Infostealer 20
- 5 Malicious Rust Crates Posed as Time Utilities to Exfiltrate .env Files
- Malicious Chrome Extension Steals Meta Business Manager Exports and TOTP 2FA Seeds
- Inside the GitHub Infrastructure Powering North Korea's Contagious Interview npm Attacks
- Shai Hulud Strikes Again (v2)
- Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
- Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages
- Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
- 60 Malicious Ruby Gems Used in Targeted Credential Theft Campaign
- Surveillance Malware Hidden in npm and PyPI Packages Targets Developers with Keyloggers, Webcam Capture, and Credential Theft
- npm 'is' Package Hijacked in Expanding Supply Chain Attack
- 2025 Blockchain and Cryptocurrency Threat Report: Malware in the Open Source Supply Chain
- Monkey-Patched PyPI Packages Use Transitive Dependencies to Steal Solana Private Keys
- The Landscape of Malicious Open Source Packages: 2025 Mid‑Year Threat Report
- The Bad Seeds: Malicious npm and PyPI Packages Pose as Developer Tools to Steal Wallet Credentials
- Gmail For Exfiltration: Malicious npm Packages Target Solana Private Keys and Drain Victims' Wallets
- Skuld Infostealer Returns to npm with Fake Windows Utilities and Malicious Solara Development Packages
- Typosquatting Cryptographic Libraries: Malicious npm Packages Threaten Crypto Developers with Keylogging and Wallet Theft
- Roblox Developers Targeted with npm Packages Infected with Skuld Infostealer and Blank Grabber
- Typosquatting on PyPI: Malicious Package Mimics Popular 'browser-cookie3' Library to Steal Sensitive Data
- Combating the Underground Economy's Automation Revolution