Malware is a topic tracked in our intelligence system with 5 linked articles.
The FBI arrested a 21-year-old for publishing fake Steam games containing malware that infected thousands and drained some victims’ crypto wallets.
Microsoft packages reportedly laced with a credential-stealer; 73 packages execute a self-replicating stealer when opened by an AI agent.
Official Red Hat npm channel was compromised, enabling a credential-stealing worm that affected over 30 packages and exposed CI/CD credentials, with Red Hat reporting no customer impact so far.
TanStack npm packages were compromised via a supply-chain attack using optionalDependencies to pull in a malicious git commit; payload exfiltrates credentials and republishes vulnerable packages; GitHub Actions OIDC trusted-publisher config suggests CI workflow compromise; multiple TanStack packages affected with two bad versions each, plus broader ecosystem risk.
A multi-stage supply-chain attack cascaded through npm → Rust → Python tooling, compromising millions and triggering a formal CVE with ongoing regulatory classification debates.
Kaspersky reports a China-linked backdoor campaign in Daemon Tools with thousands of infection attempts and at least 12 successful hacks.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.