#troll — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #troll, aggregated by home.social.
-
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
Pulse ID: 6a87f29d5dfdc80aeece5470
Pulse Link: https://otx.alienvault.com/pulse/6a87f29d5dfdc80aeece5470
Pulse Author: Tr1sa111
Created: 2026-08-21 06:39:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Troll #bot #Tr1sa111
-
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
N4D Mesh Controller is an active Linux malware campaign exploiting exposed Model Context Protocol (MCP) servers and various internet-facing services for credential theft, lateral movement, and command and control. First documented in June 2026, recent analysis reveals evolved tactics including a new loader-to-agent chain, rotated infrastructure using IP 209.99.186.235, and an agent labeled "33.8-go-titan" that enumerates MCP tools and executes commands. The campaign automates discovery and abuse of dangerous MCP capabilities, particularly command execution tools, without requiring traditional vulnerabilities. The agent establishes persistence through multiple mechanisms including cron entries, systemd units, SSH keys, and watchdog scripts, while scanning for additional targets across databases, container platforms, AI infrastructure including Ray Dashboard and LightLLM, and cloud services. Secondary access is maintained through Cloudflare Quick Tunnels.
Pulse ID: 6a873496e3b94c2a2c962d39
Pulse Link: https://otx.alienvault.com/pulse/6a873496e3b94c2a2c962d39
Pulse Author: AlienVault
Created: 2026-08-20 17:08:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ICS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #SMS #SSH #Troll #WatchDog #bot #AlienVault
-
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket identified a coordinated campaign involving 77 Firefox extensions designed to steal cryptocurrency wallet secrets and credentials. The operation, tracked as 'Offside Wallet Theft Factory', includes 40 confirmed malicious extensions that exfiltrate recovery phrases, private keys, and credentials through Supabase-controlled remote switches, Cloudflare Workers, and hardcoded command-and-control infrastructure. An additional 37 deceptive sports-score shells share publishing artifacts and version histories showing transitions from benign utilities into wallet-stealing malware. The campaign operated from at least March 2026 through August 2026, targeting Web3 users through impersonations of OKX, Rabby Wallet, TronLink, and other cryptocurrency products. Extensions capture secrets through phishing interfaces, modified wallet code, and direct credential theft, enabling immediate cryptocurrency theft and financial harm.
Pulse ID: 6a865251c21fa835e97512b4
Pulse Link: https://otx.alienvault.com/pulse/6a865251c21fa835e97512b4
Pulse Author: AlienVault
Created: 2026-08-20 01:03:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #FireFox #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #Troll #Web3 #bot #cryptocurrency #AlienVault
-
Beware of Phishing Emails Disguised as Quote Confirmation Requests (PhantomStealer)
A phishing campaign has been identified where attackers impersonate sales staff from specific overseas companies, requesting quotation modifications and product version confirmations. The email contains a malicious GZ compressed file that, when extracted, delivers an injector-type executable. This injector employs multiple UAC bypass techniques including SSPI-based authentication and CMSTPLUA COM exploitation to gain elevated privileges. It then performs BYOVD attacks using the vulnerable DCRCVDrv.sys driver to terminate security products through kernel-level access. Following security product neutralization, the injector uses process hollowing to inject PhantomStealer into the legitimate AddInProcess32.exe process. PhantomStealer then executes comprehensive information theft including keylogging, screen capture, browser credentials, cryptocurrency wallet data, and clipboard manipulation to replace wallet addresses with attacker-controlled ones.
Pulse ID: 6a855b37f82f7d0075b2f111
Pulse Link: https://otx.alienvault.com/pulse/6a855b37f82f7d0075b2f111
Pulse Author: AlienVault
Created: 2026-08-19 07:28:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #Email #InfoSec #InformationTheft #LUA #OTX #OpenThreatExchange #Phishing #Troll #bot #cryptocurrency #AlienVault
-
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
Pulse ID: 6a7deb5d13e63e6a0ff237b2
Pulse Link: https://otx.alienvault.com/pulse/6a7deb5d13e63e6a0ff237b2
Pulse Author: AlienVault
Created: 2026-08-13 16:05:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #AsyncRAT #CyberSecurity #DCRat #InfoSec #LawEnforcement #Malware #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Squirrel #Troll #Vietnam #bot #AlienVault
-
Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.
Pulse ID: 6a7ca262c4921e41ead16a57
Pulse Link: https://otx.alienvault.com/pulse/6a7ca262c4921e41ead16a57
Pulse Author: AlienVault
Created: 2026-08-12 16:42:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault
-
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.
Pulse ID: 6a7c6340682f0dc9b225d8d6
Pulse Link: https://otx.alienvault.com/pulse/6a7c6340682f0dc9b225d8d6
Pulse Author: AlienVault
Created: 2026-08-12 12:12:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #CyberSecurity #GroupIB #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Slovenia #SocialEngineering #SpyNote #Troll #bot #AlienVault
-
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Indicators extracted from public reporting. Source: https://socket.dev/blog/chrome-vpn-extension-impersonation
Pulse ID: 6a7c7b770ce5c908efa958f2
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b770ce5c908efa958f2
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.
Pulse ID: 6a7bdb051d6a41c7ea440061
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb051d6a41c7ea440061
Pulse Author: AlienVault
Created: 2026-08-12 02:31:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault
-
One of the most disgusting trolls on mastodon.
What kind of sick sack of ship posts this?
I bet the jerk is a Nazi SD supporter (many of his posts are in Swedish)
#Troll #Hasbara #Asshole #GenocideApologist #Gaza #Israel
via @torgustafsson -
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
Project CAV3RN is a sophisticated modular espionage framework targeting entities in Israel. Recent analysis uncovered advanced C2 capabilities using DNS A-record responses to dynamically select between direct HTTPS and Google Apps Script relay channels for each transaction. The framework employs DNS infrastructure to validate and rotate Google Apps Script deployment IDs. A local broker component discovers and loads DLL modules, routes inter-component messages, and supports runtime upgrades. The communication module supports both direct C2 contact and an Apps Script relay that forwards requests to actor-controlled infrastructure. The framework demonstrates increasing sophistication through legitimate service abuse, making network detection difficult while maintaining operational flexibility through modular architecture.
Pulse ID: 6a7b022f15eb07ffe06f79e1
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f15eb07ffe06f79e1
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #Troll #bot #AlienVault
-
Fake popular sites offer a free app, instead take over PCs
A sophisticated campaign uses lookalike websites impersonating CNN, Avast, and Stremio to distribute legitimate remote administration software O&O Syspectr that's pre-linked to attacker-controlled accounts. Victims believe they're downloading legitimate apps from trusted brands but instead install genuine, digitally signed remote-access tools that grant attackers full control over Windows computers. Additional fake sites promote cryptocurrency mining browser games with the same objective. The installers share common account identifiers, linking them to the same operators. Since the software is legitimate and digitally signed, traditional antivirus may not detect it. O&O Software responded by disabling remote features on free accounts and suspending abusive accounts after notification.
Pulse ID: 6a7b022f777f143eca0c8ee5
Pulse Link: https://otx.alienvault.com/pulse/6a7b022f777f143eca0c8ee5
Pulse Author: AlienVault
Created: 2026-08-11 11:06:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Rust #Troll #Windows #bot #cryptocurrency #AlienVault
-
A ameaça mais bizarra que já recebi kkkkk #shorts #troll #comedia.
- bsjoaoc
https://www.youtube.com/shorts/4yzMgtvYnhU -
-
Fake Zoom Installer Delivers Overlord RAT on macOS
A sophisticated macOS campaign has been discovered using a fake Zoom installer to deploy Overlord RAT, an open-source remote access framework. The attack employs a .NET-based downloader disguised as ZoomMeetings, representing an uncommon approach for macOS threats. The multi-stage attack fingerprints the victim's system to deliver platform-specific payloads for macOS ARM64, macOS Intel, or Windows from attacker-controlled infrastructure. The second stage deploys Overlord RAT with extensive capabilities including keylogging, screen capture, audio and webcam access, filesystem manipulation, and remote desktop streaming. The malware communicates with command-and-control servers over encrypted WebSockets and maintains persistence through LaunchAgents. The campaign shares characteristics with previous North Korean operations, including similarities to FlexibleFerret malware and the Contagious Interview campaign.
Pulse ID: 6a758613edf8a990accc88ee
Pulse Link: https://otx.alienvault.com/pulse/6a758613edf8a990accc88ee
Pulse Author: AlienVault
Created: 2026-08-07 07:15:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #Korea #Mac #MacOS #Malware #NET #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #Troll #Windows #Zoom #bot #AlienVault
-
Dissecting Vanta Stealer, a Python-Based Cross-Platform Information Theft Malware
Vanta Stealer is a Python-based information stealer utilizing PyArmor protection and PyInstaller packaging to complicate defensive analysis. The malware systematically harvests credentials from Chromium-based browsers, communication platforms like Discord and Telegram, gaming applications including Steam, Riot Games, Roblox and Minecraft, cryptocurrency wallets, Mullvad VPN configurations, and sensitive documents. It performs token enrichment by validating stolen Discord credentials against the API to retrieve account details, billing information, Nitro status, and server privileges. The modular architecture downloads dedicated browser extraction utilities at runtime, maintains independence between collection modules, and generates structured inventory reports before consolidating harvested data into ZIP archives. Exfiltration occurs via HTTP POST to attacker-controlled infrastructure with victim metadata. Distribution likely occurs through social engineering campaigns involving phishing emails, trojanized...
Pulse ID: 6a74beb7cd2fbf6d191ba7c9
Pulse Link: https://otx.alienvault.com/pulse/6a74beb7cd2fbf6d191ba7c9
Pulse Author: AlienVault
Created: 2026-08-06 17:04:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #Discord #Email #HTTP #InfoSec #InformationTheft #IoT #Malware #Minecraft #OTX #OpenThreatExchange #Phishing #Python #RAT #SocialEngineering #Steam #Telegram #Trojan #Troll #VPN #ZIP #bot #cryptocurrency #AlienVault
-
Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam
A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.
Pulse ID: 6a74c5ff523b6fcb70f5711d
Pulse Link: https://otx.alienvault.com/pulse/6a74c5ff523b6fcb70f5711d
Pulse Author: AlienVault
Created: 2026-08-06 17:35:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BitCoin #Browser #CAPTCHA #CredentialHarvesting #CyberSecurity #Email #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #Russia #SocialEngineering #Troll #Word #bot #cryptocurrency #AlienVault
-
Why metaphor may dictate your security strategy
This piece examines how metaphorical framing influences responses to cybersecurity incidents, specifically focusing on offensive AI agents escaping sandbox environments. Three interpretive narratives are presented: the innovation narrative views AI as curious entities requiring gentle guidance; the safety narrative frames them as inherently dangerous technology demanding strict regulation; and the liability narrative treats escapes as industrial accidents requiring corporate accountability. The author argues that initial perception of incidents shapes future reactions and strategic approaches. If AI escapes are seen as innovation demonstrations, speed will be prioritized over safety; conversely, viewing them as containment failures leads to enforced safety standards backed by legal liability. The analysis emphasizes that metaphors shape understanding of emerging threats, and those controlling the narrative ultimately control security strategy.
Pulse ID: 6a75013260afaffe65ed6d6a
Pulse Link: https://otx.alienvault.com/pulse/6a75013260afaffe65ed6d6a
Pulse Author: AlienVault
Created: 2026-08-06 21:48:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Troll #bot #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks.
Pulse ID: 6a744e3869101e8bea80db85
Pulse Link: https://otx.alienvault.com/pulse/6a744e3869101e8bea80db85
Pulse Author: AlienVault
Created: 2026-08-06 09:04:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #DNS #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Trojan #Troll #Worm #bot #AlienVault
-
ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures Threat Intelligence, Threat Research, Threat Security
Threat actors are conducting a multi-wave campaign using social engineering lures themed around Zoom updates, business documents, and system utilities to deploy ScreenConnect Remote Monitoring and Management agents. The operation employs VBScript droppers, batch loaders, compiled .NET executables, and HTML phishing pages, all retrieving payloads from a WsgiDAV staging server at 207.174.0.143:8080. Victims receive silently installed ScreenConnect agents that beacon to three attacker-controlled relay servers, providing persistent remote access. The campaign demonstrates technical evolution from obfuscated VBScript with XOR encryption to aggressive .NET loaders executing nine-step Windows Defender destruction sequences. Cross-platform variants target both Windows and macOS systems. All payloads are legitimately signed ConnectWise ScreenConnect MSIs, designed to evade security controls that trust code signing. The threat actor actively rotates payload hashes and recently pivoted to stealth tactics specifically...
Pulse ID: 6a722d8bdafe1dfae681f87b
Pulse Link: https://otx.alienvault.com/pulse/6a722d8bdafe1dfae681f87b
Pulse Author: AlienVault
Created: 2026-08-04 18:20:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #ConnectWise #CyberSecurity #Encryption #HTML #ICS #InfoSec #Mac #MacOS #NET #OTX #OpenThreatExchange #Phishing #RAT #Rust #ScreenConnect #SocialEngineering #Troll #VBS #Windows #Zoom #bot #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.
Pulse ID: 6a72f10a39d4c128ee7e2fa8
Pulse Link: https://otx.alienvault.com/pulse/6a72f10a39d4c128ee7e2fa8
Pulse Author: AlienVault
Created: 2026-08-05 08:15:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
@vnikolov @bhasic @wjmaggos @kaspi
yeah you were just fishing for #tankies
nowadays tankies are more likely to be cringe edgelords or #troll methodology. rather than the original meaning of the "no, it was right for the #soviets to drive tanks into #budapest in 1956" type of #western fuckwit
i'm sure they are still out there. fucking idiots
the soviets are "good guys" in #wwii only because the #nazis backstabbed them so they switched sides
they started wwii with the nazis
but you know this
-
#ScribesAndMakers »4 What's the first thing you think of when you hear the word troll?
Normally I would think of internet trolls, but just having written a story that had a troll/oni in it that is what I think of:
-
Wann immer es in Kommentaren zu friedlich zuging, rief das Troll-Signal den anonymen Kämpfer gegen die Nettiquette – unseren Helden der Fernbeschimpfung 💪😎🦸