Malware
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster
Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.
SleeperGem: Hijacked Dormant RubyGems Accounts Drop a Persistent Backdoor on Developer Machines
Researchers disclose SleeperGem, a RubyGems supply-chain attack that hijacked long-dormant maintainer accounts to publish trojanized gems whose loader specifically targets developer workstations while evading CI runners.
ViteVenom: Scoped npm Packages Impersonate @vitejs to Deliver a Blockchain-C2 RAT
Checkmarx tracks ViteVenom, a sequel to the ChainVeil campaign, in which seven scoped npm packages impersonating the @vitejs namespace deploy a RAT that fetches its C2 address from Tron and Aptos blockchain transactions.
AsyncAPI npm Packages Backdoored via GitHub Actions 'Pwn Request', Deliver Miasma RAT
A stolen CI token let attackers push a malicious commit into AsyncAPI's npm packages on July 14, delivering an IPFS-hosted Miasma RAT to millions of weekly installs — this time configured as a stealthy botnet, not a self-propagating worm.
Injective Labs' @injectivelabs/sdk-ts npm Package Backdoored to Steal Wallet Private Keys
A compromised release of Injective Labs' TypeScript SDK, @injectivelabs/sdk-ts, and 17 dependent packages hooked wallet key-derivation functions to exfiltrate mnemonic seed phrases and private keys to an endpoint disguised as legitimate Injective infrastructure.
17 Malicious npm/PyPI Packages Impersonate Paysafe, Skrill, and Neteller SDKs to Steal CI/CD Secrets
A coordinated typosquatting campaign published 13 npm and 4 PyPI packages that mimic Paysafe, Skrill, and Neteller payment SDKs, returning fake success responses while exfiltrating API keys, AWS credentials, and CI tokens to an obfuscated C2 host.
Malicious NuGet Package Impersonates Sicoob Banking SDK, Exfiltrates mTLS Certificates Through Sentry
A trojanized NuGet package posing as the official Sicoob C# SDK reads PFX certificates off disk and ships them, plus the password, to an attacker-controlled Sentry endpoint — abusing a trusted telemetry service as its exfiltration channel.
TrapDoor: Cross-Ecosystem Supply Chain Attack Plants Credential Stealers and AI-Assistant Backdoors
A coordinated campaign across npm, PyPI, and Crates.io seeded 34+ malicious packages that steal developer secrets and plant hidden instructions to weaponize AI coding assistants.
Laravel-Lang Supply Chain Attack: 233 Package Versions Backdoored to Steal Cloud and CI/CD Secrets
Attackers repointed git tags across four Laravel-Lang Composer packages to a malicious fork, backdooring 233 versions with a credential stealer that drains cloud, CI/CD, and developer secrets.
ZionSiphon: OT Sabotage Malware Targeting Israeli Water and Desalination Plants
Darktrace dissects ZionSiphon, a politically motivated OT malware built to tamper with chlorine and pressure in Israeli water systems. Broken by bad crypto, but the blueprint is real.
CPUID Website Compromised to Deliver STX RAT via CPU-Z and HWMonitor Downloads
Attackers compromised CPUID's download infrastructure for ~19 hours, replacing CPU-Z and HWMonitor installers with trojanized builds that sideload STX RAT via a malicious CRYPTBASE.dll.
North Korea's Contagious Interview Campaign Hits 1,700 Malicious Packages Across Five Ecosystems
DPRK-linked Contagious Interview operation now spans npm, PyPI, Go Modules, crates.io, and Packagist with 1,700+ poisoned packages delivering BeaverTail and InvisibleFerret malware.
Dead Drops on the Chain: Why Blockchain Became the C2 Infrastructure Defenders Can't Take Down
From EtherHiding to CanisterWorm to GlassWorm — attackers spent three years systematically proving that blockchain is the unkillable C2 channel. Here's how each technique works and what you can actually do about it.