threat-intel JavaScript obfuscation: From party trick to phishing kit This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including string manipulation, identifier renaming, runtime decoding, and control-flow flattening. They emphasi… Cisco Talos · 3d ago High obfuscationjavascriptmalware
threat-intel A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th) This article details a sophisticated phishing page that employs a polymorphic obfuscation technique to evade detection. The page initially presents as broken, causing a 30-second delay and high CPU usage, due to a global… SANS Internet Storm Center · 3d ago Medium phishingobfuscationpolymorphism
vulnerability Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE A critical vulnerability in isolated-vm, a popular JavaScript sandbox library, allows attackers to escape the sandbox environment and potentially execute code on the host system. The flaw stems from a type confusion issu… The Hacker News · Aug 20, 2026 Critical vulnerabilitysandboxjavascript
data-breach Over 1,000 Charities Hit by Beacon CRM Data Breach A data breach at UK-based CRM provider Beacon has impacted over 1,000 charities, exposing supporter data including names, email addresses, and postal addresses. The breach stemmed from a compromised AWS access key and in… SecurityWeek · Aug 14, 2026 Medium GBdata breachcrmaws
supply-chain Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites Adform, an advertising technology company, suffered a supply-chain attack where attackers injected malicious JavaScript code into their tracking script, allowing them to swap cryptocurrency wallet addresses across custom… The Hacker News · Aug 1, 2026 High supply-chainjavascriptcryptocurrency
threat-intel North Korean hackers behind major open-source supply chain attacks, Amazon says North Korean hackers, operating under the alias SapphireSleet, have been responsible for a series of attacks targeting widely used open-source JavaScript packages. These attacks, spanning from March 2025 to March 2026, i… The Record · Jul 30, 2026 High KRnorth koreaopen sourcesupply chain
threat-intel Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (T… The Hacker News · Jul 29, 2026 High KPnpmmalwareremote access trojan
vulnerability n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process N8n, a workflow automation platform, had a high-severity expression-sandbox escape that could allow authenticated workflow editors to execute operating system commands on the server. The vulnerability stemmed from a flaw… The Hacker News · Jul 27, 2026 High CVE-2026-27577expression-sandboxworkflowjavascript
supply-chain Multiple Jscrambler Packages Impacted by Supply Chain Attack A supply chain attack targeting Jscrambler’s NPM package led to the distribution of malicious versions containing malware designed to steal sensitive information from developer and cloud environments. The attack exploite… SecurityWeek · Jul 14, 2026 High npmsupply chainmalware
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
threat-intel Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability A popular Google Chrome ad blocker extension, Adblock for YouTube, with over 10 million installs, has been found to contain a dormant script injection capability. Researchers discovered the extension’s architecture allow… The Hacker News · Jun 25, 2026 High USadblockjavascriptprivacy
supply-chain 144 Mastra npm Packages Compromised via Hijacked Contributor Account A software supply chain attack, dubbed ‘easy-day-js,’ compromised 144 npm packages within the Mastra namespace by hijacking a contributor account. The attack leveraged a malicious dependency, ‘easy-day-js,’ to deploy a c… The Hacker News · Jun 17, 2026 High supply chainnpmjavascript
supply-chain Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer A new supply chain attack, dubbed Hades, is leveraging the Miasma campaign to compromise 37 PyPI packages, including those used in bioinformatics and computational biology. The attack utilizes a malicious setup.pth file… The Hacker News · Jun 9, 2026 High RUsupply-chainpythoncredential-stealing
vulnerability Google patches new Chrome zero-day flaw exploited in the wild Google has released a security update to address a newly discovered and actively exploited zero-day vulnerability (CVE-2026-11645) within the Chrome browser. This flaw, originating in the V8 JavaScript engine, allows att… BleepingComputer · Jun 9, 2026 High CVE-2026-11645CVE-2024-0519CVE-2026-2441zero-daychromev8
supply-chain 'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud A new wave of attacks, dubbed the 'Hades' campaign, has targeted the Python Package Index (PyPI) with a variant of the Shai-Hulud worm. This campaign involved compromising 37 PyPI wheels and 19 code packages, utilizing a… Dark Reading · Jun 8, 2026 High USsupply-chainpythonopen-source
threat-intel Suspicious Polyfill login prompts pop up on Toshiba, Muji websites Toshiba and Muji websites were temporarily affected by malicious login prompts generated by the polyfill[.]io service, which injected malicious code into their scripts. The issue stemmed from the domain being acquired by… BleepingComputer · Jun 5, 2026 Medium JACHcdnjavascriptlogin
threat-intel OWASP Incubator Project Helps Developers Find and Fix Vulnerable Dependencies in Seconds This article discusses the launch of CVE Lite CLI, an open-source command-line security scanner developed by Sonu Kapoor to address the challenges of managing vulnerabilities within JavaScript and Typescript projects usi… SecurityWeek · Jun 5, 2026 Medium dependency-scanningvulnerabilityjavascript
malware FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads A new macOS malvertising campaign, dubbed Operation FlutterBridge, is utilizing FlutterShell, a backdoor that spreads adware via malicious Google and YouTube ads. The campaign, traced back to the CL-CRI-1089 threat actor… The Hacker News · Jun 4, 2026 High USCAAUmalvertisingmacoswebview
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
threat-intel Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability in Ghost CMS to deploy ClickFix attack flows, targeting over 700 websites across various sectors. The campaign leverages stolen admin API keys t… BleepingComputer · May 24, 2026 High CVE-2026-26980sql injectionclickfixghost cms