threat-intel 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets A new typosquatting campaign targeting RubyGems users has been identified, leveraging a Rust-based stealer to steal browser credentials, cryptocurrency wallets, and Telegram data. The campaign utilizes a 'StubMaker' tool that generates a fake build toolchain to conceal a malicious install, and exploits a vulnerability… The Hacker News · Aug 18, 2026 High typosquattingrubymalware
threat-intel ChainDrop: Inside a Self-Propagating npm Worm A self-propagating npm worm, nicknamed ChainDrop, has infected over 400 packages, collectively downloaded hundreds of millions of times weekly. Developed by a threat actor, the worm steals sensitive data including cloud… Palo Alto Unit 42 · Aug 6, 2026 High npmgithubcredential theft
threat-intel Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library A typosquatted version of the Newtonsoft.Json library has been discovered, designed to rig live game results on Digitain, an online betting platform. The package, disguised as a legitimate library, exfiltrates rigged dat… The Hacker News · Jul 22, 2026 High NOtyposquattingriggingexfiltration
threat-intel Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware Four npm packages have been identified as containing malicious code, including a clone of the Shai-Hulud worm. One package delivers a DDoS botnet (Phantom Bot), while the others function as infostealers, stealing sensiti… The Hacker News · May 18, 2026 High NOsupply chainnpminfostealer