Skip to main content
← All Articles

Tag

#Credential Stealer

8 articles

Advertisement

HIGH
Supply Chain

Jscrambler NPM Packages Poisoned in Supply Chain Attack

Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.

Runtime Rebel Intel
4 min read · Jul 14, 2026
CRITICAL
Vulnerabilities

CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer

Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.

Runtime Rebel Intel
4 min read · May 28, 2026
FortiClient EMS Critical Flaw Exploited for Credential Stealing
CRITICAL
Vulnerabilities

FortiClient EMS Critical Flaw Exploited for Credential Stealing

Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.

Runtime Rebel Intel
5 min read · May 28, 2026
Laravel-Lang PHP Packages Compromised: Credential Stealer Alert
HIGH
Supply Chain

Laravel-Lang PHP Packages Compromised: Credential Stealer Alert

Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.

Runtime Rebel Intel
4 min read · May 23, 2026
Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer
HIGH
Supply Chain

Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer

Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.

Runtime Rebel Intel
3 min read · May 19, 2026
HIGH
Supply Chain

Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages

The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.

Runtime Rebel Intel
4 min read · May 12, 2026

Advertisement

PCPJack Credential Stealer: Cloud System Exploitation & Spread
HIGH
Malware

PCPJack Credential Stealer: Cloud System Exploitation & Spread

PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…

Runtime Rebel Intel
5 min read · May 7, 2026
HIGH
Supply Chain

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.

Runtime Rebel Intel
4 min read · May 4, 2026