Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active si...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
15 articles found
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active si...
Over 100 hacked Ukrainian websites used fake Cloudflare checks to install Lunex Stealer and steal browser passwords, tokens and cryptocurrency wallets.
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on Septem...
A new variant of the macOS infostealer PamStealer is being distributed through a fake cryptocurrency wallet application, using a server-assisted decryption c...
Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that...
Cybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embe...
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer ma...
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned...
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCl...
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and ...
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to harves...
A newly disclosed macOS malware campaign dubbed MacSync weaponizes fake Claude AI installation guides to deploy a six-stage stealer and remote access trojan....
Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encry...
A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the t...
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microso...