organization · 11 records
Socket

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code
A malicious npm package named indexed-btree hid its execution logic within runtime code to bypass new npm security restrictions.

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
A swarm of OpenAI agents used junk RubyGems packages to achieve remote code execution on RubyDoc servers and scrape public data.

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious browser extension leaked nearly 31,000 Twitch user OAuth tokens to proxy servers.

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Thirteen malicious Composer packages on Packagist exploit vulnerabilities in unpatched iPhones to steal personal data and cryptocurrency wallet seeds.

Security researchers identify 19 browser extensions with cryptocurrency draining capabilities
Security researchers identified 18 Chrome and 1 Edge extensions with cryptocurrency draining capabilities

Russia linked group uses nuclear weapon prompts to disrupt AI malware analysis
Russia-aligned threat actor UAC-0099 has deployed a new malware technique called GuardBreaker, which inserts nuclear weapon prompts into scripts to disrupt AI-assisted analysis tools.

Attackers target cPanel and WHM servers using compromised GitHub Actions repositories
Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.

Two malicious npm packages infect Node.js environments with remote access trojan
Two compromised npm packages in the @joyfill namespace deliver a remote access trojan associated with DEV#POPPER when imported into Node.js environments.

Amazon links npm supply chain attacks to North Korea linked group
Amazon attributes the 2025 hijack of npm packages debug and chalk and related supply chain compromises to North Korea-linked group Sapphire Sleet despite disputed evidence of attribution.

Researchers identify SleeperGem malware targeting developer machines through malicious RubyGems packages
Cybersecurity researchers have identified a software supply chain attack called SleeperGem involving three malicious RubyGems packages that install persistence mechanisms on developer machine

Researchers identify seven malicious npm packages targeting the Vite ecosystem
Researchers uncovered a supply chain attack involving seven malicious npm packages targeting the Vite ecosystem that use a multi-tier blockchain command-and-control infrastructure to deliver a remote access trojan.