the template myself!
Now it will be super easy to just swap designs for future releases.
Download for free: https://cdn.cyfrowynomada.com/templates/game-boy-game-box-template.svg
-
GAME BOY - GAME BOX TEMPLATE
I could not find a good file for game boy color box. So using a scan and some deduction I recreated the template myself!
Now it will be super easy to just swap designs for future releases.
Download for free: https://cdn.cyfrowynomada.com/templates/game-boy-game-box-template.svg
-
RE: https://floss.social/@igalia/116963760482026159
Nikolas Zimmermann is doing an exceptional work around #SVG for the #webkit project in general. And he is a wonderful voice on the W3C SVG WG to make progress on the SVG 2 spec. Go read his two blog posts. We need more of these in the browsers world.
-
RE: https://floss.social/@igalia/116963760482026159
Nikolas Zimmermann is doing an exceptional work around #SVG for the #webkit project in general. And he is a wonderful voice on the W3C SVG WG to make progress on the SVG 2 spec. Go read his two blog posts. We need more of these in the browsers world.
-
Our colleague Nikolas Zimmermann (of KSVG fame) has two very interesting posts on the Layer-Based #SVG Engine (LBSE) he’s been implementing. The first post covers the steps he’s taken to reduce layer overhead; the second gets into the details of compositing. Worth your time if you’ve ever written SVG, or if you’re interested in how browsers render things that aren’t HTML and CSS!
https://blogs.igalia.com/nzimmermann/posts/2026-07-14-lbse-conditional-layers/
https://blogs.igalia.com/nzimmermann/posts/2026-07-22-lbse-paint-order-segments/ -
Our colleague Nikolas Zimmermann (of KSVG fame) has two very interesting posts on the Layer-Based #SVG Engine (LBSE) he’s been implementing. The first post covers the steps he’s taken to reduce layer overhead; the second gets into the details of compositing. Worth your time if you’ve ever written SVG, or if you’re interested in how browsers render things that aren’t HTML and CSS!
https://blogs.igalia.com/nzimmermann/posts/2026-07-14-lbse-conditional-layers/
https://blogs.igalia.com/nzimmermann/posts/2026-07-22-lbse-paint-order-segments/ -
✏️ InfiniPaint — приложение для совместного создания заметок и рисования на холсте с бесконечным пространством и возможностью масштабирования
©️ Бесплатная и с открытым исходным кодом программа
⬇️ Установка: Flatpak пакета, EXE (Windows), DMG (macOS), Android (APK), веб-версия
-
✏️ InfiniPaint — приложение для совместного создания заметок и рисования на холсте с бесконечным пространством и возможностью масштабирования
©️ Бесплатная и с открытым исходным кодом программа
⬇️ Установка: Flatpak пакета, EXE (Windows), DMG (macOS), Android (APK), веб-версия
-
I've just had a terrible idea involving programmatic #SVG and clip paths.
I don't know if it's actually an awesome idea in disguise. Regardless, I've moved it up the #programming #sideproject queue quite a bit in the last hour. -
A Mercator map claimed to divide humanity into two equal geographic groups. My wife asked what it would look like using the Equal Earth projection--so I rebuilt it from an SVG, GeoNames population data, awk, a spreadsheet, and a little CSS. The highlighted countries contain 49.65% of the listed world population.
https://salemdata.net/johnpress/?p=1113
#Cartography #EqualEarth #Mercator #DataVisualization #SVG #OpenData #Linux #awk
-
A Mercator map claimed to divide humanity into two equal geographic groups. My wife asked what it would look like using the Equal Earth projection--so I rebuilt it from an SVG, GeoNames population data, awk, a spreadsheet, and a little CSS. The highlighted countries contain 49.65% of the listed world population.
https://salemdata.net/johnpress/?p=1113
#Cartography #EqualEarth #Mercator #DataVisualization #SVG #OpenData #Linux #awk
-
A Mercator map claimed to divide humanity into two equal geographic groups. My wife asked what it would look like using the Equal Earth projection--so I rebuilt it from an SVG, GeoNames population data, awk, a spreadsheet, and a little CSS. The highlighted countries contain 49.65% of the listed world population.
https://salemdata.net/johnpress/?p=1113
#Cartography #EqualEarth #Mercator #DataVisualization #SVG #OpenData #Linux #awk
-
A Mercator map claimed to divide humanity into two equal geographic groups. My wife asked what it would look like using the Equal Earth projection--so I rebuilt it from an SVG, GeoNames population data, awk, a spreadsheet, and a little CSS. The highlighted countries contain 49.65% of the listed world population.
https://salemdata.net/johnpress/?p=1113
#Cartography #EqualEarth #Mercator #DataVisualization #SVG #OpenData #Linux #awk
-
A Mercator map claimed to divide humanity into two equal geographic groups. My wife asked what it would look like using the Equal Earth projection--so I rebuilt it from an SVG, GeoNames population data, awk, a spreadsheet, and a little CSS. The highlighted countries contain 49.65% of the listed world population.
https://salemdata.net/johnpress/?p=1113
#Cartography #EqualEarth #Mercator #DataVisualization #SVG #OpenData #Linux #awk
-
SVG filters on type. @carmenansio shows how SVG filter primitives recreate historical printing effects on web: feMorphology draws true outer strokes, stacked feOffset layers extrude letters into 3D, feSpecularLighting mimics light on raised type, and feDisplacementMap with feTurbulence distorts text organically. She builds gilded initials, chromatic splits, neon glow, and gooey letter merging, with notes on sRGB blending and performance. #svg #typography
-
SVG filters on type. @carmenansio shows how SVG filter primitives recreate historical printing effects on web: feMorphology draws true outer strokes, stacked feOffset layers extrude letters into 3D, feSpecularLighting mimics light on raised type, and feDisplacementMap with feTurbulence distorts text organically. She builds gilded initials, chromatic splits, neon glow, and gooey letter merging, with notes on sRGB blending and performance. #svg #typography
-
SVG-фильтры для текста. Кармен Ансио показывает, как примитивы SVG-фильтров воссоздают исторические типографские эффекты: feMorphology рисует настоящую внешнюю обводку, наложенные слои feOffset придают буквам объём, feSpecularLighting имитирует свет на рельефе, а feDisplacementMap с feTurbulence органично искажает текст. Она собирает золочёные буквицы, хроматические сдвиги, неоновое свечение и слияние букв, с заметками о sRGB и производительности. #svg #typography
-
SVG-фильтры для текста. Кармен Ансио показывает, как примитивы SVG-фильтров воссоздают исторические типографские эффекты: feMorphology рисует настоящую внешнюю обводку, наложенные слои feOffset придают буквам объём, feSpecularLighting имитирует свет на рельефе, а feDisplacementMap с feTurbulence органично искажает текст. Она собирает золочёные буквицы, хроматические сдвиги, неоновое свечение и слияние букв, с заметками о sRGB и производительности. #svg #typography
-
Mermaid как платная AI функция в проекте Django/Next
Mermaid это текстовый формат описания диаграмм. В строках задаются тип схемы, узлы и связи. На выходе получается SVG. Формат подходит для API и базы данных. Код можно сгенерировать, проверить, сохранить, открыть повторно и отрендерить на клиенте. В mermind/ views.py добавлен 503 , если ответ модели не начинается с валидной головы Mermaid. Без этой проверки запрос завершается успешно, ответ от модели приходит, но диаграмма не строится. В ответе остаются fenced-блоки, Markdown, строки с # , служебный текст и фрагменты до первой строки диаграммы. В проекте собран полный серверный и клиентский контур. Генерация, очистка ответа, проверка, рендер, повторная правка, сохранение и библиотека. Как извлекать Mermaid-код из ответа модели. Ответ сначала режется до fenced-блока. Потом проверяется первая строка.
https://habr.com/ru/articles/1061160/
#Mermaid #Nextjs #Django #TypeScript #OpenRouter #LLM #AI #Fullstack #API #SVG
-
Mermaid как платная AI функция в проекте Django/Next
Mermaid это текстовый формат описания диаграмм. В строках задаются тип схемы, узлы и связи. На выходе получается SVG. Формат подходит для API и базы данных. Код можно сгенерировать, проверить, сохранить, открыть повторно и отрендерить на клиенте. В mermind/ views.py добавлен 503 , если ответ модели не начинается с валидной головы Mermaid. Без этой проверки запрос завершается успешно, ответ от модели приходит, но диаграмма не строится. В ответе остаются fenced-блоки, Markdown, строки с # , служебный текст и фрагменты до первой строки диаграммы. В проекте собран полный серверный и клиентский контур. Генерация, очистка ответа, проверка, рендер, повторная правка, сохранение и библиотека. Как извлекать Mermaid-код из ответа модели. Ответ сначала режется до fenced-блока. Потом проверяется первая строка.
https://habr.com/ru/articles/1061160/
#Mermaid #Nextjs #Django #TypeScript #OpenRouter #LLM #AI #Fullstack #API #SVG
-
Mermaid как платная AI функция в проекте Django/Next
Mermaid это текстовый формат описания диаграмм. В строках задаются тип схемы, узлы и связи. На выходе получается SVG. Формат подходит для API и базы данных. Код можно сгенерировать, проверить, сохранить, открыть повторно и отрендерить на клиенте. В mermind/ views.py добавлен 503 , если ответ модели не начинается с валидной головы Mermaid. Без этой проверки запрос завершается успешно, ответ от модели приходит, но диаграмма не строится. В ответе остаются fenced-блоки, Markdown, строки с # , служебный текст и фрагменты до первой строки диаграммы. В проекте собран полный серверный и клиентский контур. Генерация, очистка ответа, проверка, рендер, повторная правка, сохранение и библиотека. Как извлекать Mermaid-код из ответа модели. Ответ сначала режется до fenced-блока. Потом проверяется первая строка.
https://habr.com/ru/articles/1061160/
#Mermaid #Nextjs #Django #TypeScript #OpenRouter #LLM #AI #Fullstack #API #SVG
-
Contagious Interview malware in SVG images: DPRK campaign
Pulse ID: 6a5daa159afa8ff8f48b9816
Pulse Link: https://otx.alienvault.com/pulse/6a5daa159afa8ff8f48b9816
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #SVG #bot #Tr1sa111
-
Contagious Interview malware in SVG images: DPRK campaign
Pulse ID: 6a5daa159afa8ff8f48b9816
Pulse Link: https://otx.alienvault.com/pulse/6a5daa159afa8ff8f48b9816
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #SVG #bot #Tr1sa111
-
Contagious Interview malware in SVG images: DPRK campaign
Pulse ID: 6a5daa159afa8ff8f48b9816
Pulse Link: https://otx.alienvault.com/pulse/6a5daa159afa8ff8f48b9816
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #SVG #bot #Tr1sa111
-
Contagious Interview malware in SVG images: DPRK campaign
Pulse ID: 6a5daa159afa8ff8f48b9816
Pulse Link: https://otx.alienvault.com/pulse/6a5daa159afa8ff8f48b9816
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #SVG #bot #Tr1sa111
-
Contagious Interview malware in SVG images: DPRK campaign
Pulse ID: 6a5daa159afa8ff8f48b9816
Pulse Link: https://otx.alienvault.com/pulse/6a5daa159afa8ff8f48b9816
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #SVG #bot #Tr1sa111
-
🦖 specularExponent 🦖
https://developer.mozilla.org/en-US/docs/Web/SVG/Reference/Attribute/specularExponent
The specularExponent attribute controls the focus for the light source. The bigger the value the brighter the light.
-
🦖 specularExponent 🦖
https://developer.mozilla.org/en-US/docs/Web/SVG/Reference/Attribute/specularExponent
The specularExponent attribute controls the focus for the light source. The bigger the value the brighter the light.
-
🦖 specularExponent 🦖
https://developer.mozilla.org/en-US/docs/Web/SVG/Reference/Attribute/specularExponent
The specularExponent attribute controls the focus for the light source. The bigger the value the brighter the light.
-
🦖 specularExponent 🦖
https://developer.mozilla.org/en-US/docs/Web/SVG/Reference/Attribute/specularExponent
The specularExponent attribute controls the focus for the light source. The bigger the value the brighter the light.
-
🦖 specularExponent 🦖
https://developer.mozilla.org/en-US/docs/Web/SVG/Reference/Attribute/specularExponent
The specularExponent attribute controls the focus for the light source. The bigger the value the brighter the light.
-
https://github.com/yannchemin/svg2grass.symbol
Converts simple #SVG icons into #GRASSGIS 's #native #vector #symbol #format, the small text grammar read by d.vect icon= (VERSION/BOX/POLYGON/RING/STRING/LINE/ARC). #GRASS has no SVG symbol support at all, so this fills that gap for anyone who wants to render SVG-designed icons as GRASS point/centroid symbols. -
https://github.com/yannchemin/svg2grass.symbol
Converts simple #SVG icons into #GRASSGIS 's #native #vector #symbol #format, the small text grammar read by d.vect icon= (VERSION/BOX/POLYGON/RING/STRING/LINE/ARC). #GRASS has no SVG symbol support at all, so this fills that gap for anyone who wants to render SVG-designed icons as GRASS point/centroid symbols. -
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault
-
Contagious Interview malware in SVG images: DPRK campaign
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.
Pulse ID: 6a5a8ba0229db5a5b2686baa
Pulse Link: https://otx.alienvault.com/pulse/6a5a8ba0229db5a5b2686baa
Pulse Author: AlienVault
Created: 2026-07-17 20:08:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #DPRK #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RemoteAccessTrojan #SVG #Steganography #SupplyChain #Trojan #bot #cryptocurrency #developers #AlienVault