T1071.001 13
- 5 Malicious Rust Crates Posed as Time Utilities to Exfiltrate .env Files
- Malicious Go "crypto" Module Steals Passwords and Deploys Rekoobe Backdoor
- Malicious Chrome Extension Steals Meta Business Manager Exports and TOTP 2FA Seeds
- PyPI Package Impersonates SymPy to Deliver Cryptomining Malware
- Malicious Chrome Extension Steals MEXC API Keys for Account Takeover
- Two Malicious Rust Crates Impersonate Popular Logger to Steal Wallet Keys
- Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
- Backdooring the IDE: Malicious npm Packages Hijack Cursor Editor on macOS
- The Bad Seeds: Malicious npm and PyPI Packages Pose as Developer Tools to Steal Wallet Credentials
- Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
- North Korean APT Lazarus Targets Developers with Malicious npm Package
- Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
- Typosquatting Cryptographic Libraries: Malicious npm Packages Threaten Crypto Developers with Keylogging and Wallet Theft