threat-intel Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks A sophisticated npm worm, linked to the Keyv vulnerability and attributed to the Shai-Hulud threat actor family, has spread across hundreds of packages, injecting credential-stealing and malicious code. The worm leverages preinstall scripts to harvest sensitive data – including GitHub, npm, cloud, and private keys – an… The Hacker News · Aug 4, 2026 High npmsupply-chaincredential-stealing
threat-intel ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Jul 29, 2026 High phishingcredential-stealingbusiness-application
threat-intel Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline A junior hacker, identified as ‘Poisson,’ infiltrated a French automotive business by exploiting vulnerabilities and establishing persistent access after his command-and-control server was taken down. He utilized OpenSSH… The Hacker News · Jun 17, 2026 Medium FRDEpersistenceremote-accessssh
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
supply-chain IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks A sophisticated supply chain attack targeting the npm ecosystem has resulted in the deployment of both IronWorm, a Rust-based information stealer with self-replicating capabilities, and a new variant of the Miasma worm.… The Hacker News · Jun 5, 2026 High USsupply-chainnpmrust
threat-intel MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The MuddyWater hacking group, backed by Iran, has been conducting a sophisticated espionage campaign targeting organizations across nine countries on four continents during Q1 2026. The campaign utilizes DLL side-loading… The Hacker News · May 26, 2026 High KRSAAEdll-side-loadingcredential-stealingreconnaissance
supply-chain TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A sophisticated supply chain attack, dubbed TrapDoor, is spreading credential-stealing malware across npm, PyPI, and Crates.io, targeting developers in the crypto, DeFi, Solana, and AI communities. The attack utilizes a… The Hacker News · May 25, 2026 High USsupply-chaincredential-stealingdeveloper-workflow
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp