Skip to main content
← All Articles

Tag

#Malware

31 articles

Advertisement

MA
HIGH
Malware

GlassWorm Malware Resurfaces via 73 OpenVSX Sleeper Extensions

A new GlassWorm campaign exploits the OpenVSX ecosystem with 73 'sleeper' extensions, posing a significant supply chain threat to developers.

Runtime Rebel Intel
4 min read·Apr 28, 2026
MA
CRITICAL
Malware

AgingFly Malware: Credential Theft Operations Against Ukraine

Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and

Runtime Rebel Intel
5 min read·Apr 16, 2026
SU
HIGH
Supply Chain

Trojanized CPU-Z and HWMonitor Distributed via CPUID Site Hack

Russian-speaking threat actors compromised the CPUID website to distribute STX RAT through trojanized versions of CPU-Z and HWMonitor diagnostic tools.

Runtime Rebel Intel
3 min read·Apr 13, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
CRITICAL
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
3 min read·Apr 8, 2026
MA
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and

Runtime Rebel Intel
4 min read·Apr 3, 2026
MA
HIGH
Malware

NoVoice Android Malware on Google Play: 2.3 Million Devices Infected

NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.

Runtime Rebel Intel
5 min read·Apr 1, 2026
MA
HIGH
Malware

DeepLoad Malware: Analysis of ClickFix Attacks and Mitigation

DeepLoad malware, observed in ClickFix attacks, steals credentials, installs malicious browser extensions, and propagates via USB drives. Learn TTPs and defense

Runtime Rebel Intel
4 min read·Apr 1, 2026
WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems
HIGH
Malware

WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems

Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting

Runtime Rebel Intel
4 min read·Apr 1, 2026
TH
MEDIUM
Threat Intel

macOS Terminal ClickFix Protections: Blocking Malicious Shell Commands

Apple introduces Terminal warnings in macOS Sequoia 15.2 to combat ClickFix social engineering attacks that trick users into executing malicious shell scripts.

Runtime Rebel Intel
3 min read·Mar 30, 2026
SU
CRITICAL
Supply Chain

trivy-action Supply Chain Attack: Scattered Swarm Steals GitHub Secrets

Analysis of the trivy-action supply chain compromise by Scattered Swarm. Learn how GitHub runner secrets were stolen and critical mitigation steps.

Runtime Rebel Intel
5 min read·Mar 21, 2026
SnappyClient C2 Implant Targets Crypto Wallets for Data Theft
HIGH
Malware

SnappyClient C2 Implant Targets Crypto Wallets for Data Theft

A new C2 implant, SnappyClient, is actively targeting crypto wallets, facilitating remote access, extensive data theft, and persistent spying on victims.

Runtime Rebel Intel
5 min read·Mar 19, 2026
GlassWorm Abuses Open VSX Registry in Supply-Chain Attack
HIGH
Supply Chain

GlassWorm Abuses Open VSX Registry in Supply-Chain Attack

The GlassWorm campaign exploits transitive dependencies in 72 Open VSX extensions to deliver malicious loaders into developer environments.

Runtime Rebel Intel
3 min read·Mar 14, 2026