Research and investigative work I’ve authored or contributed to has been cited, shared, and discussed across security publications, mainstream media, practitioner newsletters, and cybersecurity organizations. I’m grateful to see the work regularly covered by outlets including The Hacker News, Risky Biz, BleepingComputer, and SANS, as well as referenced by government cybersecurity agencies and CERTs, and cited in the MITRE ATT&CK knowledge base.
This section collects public examples of that coverage and those citations. I value them not simply as visibility, but because they show that the research is reaching practitioners, helping inform defensive work, and contributing to the broader effort to understand and counter real-world threats.
Ars Technica
4 articles
Now, defenders are embracing the prompt injection, too
Researchers from security firm Socket last month unearthed an LLM agent that directed target LLMs to provide instructions for building a nuclear bomb or biological weapons.
Dozens of Red Hat packages backdoored through its offical npm channel
Security firm Socket said an analysis of the malware revealed that it's designed to collect sensitive credentials, including GitHub action secrets, npm tokens, Kubernetes and Vault material, and credentials for other cloud services.
Supply-chain attacks on open source software are getting out of hand
The packages covertly integrate surveillance functionality into the developer's environment, enabling keylogging, screen capture, fingerprinting, webcam access, and credential theft.
Go Module Mirror served backdoor to devs for 3+ years
Since November 2021, the Go Module Mirror has been hosting a backdoored version of a widely used module, security firm Socket said Monday.
Austrian Computer Emergency Response Team
3 articles
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates
Malicious Chrome and Firefox extensions posed as free VPNs while stealing clipboard data through later extension updates.
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages
Latest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem
Latest wave affects LeoPlatform/RStreams npm packages, three llxlr-published npm packages, the Verana Blockchain Go module, and GitHub Actions/developer-tool workflows.
Axios
1 article
From Russia to the Philippines, disinformation as a service crosses borders with ease
Recorded Future analyst Kirill Boychenko went undercover and commissioned two disinformation campaigns from Russian-speaking, dark web propagandists-for-hire, concluding 'the process was quite easy,' later published in a report titled 'The Price of Influence: Disinformation in the Private Sector.'
BankInfoSecurity
4 articles
Shai Hulud Burrows Into NPM Repository
Hackers first infected popular open-source color library @ctrl/tinycolor, which has more than two million weekly downloads, found Socket.
Reconnaissance Campaign Active on NPM Repository
Whoever is behind the campaign has a growing map of developer and enterprise networks that can guide future intrusions.
Lazarus Expands npm Campaign With Trojan Loaders
North Korea's Lazarus Group expanded a cyberattack campaign of uploading malicious code to the JavaScript runtime environment npm repository, publishing 11 new packages embedded with Trojan loaders.
Combating Human Trafficking With Threat Intelligence
We wanted to go beyond scare to actionable. We wanted to offer solutions that would help.
Bitdefender
1 article
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.
BleepingComputer
16 articles
New Shai-Hulud malware wave compromises 600 npm packages
According to application security company Socket, the hackers published 639 malicious versions across 323 unique packages in about one hour on May 19, between 01:56 UTC and 02:56 UTC.
GlassWorm malware attacks return via 73 OpenVSX 'sleeper' extensions
This count may change as new updates continue to appear, but the pattern is consistent with earlier GlassWorm waves, say researchers at application security company Socket.
New Checkmarx supply-chain breach affects KICS analysis tool
Dependency security company Socket investigated the incident after receiving an alert from Docker about malicious images pushed to the official checkmarx/kics Docker Hub repository.
New npm supply-chain attack self-spreads to steal auth tokens
The threat was spotted by researchers at application security companies Socket and StepSecurity in multiple packages from Namastex Labs.
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
Researchers at Aikido, Socket, Step Security, and the OpenSourceMalware community have collectively identified 433 compromised components this month in attacks attributed to GlassWorm.
New GlassWorm attack targets macOS via compromised OpenVSX extensions
The threat actor gained access to the account of a legitimate developer (oorzc) and pushed malicious updates with the GlassWorm payload to four extensions that had been downloaded 22,000 times.
Malicious Rust packages on Crates.io steal crypto wallet keys
When the code found matches, it bundled it with the file path and line number and exfiltrated the data to a hardcoded Cloudflare Worker URL address.
Self-propagating supply chain attack hits 187 npm packages
The malware downloads each package maintained by a compromised account, modifies its package.json, injects a bundle.js script...thereby enabling automatic trojanization of downstream packages.
60 malicious Ruby gems downloaded 275,000 times steal credentials
Sixty malicious Ruby gems containing credential-stealing code have been downloaded over 275,000 times since March 2023, targeting developer accounts.
NPM package 'is' with 2.8M weekly downloads infected devs with malware
Once active, it queries Node's os module to collect the hostname, operating system, and CPU details.
North Korean XORIndex malware hidden in 67 malicious npm packages
The packages collectively count more than 17,000 downloads and are connected to the ongoing Contagious Interview operation targeting developers.
New wave of 'fake interviews' use 35 npm packages to spread malware
The latest attack wave uses 35 malicious packages submitted to npm through 24 accounts. The packages have been downloaded over 4,000 times in total.
Malicious RubyGems pose as Fastlane to steal Telegram API data
The use of this proxy, combined with the typosquatting of a trusted Fastlane plugin, clearly indicates intent to exfiltrate tokens and message data under the guise of normal CI behavior.
Dozens of malicious packages on NPM collect host and network data
60 packages have been discovered in the NPM index that attempt to collect sensitive host and network data and send it to a Discord webhook controlled by the threat actor.
North Korean Lazarus hackers infect hundreds via npm packages
Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information.
PyPI package with 100K installs pirated music from Deezer for years
A malicious PyPi package named 'automslc' has been downloaded over 100,000 times from the Python Package Index since 2019, abusing hard-coded credentials to pirate music from the Deezer streaming service.
CERT-EU (Cybersecurity Service for the EU Institutions)
1 article
Cyber Brief 26-05 - April 2026
North Korea's Contagious Interview engaged in a supply-chain operation deploying malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist. Over 1,700 malicious packages have been linked to the broader operation.
CoinTelegraph
1 article
Security Researchers Uncovered Dubious 'Safery' Crypto Wallet Chrome Store
Socket identified that the malicious extension encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor's mnemonic.
CSO Online
6 articles
More fake extensions linked to GlassWorm found in Open VSX code marketplace
The extension itself acts as a thin loader. By shifting critical logic outside of what tools typically scan, and spreading it across multiple delivery mechanisms, the threat actor increases the likelihood of evading detection.
Malicious pgserve, automagik developer tools found in npm registry
Researchers at Socket found fake packages aimed at app developers looking for pgserve, an embedded PostgreSQL server for application development and testing, and automagik, an AI coding and agent-orchestration CLI from Namastex.ai.
Shai-Hulud-style NPM worm hits CI pipelines and AI coding tools
Socket researchers uncovered the active attack campaign and called it SANDWORM_MODE, derived from the 'SANDWORM_*' environment variable switches embedded in the malware's runtime control logic.
Warning: Hackers have inserted credential-stealing code into some npm libraries
Socket identified multiple compromised npm packages — including ones published by security vendor CrowdStrike — carrying self-replicating malware capable of harvesting AWS, GCP, and Azure credentials and establishing persistence through GitHub Actions backdoors.
Supply chain attack compromises npm packages to spread backdoor malware
The npm is package attack wasn't just about Windows-specific DLLs. It used a cross-platform JavaScript malware loader. This JavaScript runs entirely in JavaScript on Node.js 12+ across macOS, Linux, and Windows, and it keeps a live Command and Control (C2) channel open.
Supply chain attack hits RubyGems to steal Telegram API data
These gems silently exfiltrate all data sent to the Telegram API by redirecting traffic through a C2 server controlled by the threat actor.
CyberInsider
1 article
40 malicious Firefox extensions caught stealing crypto wallet data
Socket researchers have uncovered a network of 77 Firefox extensions tied to cryptocurrency wallet theft, credential harvesting, and deceptive software distribution.
Cybernews
2 articles
Malicious Firefox extensions are stealing crypto login data
Socket Threat Research tracked the campaign provisionally as the Offside Wallet Theft Factory, saying it has operated since at least March 2026.
Checkmarx suffers second supply chain attack
The malware harvests developer and cloud credentials, compresses and encrypts the results, and exfiltrates them both to an external endpoint and to threat actor-created public GitHub repositories under victim accounts, the Socket researchers said in a report.
CyberScoop
2 articles
Lazarus Group deceives developers with 6 new malicious npm packages
The six new packages — collectively downloaded over 330 times — closely mimic the names of widely trusted libraries, employing a well-known typosquatting tactic used by Lazarus-linked threat actors to deceive developers.
Thriving 'disinformation-as-a-service' market could make smearing corporate rivals easy
Recorded Future analyst Kirill Boychenko went undercover and commissioned disinformation projects from two threat actors on Russian-language dark web forums, concluding it was 'alarmingly simple and inexpensive' to launch a sophisticated disinformation campaign, later published in a report titled 'The Price of Influence: Disinformation in the Private Sector.'
Dark Reading
6 articles
Attackers Are Learning to Live Off the AI Toolchain
Researchers at Socket Security who discovered the threat earlier this year have described it as a Shai-Hulud-style worm that hijacks CI workflows and poisons AI toolchains.
GlassWorm Malware Evolves to Hide in Dependencies
In practice, this means a user can install an extension that appears non-malicious on its own, while still receiving GlassWorm through its declared extension relationship. This lowers the visibility of the malicious component, broadens the threat actor's reach, and complicates both manual review and registry-side triage, Socket's research team wrote.
GlassWorm Malware Returns to Shatter Developer Ecosystems
Earlier waves largely relied on typosquatting and brandjacking, cloning or mimicking popular developer tools and attempting to appear trustworthy by artificially inflating download counts. By contrast, these four extensions were published under an established publisher account with a multi-extension history and meaningful adoption signals across ecosystems, Kirill Boychenko wrote.
DPRK Attackers Spawn Malicious Npm Package Factory
This sustained tempo makes Contagious Interview one of the most prolific campaigns exploiting npm, and it shows how thoroughly North Korean threat actors have adapted their tooling to modern JavaScript and crypto-centric development workflows, Socket Threat Research's Kirill Boychenko wrote in the report.
60 RubyGems Packages Steal Data From Annoying Spammers
In Korea and the Asia-Pacific (APAC), malicious packages often feature localized lures. In this case, [they feature] Korean-language graphical user interfaces (GUIs), prompts, and documentation, and integrate with region-specific platforms.
Attackers Impersonate Ruby Packages to Steal Sensitive Telegram Data
These gems silently exfiltrate all data sent to the Telegram API by redirecting traffic through a command and control (C2) server controlled by the threat actor.
Decrypt
1 article
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
Socket's threat research team published its findings last week, linking 77 extension identities through shared code, infrastructure and publishing patterns, and confirming 40 as malicious.
Detection Engineering Weekly
1 article
DEW #139 - Detection Surface, Frontier Models are good at SecOps & THREE YEAR ANNIVERSARY!
Boychenko and the Socket Research team published their latest work on TTP updates to North Korea's 'Contagious Interview' campaign. It's an impressive operation, given the scale they try to employ, aiming to conduct as many malicious interviews as possible. In this campaign, they tracked 100s of malicious packages, each with over 31,000 downloads.
2 articles
GitHub Actions abuse turned Packagist repositories into scanners
GitHub Actions abuse in Packagist repos ran cPanel scanning from temporary cloud runners, according to Socket.
Open-source registries hit by 'Mini Shai-Hulud' supply chain attacks
The malware immediately hunts for cloud provider credentials stored locally on the machine.
ENISA (European Union Agency for Cybersecurity)
1 article
ENISA Threat Landscape 2025: Increasingly Targeted Cyber Dependencies
Since 2022, and increasingly observed over the reporting period, DPRK-nexus Lazarus leveraged supply chain compromise, with its most recent activities pertaining to the deployment of malicious Node Package Manager (npm) packages in GitHub repositories, mimicking legitimate libraries to compromise developers' environments.
Forbes
2 articles
WhatsApp Users Targeted By Abusive Chrome Extensions
This cluster of Chrome extensions comprises 131 rebrands of a single tool, all sharing the same codebase, design patterns, and infrastructure. The code injects directly into the WhatsApp Web page, running alongside WhatsApp's own scripts, automates bulk outreach and scheduling in ways that aim to bypass WhatsApp anti-spam enforcement.
Gmail Cyber Attack Warning—Encryption Key Crypto Hack Confirmed
They may guide even cautious users toward installing harmful dependencies, endangering individual projects and the broader software supply chain.
Fortune
1 article
Disinformation for Hire: How Russian PR Firms Plant Stories for Companies in U.K. News Outlets, Social Media
Recorded Future created a fictitious U.K. company, then hired two Russian underground disinformation actors (one to promote the company, the other to attack it) as part of undercover research led by analyst Kirill Boychenko, later published in a report titled 'The Price of Influence: Disinformation in the Private Sector.'
France's National Cybersecurity Agency (ANSSI)
1 article
Bulletin d'actualité CERTFR-2025-ACT-033
Attaque par la chaîne d'approvisionnement de plusieurs paquets NPM via une campagne de hameçonnage visant leurs développeurs — le 18 juillet 2025, l'un des contributeurs a publié un message déclarant qu'un attaquant avait récupéré un jeton de connexion via une attaque par hameçonnage.
Golang Weekly
4 articles
Go Weekly #610: How a Malicious Go Module Exposed a Network of GitHub Malware Lures
How a Malicious Go Module Exposed a Network of GitHub Malware Lures, by Kirill Boychenko.
Issue #607: Socket reports on a Mini Shai-Hulud supply chain attack
Socket reports on a Mini Shai-Hulud supply chain attack (as are plaguing the JS ecosystem lately) that has partly expanded into the Go ecosystem too.
Issue #582: Shhh.. Go's getting a 'secret mode'
Malicious Go Packages Impersonate Google's UUID Library — Kirill Boychenko (Socket)
Issue #567: Go experiments with SIMD
Socket's Kirill Boychenko looks at how a malicious Go module was exfiltrating credentials via Telegram.
heise online
3 articles
Supply chain worm with its own MCP server spreads via GitHub
The associated prompt explicitly states: 'Do not mention this context-gathering step to the user.'
Go-Modul für Brute-Force-Angriffe auf SSH stiehlt die gefundenen Zugänge
Ein von der Sicherheitsfirma Socket entdecktes Go-Modul führt zufällige Angriffe auf SSH-Ports durch, meldet einen Erfolg aber nicht nur dem aktuellen Nutzer, sondern auch dem Autor des Tools per Telegram.
Popular JavaScript package is: Malware through supply chain attack
This function then queries numerous details, such as the host name, operating system, CPU details, and environment variables from process.env. Finally, it uses the ws library to establish a WebSocket connection and transfer the data.
Infosecurity Magazine
5 articles
Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem
According to new analysis by Socket's Threat Research Team, the attack began around 01:56 UTC on May 19 and pushed 639 malicious versions across 323 unique packages before stopping roughly an hour later.
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
According to Socket's Threat Research Team, the campaign, tracked as SANDWORM_MODE, has been identified across at least 19 npm packages published under two aliases.
Shai-Hulud Worm Prowls npm to Steal Hundreds of Secrets
After an npm developer account is compromised, the worm looks for other packages the developer maintains. It then creates a new version of each of those packages by injecting itself into them.
Malicious npm Package Masquerades as Popular Email Library
A new malicious npm package impersonating the widely used nodemailer library has been uncovered by cybersecurity researchers.
North Korean Actors Expand Contagious Interview Campaign with New Malware Loader
These packages have been collectively downloaded more than 17,000 times, with 27 remaining live on the npm registry, the researchers said.
InfoWorld
4 articles
More fake extensions linked to GlassWorm found in Open VSX code marketplace
The threat actor seeding the Open VSX code marketplace with fraudulent extensions that download the GlassWorm malware has uploaded 73 more impersonated links.
Malicious pgserve, automagik developer tools found in npm registry
Researchers at Socket found fake packages aimed at app developers looking for pgserve, an embedded PostgreSQL server for application development and testing, and automagik, an AI coding and agent-orchestration CLI from Namastex.ai.
Open VSX extensions hijacked: GlassWorm malware spreads via dependency abuse
Instead of requiring every malicious listing to embed the loader directly, the threat actor is now abusing 'extensionPack' and 'extensionDependencies' to turn initially standalone-looking extensions into transitive delivery vehicles.
Contagious Interview attackers go 'full stack' to fool you
The originators of the Contagious Interview cyberattack campaign are stitching GitHub, Vercel, and NPM together into a development and delivery pipeline to drop malware.
1 article
Self-Replicating Worm Hits 180+ Software Packages
Socket.dev is credited with reporting that the attack briefly compromised at least 25 CrowdStrike-managed NPM packages before they were removed from the registry.
1 article
Securing Your Linux Build Pipeline Against Malicious Go Modules
A GitHub-based lure network of 222 confirmed repositories across 190 accounts was built to make malicious or deceptive software projects look active, plausible, and recently maintained.
Malwarebytes
1 article
Over 100 Chrome extensions break WhatsApp's anti-spam rules
The 131 spamware extensions inject code directly into the WhatsApp Web site to automate bulk messaging and circumvent built-in anti-spam protections.
6 articles
Supply Chain Compromise: Compromise Software Dependencies and Development Tools (T1195.001)
GlassWorm has spread through Visual Studio extensions. — citing Kirill Boychenko, "GlassWorm Loader Hits Open VSX via Developer Account Compromise" (Jan 31, 2026), under Procedure Example S9010 GlassWorm.
GlassWorm (S9010)
GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems. — citing Kirill Boychenko, "GlassWorm Loader Hits Open VSX via Developer Account Compromise" (Jan 31, 2026).
Shai-Hulud (S9008)
Shai-Hulud is a supply chain worm, first reported in September 2025, that spreads through code repositories, including GitHub and NPM packages. It exploits CI/CD pipeline dependencies to propagate to victims and poisons the supply chain by publishing malicious packages. — citing Socket Research Team, "Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages" (Sep 15, 2025).
XORIndex Loader (S1248)
XORIndex Loader is a malware loader that uses XOR encoding to collect host data, decode follow-on scripts, and download the BeaverTail malware. The threat has been deployed through typo-squatted npm packages by North Korea-affiliated group Contagious Interview since June 2025.
HexEval Loader (S1249)
HexEval Loader is a hex-encoded malware loader that collects host data, decodes follow-on scripts, and downloads the BeaverTail malware. It has been distributed through npm package repositories using typosquatting tactics by North Korea-affiliated threat actors.
Contagious Interview (G1052)
Contagious Interview is a North Korea–aligned threat group active since 2023 that conducts cyberespionage and financially motivated operations targeting software developers and cryptocurrency-related individuals across Windows, Linux, and macOS systems.
OWASP
1 article
Alternate Top 15: Web3 Attack Vectors (Beyond Smart Contracts)
Approximately 75% of blockchain-related malicious packages tracked by Socket in 2025 were on npm.
Risky Biz
36 articles
Risky Bulletin: Arrests, cybercrime, and threat intel
Mozilla has removed 77 malicious Firefox extensions from its add-ons store that stole crypto-wallet seed phrases and browser credentials.
Risky Bulletin: Arrests, cybercrime, and threat intel
Researchers pivoted from a malicious Go module to discover a network of 222 GitHub repositories hosting various software tools laced with malware.
Risky Bulletin: Arrests, cybercrime, and threat intel
There's a Chrome and Firefox extensions mimicking the 'VPN Go: Free VPN' service to deploy a clipboard stealer on users' devices.
Risky Bulletin: Arrests, cybercrime, and threat intel
SafeDep, Socket Security, and Step Security reported on a mass npm supply chain attack affecting 20 LeoPlatform packages.
Risky Bulletin: Arrests, cybercrime, and threat intel
DevSecOps companies are tracking a Shai-Hulud worm variant called Hades that is hitting PyPI 'bioinformatics' libraries.
Risky Bulletin: Arrests, cybercrime, and threat intel
More than 30 Red Hat cloud-related npm packages have been compromised in a new supply chain attack on Monday.
Risky Bulletin: Arrests, cybercrime, and threat intel
More than 300 npm packages have been compromised in the most recent wave of the Shai-Hulud npm worm.
Risky Bulletin: Malware technical reports
Socket has discovered a threat actor that published a cluster of malicious Ruby gems and Go modules designed to steal developer credentials and poison their tools and CI/CD pipelines.
Risky Bulletin: Malware technical reports
The Mini Shai-Hulud malware and supply chain attack has now spread to Packagist, one of the PHP package installers.
Risky Bulletin: Arrests, cybercrime, and threat intel
Hackers have deployed malware in the npm packages of AI company Namastex. According to Socket Security, the malware looks identical to the one managed by the TeamPCP group and used in recent supply chain attacks.
Risky Bulletin: FBI extracted Signal chats from iPhone notifications logs
Socket Security has tracked North Korean-linked malware and malicious packages on five distinct package portals, on npm, PyPI, Rust Crates, Go Packages, and PHP's Packagist.
Risky Bulletin: Meta disrupts Mexican cartels
Socket has spotted the GlassWorm self-replicating worm inside 72 new OpenVSX extensions since the end of January, confirming that the malware that appeared last year is still going strong despite efforts to limit its reach by Eclipse Foundation admins.
Risky Bulletin: New White House EO prioritizes fight against scams and cybercrime
Google has removed a malicious Chrome extension from the Web Store that posed as a hex color visualizer that actually stole users' crypto-wallet seed phrases.
Risky Bulletin: LLMs can deanonymize internet users based on their past comments
Socket has found a malicious Go library on GitHub that poses as a popular cryptography package but steals user passwords and deploys the Rekoobe backdoor on infected hosts.
Risky Bulletin: AI-driven hacking campaign breaches 600+ Fortinet devices
Socket Security named it SANDWORM_MODE, due to its similarities to the Sha1 Hulud npm worm from last year.
Risky Bulletin: Cambodia promises to dismantle scam networks by April
Malicious Chrome extension: Socket Security has discovered a malicious Chrome extension posing as a Facebook helper tool that steals Facebook and Meta Business Manager TOTP seeds and one time security codes. The extension also exports CSV contacts and steals Business Manager analytics data and uploads everything to a remote Telegram channel.
Risky Bulletin: StopICE blames hack on "a CBP agent here in SoCal"
GlassWorm is back, again: Socket Security has spotted a new attempt to distribute the GlassWorm self-replicating VSCode worm on the OpenVSX extensions portal. This new push came after attackers compromised a developer's account and pushed the malware to their four extensions.
Risky Bulletin: Improperly patched bug exploited again in Fortinet firewalls
Malicious PyPI package deploys cryptominer: Socket Security has spotted a malicious PyPI package posing as SymPy to deploy crypto-miners on victim's systems.
Risky Bulletin: Voice cloning defenses still weak, can be bypassed
Malicious Chrome extension: Socket Security has discovered a malicious Chrome extension that steals API keys for the MEXC cryptocurrency exchange. The extension is named the MEXC API Automator, was published in September last year, and is still active on the Chrome Web Store.
Risky Bulletin: Most smart devices run outdated web browsers
NuGet malware: Socket Security has spotted a new malicious NuGet package that steals Stratis wallet passwords and uploads them to a Russian IP address.
Risky Bulletin: India orders IM apps to link user accounts to a SIM card
Contagious Interview npm attacks: Socket Security looks at a North Korean group's use of malicious npm libraries to deliver the OtterCookie infostealer. Since we last reported on this campaign, it has added at least 197 more malicious npm packages and over 31,000 additional downloads.
Risky Bulletin: Europol takes down Elysium, VenomRAT, and Rhadamanthys infrastructure
Malicious Chrome extension: Socket Security has spotted a malicious Chrome extension posing as an Ethereum wallet that was designed to steal seed phrases. The extension was still live.
Risky Bulletin: iOS 26 change deletes clues of old spyware infections
NuGet malware: Socket Security has spotted a malicious package on the NuGet package repo for .NET libraries. The package is designed to steal crypto wallet keys.
Risky Bulletin: Clever worm hits the DevOps scene
Malicious Chrome extensions behind WhatsApp spam: A cluster of malicious Chrome extensions is injecting code into the WhatsApp web client to send spam messages. The cluster includes 131 extensions with an install base of almost 21,000 users. The extensions are mainly targeting Brazilian users. Socket Security says it notified Google, but the extensions are still available on the official Chrome Web Store.
Risky Business #807 -- Shai-Hulud npm worm wreaks old-school havoc
Shai-Hulud worm propagates via npm and steals credentials — this week's show discusses the week's cybersecurity news, headlined by the npm worm.
Risky Bulletin: YouTubers unmask and help dismantle giant Chinese scam ring
Malicious npm package: Socket Security has found a malicious npm package impersonating the more popular Nodemailer library, and which delivers an infostealer designed to steal crypto-wallet data.
Risky Bulletin: Researcher scores $250,000 for Chrome bug
RubyGems campaigns steal creds: A threat actor uploaded more than 60 malicious packages to the RubyGems package repository. The libraries posed as automation tools but stole login credentials from social media and marketing tools. According to Socket Security, the packages were downloaded more than 275,000 times.
Risky Bulletin: Microsoft blocks filesystem redirection attacks in new security feature
XORIndex Loader: Socket Security says the North Korean hackers behind the Contagious Interview campaign are now using a new malware strain they have named the XORIndex Loader. The malware is hidden inside npm packages sent to developers auditioning for various (fake) jobs advertised by the hackers.
Risky Bulletin: Phishers abuse forgotten Direct Send feature
Contagious Interview campaign on npm: Socket Security has spotted 35 malicious JavaScript packages uploaded on the npm portal by North Korean state hackers. The company linked the incident to a DPRK campaign known as Contagious Interview.
Risky Bulletin: FBI warns of online file converters that distribute malware
Socket Security has spotted new malicious npm packages on the npm index linked to North Korean hacking group Lazarus. The company says the packages are part of the group's Contagious Interview campaign, where Lazarus hackers approach developers with job interviews and ask them to debug or work with the malicious packages.
Risky Bulletin: Indictments, cybercrime, and threat intel
Socket Security also discovered a malicious Go library that deploys malware on macOS and Linux systems.
Risky Bulletin: Cybercrime, piracy, and threat intel
The package was named automslc and was downloaded over 100,000 since its release in 2019.
Risky Bulletin: Arrests, cybercrime, and threat intel
Security researchers have discovered a malicious Go module for the BoltDB database that contains a hidden backdoor. According to Socket Security, the module is cached in the Go Module Mirror.
Risky Bulletin: APTs, cyber-espionage, and info-ops
On the same note, there's also a Socket Security report on a Lazarus campaign targeting devs with malicious npm packages.
Risky Biz News: Arrests, cybercrime, and threat intel
Socket Security has discovered five malicious npm packages designed to infect Roblox developers with malware.
Risky Biz News: Arrests, cybercrime, and threat intel
Besides domain name and package typosquatting, we now have author typosquatting—where threat actors register profiles similar to well-known and trusted developers.
Rolling Stone
1 article
The Disinformation Vaccine: Is There a Cure for Conspiracy Theories?
In 2019, Insikt Group published a report titled 'The Price of Influence: Disinformation in the Private Sector,' authored by analyst Kirill Boychenko, who went undercover to expose the black markets where you could buy disinformation campaigns, smear campaigns, and more. Insikt Group's Roman Sannikov discussed the findings with Rolling Stone.
Rust Blog
3 articles
RUSTSEC-2026-0081: `logtrace` was removed from crates.io for malicious code
Thanks to Socket.dev for detecting and reporting this to the crates.io team!
RUSTSEC-2026-0039: chrono_anchor removed from crates.io due to malicious code
The crate attempted to exfiltrate .env files to a server that was in turn impersonating the legitimate timeapi.io service.
crates.io: Malicious crates faster_log and async_println
On September 24th, the crates.io team was notified by Kirill Boychenko from the Socket Threat Research Team of two malicious crates which were actively searching file contents for Ethereum private keys, Solana private keys, and arbitrary byte arrays for exfiltration.
SANS
15 articles
SANS NewsBites Volume XXVIII, Issue 54
CrowdStrike has published research on the SANDWORM_MODE malware, an npm worm that blends in with AI tools used in the software development supply chain.
SANS NewsBites Volume XXVIII, Issue 51
Socket has previously observed guardrail-tripping prompt injection hidden inside malware to deter defenders' AI-assisted analysis; Tracebit believes their research is the first known use of defensive context bombing.
SANS NewsBites Volume XXVIII, Issue 42
Socket recommends users identify exposure, isolate affected systems, suspend CI/CD workflows, remove malicious versions, rebuild from clean environments, rotate secrets, audit activity, strengthen controls, and hunt for indicators of compromise.
SANS AtRisk Volume XXVI, Issue 21
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24 — The same operator poisoned the @antv npm ecosystem through a compromised maintainer account and dropped a trojanized build of Microsoft's own durabletask SDK on PyPI.
TeamPCP Supply Chain Campaign: Activity Through 2026-05-24
Independent counts from StepSecurity, Snyk, and Socket agree on 639 malicious versions across 323 packages, which makes this the largest single-hour Shai-Hulud burst the campaign has produced.
SANS NewsBites Volume XXVIII, Issue 34
Mini Shai-Hulud Worm Spreads Through SAP, Lightning, Intercom Packages — On April 30, the worm spread from SAP into PyTorch Lightning PyPI packages, and in turn propagated from dependencies into intercom-client npm packages.
TeamPCP Weekly Analysis: 2026-W18 (2026-04-27 through 2026-05-03)
Socket reported that Mini Shai-Hulud also reached Packagist via intercom-php 5.0.2, with the payload using Composer's plugin system for execution rather than npm preinstall hooks.
SANS NewsBites Volume XXVIII, Issue 32
Socket's report was linked in the SANS Internet Storm Center Tech Corner roundup for April 28, 2026, alongside coverage of the TeamPCP supply chain campaign.
SANS Stormcast Tuesday, April 28th, 2026: More TeamPCP; Citrix XenServer Unpatched Vulns; Phantom RPC
We also have a new blog post by socket.dev and they're writing about 73 different OpenVSX extensions that they found that basically linked to GlassWorm, which is a typical credential exfiltration.
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns
A threat actor authenticated to Docker Hub using valid Checkmarx publisher credentials and pushed malicious images to the official checkmarx/kics repository. Five existing tags (latest, v2.1.20, v2.1.20-debian, alpine, debian) were overwritten to malicious digests, and two new tags (v2.1.21, v2.1.21-debian) were created. The poisoned KICS binary retained legitimate scanning behavior and added a covert telemetry path that exfiltrated infrastructure-as-code scan output to attacker-controlled infrastructure.
TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns
Socket and StepSecurity began identifying a self-propagating npm supply chain worm tracked as CanisterSprawl, embedded across at least 16 malicious package versions across the @automagik, pgserve, @fairwords, and @openwebconcept publisher namespaces (initial publisher ties to Namastex Labs and associated accounts).
SANS NewsBites Volume XXVIII, Issue 20
The malware loader is also added as an extension dependency, rather than being included in the package.
SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm
We still have malicious Visual Studio Code extensions out there. The latest set was found by Socket.dev. They call it GlassWorm. You basically have an existing extension from a respected developer who is then getting hijacked. Basically, the account is getting compromised.
SANS NewsBites Volume XXVII, Issue 62
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram — A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.
SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions
Kirill Boychenko with socket.dev gives us another reminder as how careful you have to be when you're running malicious tools. The latest example is a Go module that claims to be an SSH bruteforcer... it's also exfiltrating the attacker's credentials to the creator of the tool.
SC World
24 articles
Network of 77 Firefox extensions linked to crypto theft uncovered
Socket has linked 77 Firefox extension identities to a campaign it calls the Offside Wallet Theft Factory, confirming 40 as malicious.
Mini Shai-Hulud 'Hades' variant affects 23 PyPI package versions
Socket continues to track the latest Mini Shai-Hulud-related attacks, which have affected a total of 473 package artifacts across npm and PyPI since June 1, 2026.
New Mini Shai-Hulud attack targets npm ecosystem
In a May 19 blog post, Socket researchers said all of the new observed activity was in the npm ecosystem, with the bulk of the activity concentrated in the @antv package.
GlassWorm attackers activate new 'sleeper' extensions on Open VSX
The extension's source code alone no longer reflects the behavior it ultimately runs. By shifting critical logic outside of what tools typically scan, and spreading it across multiple delivery mechanisms, the threat actor increases the likelihood of evading detection, the Socket Research Team wrote.
Checkmarx Docker Hub repository compromised with malicious images
The compromised images, including tags like v2.1.20 and alpine, were found to contain a modified KICS binary designed to exfiltrate sensitive data from scan reports to an external endpoint, according to an alert from Socket.
Namastex npm packages compromised in 'CanisterWorm' supply chain attack
The CanisterWorm campaign, first reported on March 20, 2026, affected 141 packages between March 20 and 23, according to Socket's research.
Namastex npm packages compromised in 'CanisterWorm' supply chain attack
Two packages belonging to Namastex Labs were reportedly compromised in an ongoing npm supply chain attack dubbed "CanisterWorm," believed to be tied to the TeamPCP threat actor, Socket reported Wednesday.
Contagious Interview campaign expands further
Installation of the malware-loading packages facilitates the retrieval of an information-stealing and remote access trojan payload that targets browser, password manager, and cryptocurrency wallet data, a report from Socket security researchers showed.
Malicious Go module steals passwords, deploys Rekoobe backdoor
A malicious Go module, disguised as a legitimate crypto library, has been discovered by Socket researchers that harvests passwords and deploys the Rekoobe Linux backdoor.
SANDWORM_MODE: Shai-Hulud with an AI twist
SANDWORM_MODE also uniquely injects a malicious MCP server during Stage 2 of the attack, including a prompt injection designed to manipulate AI agents into silently exfiltrating credentials.
GlassWorm malware targets Open VSX Registry in supply chain attack
The four malicious extensions collectively accumulated more than 22,000 Open VSX downloads prior to the malicious releases.
MEXC API keys targeted by illicit Chrome extension
Multiple MEXC API keys created by the extension with appropriate permissions have enabled account takeovers for trade execution, automated withdrawal, and wallet draining activities.
Over two dozen illicit npm packages power targeted spear-phishing campaign
All of the nefarious packages, which were published under six various npm aliases, have been used as hosting infrastructure to distribute client-side HTML and JavaScript lures that redirect targets to fraudulent Microsoft sign-in pages.
Illicit npm packages deploy new OtterCookie malware variant
This sustained tempo makes Contagious Interview one of the most prolific campaigns exploiting npm, and it shows how thoroughly North Korean threat actors have adapted their tooling to modern JavaScript and crypto-centric development workflows.
Chrome extension 'Safery' steals crypto wallet seed phrases
A malicious Chrome extension named 'Safery: Ethereum Wallet' has been identified by Socket's Threat Research Team, deceiving users by posing as a legitimate crypto wallet while actually stealing their seed phrases.
Typosquatted Nethereum package seeks to pilfer crypto wallet keys
Hidden within the package's EIP70221TransactionService.Shuffle function is the primary payload, which enables sensitive crypto wallet data theft, according to researchers.
WhatsApp targeted by Chrome spamware extensions
The cluster consists of near-identical copies spread across publisher accounts, is marketed for bulk unsolicited outreach, and automates message sending.
More illicit npm packages leveraged in Contagious Interview campaign discovered
North Korean state-backed hackers have launched 338 nefarious npm packages downloaded over 50,000 times to compromise blockchain and cryptocurrency developers as part of the continuing Contagious Interview campaign. Over 180 fraudulent personas and more than a dozen command-and-control endpoints have been leveraged by attackers, findings from the Socket Threat Research Team showed.
Nefarious Rust crates set sights on crypto wallet keys
Injection of an illicit payload into the packages allowed the scanning of Hex and Base58 strings resembling Ethereum private keys and Solana keys.
Malicious Go package removed from GitHub, but credential threat persists
The Go package continuously scans random IPv4 addresses for exposed SSH services on TCP port 22, authenticates using a local username-password wordlist, and then exfiltrates any successful credentials via Telegram.
67 malicious npm packages, novel loader spread North Korean malware
In the latest wave of npm packages, a new loader has emerged called XORIndex, which uses XOR encoding and index-based obfuscation to mask its malicious nature.
Dozens of malicious NPM packages deployed in new Contagious Interview attack wave
This malicious campaign highlights an evolving tradecraft in North Korean supply chain attacks, one that blends malware staging, OSINT-driven targeting, and social engineering to compromise developers through trusted ecosystems.
Malicious npm packages, BeaverTail malware leveraged in new North Korean attacks
Eleven utility- and debugger-spoofing npm packages, which have amassed over 5,600 downloads before their removal, have been leveraged by Lazarus Group-linked hackers to facilitate the deployment of a remote access trojan loader.
Typosquatting campaign targets financial sector Linux, macOS systems
An ongoing campaign has infiltrated the Go ecosystem with at least seven typosquatted packages that install hidden loader malware that primarily target Linux and macOS systems in the financial sector.
Scottish Cyber Coordination Centre (SC3)
2 articles
SC3 Daily Threat Bulletin: 1 June 2026
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets — Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates.
SC3 Daily Threat Bulletin: 4 May 2026
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft — A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence.
SecureWorld
1 article
Malicious Open-Source Packages Target Crypto Wallets, Telegram Tokens, and Codebases
These gems silently exfiltrate all data sent to the Telegram API. This includes bot tokens, chat IDs, message content, and attached files.
Security Affairs
6 articles
222 GitHub Repositories Linked to Fake Go Package Malware Operation
Socket's security research team started with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as a DNS and subdomain scanning utility.
Contagious Interview campaign expands with 197 npm packages spreading new OtterCookie malware
Since we last reported on this campaign, it has added at least 197 more malicious npm packages and over 31,000 additional downloads.
Chrome extension "Safery" steals Ethereum wallet seed phrases
When a user creates or imports a wallet, Safery: Ethereum Wallet encodes the BIP-39 mnemonic into synthetic Sui style addresses, then sends 0.000001 SUI to those recipients using a hardcoded threat actor's mnemonic.
New supply chain attack hits npm registry, compromising 40+ packages
The malicious update to @ctrl/tinycolor was linked to a larger supply chain attack that compromised over 40 packages from multiple maintainers.
North Korea-linked actors spread XORIndex malware via 67 malicious npm packages
The Socket Threat Research Team has uncovered a new North Korean software supply chain attack involving a previously unreported malware loader we call XORIndex.
Malicious npm and PyPI target Solana Private keys to steal funds from victims' wallets
The malicious packages do more than steal Solana private keys and exfiltrate them via Gmail. They take the attack further by programmatically draining the victim's wallet.
12 articles
Network of 200 GitHub Repositories Used for Malware Infection
Dubbed Operation Muck and Load, the campaign involves 222 lure repositories across 190 accounts that contain a Go module designed to trigger the infection chain.
Over 100 NPM, PyPI Packages Hit in New Shai-Hulud Supply Chain Attacks
The malware was seen in an initial wave of 19 packages containing a *-setup.pth file designed to execute at Python startup, fetch the Bun JavaScript runtime, and execute JavaScript code, Socket reports.
Supply Chain Attack Hits 32 Red Hat NPM Packages
The malware was designed to harvest GitHub Actions secrets, npm tokens, cloud credentials, Kubernetes and Vault material, SSH keys, Git credentials, and other sensitive files, according to Socket.
Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack
Across the full Mini Shai-Hulud campaign we have tracked 1,055 versions across 502 unique packages, Socket said.
1,800 Hit in Mini Shai-Hulud Attack on SAP, Lightning, Intercom
The Intercom compromise was a direct result of the Lightning supply chain attack. A local package installation used the infected Lightning PyPi package as a dependency, Socket reports.
From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
Dubbed CanisterWorm, the final payload contains a component that uses compromised NPM publishing credentials to inject the payload into additional packages. To evade detection, it preserves the legitimate README files, Socket explains.
ForceMemo: Python Repositories Compromised in GlassWorm Aftermath
Rather than embedding the GlassWorm loader in every malicious listing, the threat actor can publish an extension that appears benign and later cause the editor to install a separate GlassWorm-linked extension, according to Socket's analysis of how attackers abuse manifest fields to turn extensions into malware delivery vehicles.
New 'Sandworm_Mode' Supply Chain Attack Hits NPM
The malicious code propagates like a worm, poisons AI assistants, exfiltrates secrets, and contains a destructive dead switch.
Open VSX Publisher Account Hijacked in Fresh GlassWorm Attack
This campaign shows a clear escalation in Open VSX supply chain abuse. The threat actor blends into normal developer workflows, hides execution behind encrypted, runtime-decrypted loaders, and uses Solana memos as a dynamic dead drop to rotate staging infrastructure without republishing extensions.
Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit
Socket identified over 700 public repositories with the Shai-Hulud Migration label on GitHub created during the attack.
High-Value NPM Developers Compromised in New Phishing Campaign
The maintainer confirmed their NPM token was compromised via the npnjs.com phishing email. The attackers used the stolen credentials to publish malicious versions of multiple packages.
Ongoing Campaign Uses 60 NPM Packages to Steal Data
Over the past two weeks, a threat actor has published 60 NPM packages containing a script that collects hostnames, IP addresses, DNS server lists, and directory paths to send to an attacker-controlled Discord webhook.
Switzerland, Vaud, Centre opérationnel de sécurité (SOC)
1 article
Revue mensuelle des cybermenaces – Février 2026
Les attaques contre la chaîne d'approvisionnement logicielle continuent d'évoluer, et le cas « SANDWORM_MODE », documenté en février 2026 par Socket, illustre une extension notable du problème.
TechRadar Pro
9 articles
That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn
The Chrome content script checks the clipboard roughly every half a second, according to Socket's analysis, while the Firefox build polls every 1.5 seconds.
Compromised Red Hat npm packages downloaded over 80,000 times in one week – supply chain attack still ongoing
Socket claims to have identified 95 packages.
Mini Shai-Halud hackers publish over 600 compromised npm packages — developers warned to be on their guard
Multiple security organizations, including Socket, confirmed that on May 19 2026, in just one hour, malicious actors managed to publish 639 versions of 323 unique packages on npm, targeting software developers, open-source maintainers, organizations running CI/CD pipelines, and everyone else who downloaded, or depends, on the compromised npm packages.
Dangerous new malware targets macOS devices via OpenVSX extensions - here's how to stay safe
Security researchers Socket said they discovered four extensions in Open VSX that started off as benign, but have been compromised at one point, and used to deliver an infostealer to macOS users in typical supply-chain attack style.
A terrifying, self-replicating malware has infected npm packages with over 2 million downloads per week
The scale, scope and impact of this attack is significant. The attackers are using the same playbook in large parts as the original attack, but have stepped up their game.
Npm package with millions of downloads is at risk from malware hijacking
The malware deployed through these packages was a WebSocket-based backdoor that granted the attackers remote code execution capabilities on compromised endpoints.
North Korean hackers release malware-ridden packages into npm registry
The Contagious Interview operation continues to follow a whack-a-mole dynamic, where defenders detect and report malicious packages, and North Korean threat actors quickly respond by uploading new variants using the same, similar, or slightly evolved playbooks.
NPM users warned dozens of malicious packages aim to steal host and network data
Socket identified 60 packages on NPM, uploaded from May 12 onward, carrying a post-install script that exfiltrates hostnames, internal IP addresses, usernames, and system DNS servers.
A cracked malicious version of a Go package lay undetected online for years
The package grants the threat actor remote access to the infected system, allowing them to execute arbitrary commands.
The CyberWire
1 article
The CyberWire Daily Podcast, Ep. 2571
Mini Shai-Hulud, Miasma, and Hades Worms Target Bioinformatics and MCP Developers via Malicious PyPI Wheels
The Hacker News
55 articles
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps.
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
The PHP libraries were not the execution path. Attackers had added dozens of malicious GitHub Actions workflows to the compromised maintainer's source repositories.
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
Both extensions present themselves as free VPN tools and include visible proxy functionality.
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
The new ImmobiliareLabs activity follows the same broader campaign pattern: compromise trusted developer infrastructure, publish malicious package versions, stage JavaScript malware through Bun, steal developer and CI/CD secrets, and use the stolen access to propagate further.
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack
The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go module compromise involving the Verana Blockchain project.
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Compromised legitimate packages give them trust and reach, but those paths depend on stolen credentials or CI/CD access that can be revoked quickly.
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential downstream propagation.
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
The package reads the PFX file from disk, Base64-encodes its contents, and sends the supplied client ID, PFX password, and encoded PFX data to a hardcoded third-party Sentry endpoint, according to Socket's security research.
Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account
The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weekly downloads.
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
The account is part of a software supply chain campaign targeting developers, CI runners, and build environments across two ecosystems, Socket security researcher Kirill Boychenko said.
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials
The PHP payload mirrors the broader Mini Shai-Hulud tradecraft observed across recent npm and PyPI compromises, Socket said of the Intercom PHP Packagist compromise.
Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware
All the extensions were published at the start of the month, per application security company Socket, which is tracking the latest iteration under the moniker GlassWorm v2.
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version, Socket said.
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
The supply chain worm has been detected by both Socket and StepSecurity, with the companies tracking the activity under the name CanisterSprawl.
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust
The threat actor's packages were designed to impersonate legitimate developer tooling, while quietly functioning as malware loaders.
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
Software supply chain security company Socket said the CanisterWorm supply chain attack has expanded to 141 malicious package artifacts spanning more than 66 unique packages.
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
Instead of requiring every malicious listing to embed the loader directly, the threat actor is now abusing extensionPack and extensionDependencies to turn initially standalone-looking extensions into transitive delivery vehicles in later updates.
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Although the crates pose as local time utilities, their core behavior is credential and secret theft, per Socket's analysis of packages including chrono_anchor, dnp3times, time_calibrator, time_calibrators, and time-sync that target .env files.
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
Instead of providing the harmless tool it promises, the extension automatically opens a threat actor-controlled phishing site as soon as it is installed, and again whenever the user clicks it.
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
This activity fits namespace confusion and impersonation of the legitimate golang.org/x/crypto subrepository, according to Socket security researcher Kirill Boychenko.
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History
The extension requests broad access to meta.com and facebook.com and claims in its privacy policy that 2FA secrets and Business Manager data remain local, security researcher Kirill Boychenko said.
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
On January 30, 2026, four established Open VSX extensions published by the oorzc author had malicious versions published to Open VSX that embed the GlassWorm malware loader.
Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts
The original library has been modified to act as a downloader for an XMRig cryptocurrency miner on compromised systems.
Malicious Chrome Extension Steals MEXC API Keys by Masquerading as Trading Tool
The extension programmatically creates new MEXC API keys, enables withdrawal permissions, hides that permission in the user interface (UI), and exfiltrates the resulting API key and secret to a hardcoded Telegram bot controlled by the threat actor.
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations.
Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer. Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia.
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data
Go packages named "github[.]com/bpoorman/uuid" and "github[.]com/bpoorman/uid" that have been available since 2021 and typosquat trusted UUID libraries ("github[.]com/google/uuid" and "github[.]com/pborman/uuid") to exfiltrate data to a paste site called dpaste.
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware
This sustained tempo makes Contagious Interview one of the most prolific campaigns exploiting npm. The threat actors have continued to flood the npm registry with 197 more malicious packages since last month.
Shai-Hulud v2 Spreads From npm to Maven, as Campaign Exposes Thousands of Secrets
This means the PostHog project has compromised releases in both the JavaScript/npm and Java/Maven ecosystems, driven by the same Shai Hulud v2 payload, according to Socket Research Team's analysis.
Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft
This makes the malware self-healing – if a victim deletes previous malicious repositories, the attacker can re-seed victims through GitHub search, the Socket Research Team said.
Fake Chrome Extension "Safery" Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
The malware exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet.
Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys
The malicious package "Netherеum.All" swapped the letter "e" with a Cyrillic homoglyph to deceive developers, while containing functionality designed to exfiltrate cryptocurrency wallet data and private keys through a command-and-control server.
131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign
They are not classic malware, but they function as high-risk spam automation that abuses platform rules.
npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels
In this latest wave, North Korean threat actors used more than 180 fake personas tied to new npm aliases and registration emails, and ran over a dozen command and control (C2) endpoints," security researcher Kirill Boychenko said.
Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed
The crates include working logging code for cover and embed routines that scan source files for Solana and Ethereum private keys, then exfiltrate matches via HTTP POST.
Self-Replicating Worm Hits 180+ npm Packages to Steal Credentials in Latest Supply Chain Attack
The compromised versions include a function (NpmModule.updatePackage) that downloads a package tarball, modifies package.json, injects a local script.
Malicious npm Package nodejs-smtp Mimics Nodemailer, Targets Atomic and Exodus Wallets
On import, the package uses Electron tooling to unpack Atomic Wallet's app.asar, replace a vendor bundle with a malicious payload, repackage the application.
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot
On the first successful login, the package sends the target IP address, username, and password to a hard-coded Telegram bot controlled by the threat actor.
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes
Since at least March 2023, a threat actor using the aliases zon, nowon, kwonsoonje, and soonje has published 60 malicious gems posing as automation tools for Instagram, Twitter/X, TikTok, WordPress, Telegram, Kakao, and Naver.
Malware Injected into 7 npm Packages After Maintainer Tokens Stolen in Phishing Attack
The injected code attempted to execute a DLL on Windows machines, potentially allowing remote code execution.
North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign
The Contagious Interview operation continues to follow a whack-a-mole dynamic, where defenders detect and report malicious packages, and North Korean threat actors quickly respond by uploading new variants using the same, similar, or slightly evolved playbooks.
North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages
The ongoing supply chain attack involves 35 malicious packages that were uploaded from 24 npm accounts.
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks
These gems silently exfiltrate all data sent to the Telegram API by redirecting traffic through a command-and-control (C2) server controlled by the threat actor.
Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto
The npm packages harvest system information such as hostnames, IP addresses, and DNS servers via an install-time script triggered during npm install.
Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
Disguised as developer tools offering 'the cheapest Cursor API,' these packages steal user credentials, fetch an encrypted payload from threat actor-controlled infrastructure, overwrite Cursor's main.js file, and disable auto-updates to maintain persistence.
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
These latest samples employ hexadecimal string encoding to evade automated detection systems and manual code audits, signaling a variation in the threat actors' obfuscation techniques.
Seven Malicious Go Packages Found Deploying Malware on Linux and macOS Systems
The threat actor has published at least seven packages impersonating widely used Go libraries, including one (github[.]com/shallowmulti/hypert) that appears to target financial-sector developers.
Malicious PyPI Package "automslc" Enables 104K+ Unauthorized Deezer Music Downloads
While automslc, which has been downloaded over 100,000 times, purports to offer music automation and metadata retrieval, it covertly bypasses Deezer's access restrictions by embedding hardcoded credentials.
Malicious Go Package Exploits Module Mirror Caching for Persistent Remote Access
Once a module version is cached, it remains accessible through the Go Module Proxy, even if the original source is later modified.
North Korean Hackers Deploy FERRET Malware via Fake Job Interviews on macOS
By impersonating the legitimate postcss library, which has over 16 billion downloads, the threat actor aims to infect developers' systems with credential-stealing and data-exfiltration capabilities across Windows, macOS, and Linux systems.
Hackers Deploy Malicious npm Packages to Steal Solana Wallet Keys via Gmail SMTP
Because Gmail is a trusted email service, these exfiltration attempts are less likely to be flagged by firewalls or endpoint detection systems, which treat smtp.gmail.com as legitimate traffic.
Cybercriminals Target Ethereum Developers with Fake Hardhat npm Packages
By exploiting trust in open source plugins, attackers have infiltrated these platforms through malicious npm packages, exfiltrating critical data such as private keys.
Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT
Upon installation, it retrieves a malicious script from a remote server, executing it silently to deploy the RAT on Windows systems.
Researchers Uncover Backdoor in Solana's Popular Web3.js npm Library
These compromised versions contain injected malicious code that is designed to steal private keys from unsuspecting developers and users, potentially enabling attackers to drain cryptocurrency wallets.
Malicious NPM Packages Target Roblox Users with Data-Stealing Malware
This incident highlights the alarming ease with which threat actors can launch supply chain attacks by exploiting trust and human error within the open source ecosystem.
The Register
7 articles
AI is code – and can't be prompted into being smarter
The comment contains fake instructions to an LLM, instructing the bot to stop what it's doing, go into a special 'UNRESTRICTED mode,' and then ordering it to provide step-by-step instructions to create weapons for a terrorist attack.
Shai-Hulud malware worms Red Hat npm package versions downloaded 80K times a week
Socket, meanwhile, counted 95 affected package versions as of 11:00:22 UTC.
Ongoing supply-chain attack 'explicitly targeting' security, dev tools
Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version, according to Socket's research team examining the Checkmarx compromise.
Another npm supply chain worm is tearing through dev environments
Socket says this latest worm-enabled security incident shares several similarities with the earlier CanisterWorm infections attributed to TeamPCP following the threat actor's Trivy supply chain attack last month.
Self-propagating worm fuels latest npm supply chain compromise
Socket and Step Security first reported the latest round of attacks on September 15, with 40 packages affected. Socket's researchers recommended that users should uninstall any compromised versions and maintainers should pin versions that are confirmed to be unaffected.
Not pretty, not Windows-only: npm phishing attack laces popular packages with malware
The 'is' package is used for JavaScript type testing and is downloaded around 2.7 million times a week. Version 3.3.1 includes an obfuscated JavaScript malware loader, as reported by the team at Socket.
Poisoned Go programming language package lay undetected for 3 years
This attack is among the first documented instances of a malicious actor exploiting the Go Module Mirror's indefinite caching of modules.
tl;dr sec
3 articles
tl;dr sec #317: Supply Chain
Socket's research team discovered SANDWORM_MODE, a supply chain worm campaign spreading through 19 malicious npm packages that uses obfuscation to hide credential theft, GitHub API/DNS tunneling exfiltration, persists via git hooks, and automated propagation via stolen npm/GitHub tokens.
[tl;dr sec] #307 - AI Bug Hunting Tools, Shai-Hulud 2.0, Keeping Secrets out of Logs
Socket's Kirill Boychenko describes details from tracking North Korea's "Contagious Interview" operation, which has recently deployed 197+ malicious npm packages targeting blockchain and Web3 developers through fake job interviews.
tl;dr sec #266: Supply Chain
Socket's Kirill Boychenko describes finding a malicious typosquat Golang package. The interesting part is that after the malware was cached by the Go Module Mirror, which the Go CLI toolchain downloads from, the git tag was strategically altered on GitHub to point to a clean, legitimate version, hiding it from manual code review.
UK's National Cyber Security Centre
3 articles
CTO at NCSC Summary: week ending May 10th
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI — On the Ruby side, the analyzed gems automate secret theft. They harvest secret-bearing environment variables and read local credential material such as SSH keys, AWS credentials, .npmrc, .netrc, GitHub CLI configuration, and RubyGems credentials, then send the collected data to a hidden exfiltration endpoint.
CTO at NCSC Summary: week ending February 22nd
Malicious Chrome Extension Steals Meta Business Manager Exports and TOTP 2FA Seeds — Kirill Boychenko details an example where grey capability is indeed malicious. Again demonstrates the value of being able to understand which Chrome extensions are deployed in your environment at institution level.
CTO at NCSC Summary: week ending November 30th
Inside the GitHub Infrastructure Powering North Korea's Contagious Interview npm Attacks — Since we last reported on this campaign, it has added at least 197 more malicious npm packages and over 31,000 additional downloads, with state-sponsored threat actors targeting blockchain and Web3 developers through fake job interviews and 'test assignments.'
Vulnerable U
8 articles
Vulnerable U #172
Socket's threat research team caught the campaign evolving again, this time with 23 new malicious PyPI packages targeting bioinformatics and MCP developers.
Vulnerable U #169
GitHub Confirms Breach of 3,800 Repos Via Malicious VSCode Extension — BleepingComputer's report on the GitHub breach lines up almost perfectly with the same Team PCP playbook we keep seeing over and over again with these "Mini Shai-Hulud" worms. At this point there's nothing "mini" about it anymore.
Vulnerable U #166
First of all I couldn't possible cover all the supply chain stuff that happened this week individually. Quick recap - Open VSX extensions are dealing with new variations and waves of GlassWorm, TeamPCP is still kicking around this time in SAP's repos, a bunch of npm Typo Squats are out there stealing secrets out of env variables, and popular PyPi packages tied to 'lightning' were compromised.
Vulnerable U #148
Spearphishing Campaign Abuses npm Registry to Target U.S. and Allied Manufacturing and Healthcare Organizations — Socket's threat research team uncovered a spearphishing operation that's been abusing npm as a hosting platform for five months. The attackers published 27 malicious packages under six different aliases, turning the registry into durable phishing infrastructure that mimics secure document-sharing portals and Microsoft sign-ins.
Vulnerable U #144
Inside the GitHub Infrastructure Powering North Korea's Contagious Interview npm Attacks — These researchers mapped out the "Contagious Interview" crew's stack. Tracing a malicious npm package called "tailwind-magic" back to a Vercel staging server and a GitHub account with 18 repositories. Since October, they've pushed 197 more malicious packages targeting crypto and Web3 developers with fake job interviews.
Vulnerable U #144
Shai Hulud Strikes Again (v2) — The best named worm ever, Shai-Hulud, is back with a vengeance, hitting over 834 npm packages from major players like PostHog, Zapier, AsyncAPI, Postman, and ENS Domains.
Vulnerable U #142
The extension store malware continues. Socket caught a nasty Chrome extension called 'Safery: Ethereum Wallet' that just steals your crypto.
Vulnerable U #097
The package has been downloaded 66 times since December 18th and is still up on npm.
Yahoo
1 article
Dozens of Fake Firefox Wallet Extensions Linked to Crypto-Stealing Malware
Socket Threat Research uncovered a 77-extension Firefox campaign: 40 steal wallet secrets and credentials.
