<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Credential Stealer</title><description>Cybersecurity articles tagged #Credential Stealer on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Jscrambler NPM Packages Poisoned in Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-packages-poisoned-in-supply-chain-attack</guid><description>Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.</description><pubDate>Tue, 14 Jul 2026 10:01:24 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Malware</category><category>Credential Stealer</category></item><item><title>CVE-2026-35616: FortiClient EMS Exploit Delivers EKZ Infostealer</title><link>https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-35616-forticlient-ems-exploit-delivers-ekz-infostealer</guid><description>Attackers are actively exploiting CVE-2026-35616, an authentication bypass in FortiClient EMS, to deploy the EKZ infostealer. Protect your organization now.</description><pubDate>Thu, 28 May 2026 20:53:31 GMT</pubDate><category>CVE-2026-35616</category><category>FortiClient EMS</category><category>EKZ Infostealer</category><category>Authentication Bypass</category><category>Credential Stealer</category><category>Fortinet</category></item><item><title>FortiClient EMS Critical Flaw Exploited for Credential Stealing</title><link>https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</link><guid isPermaLink="true">https://runtimerebel.com/blog/forticlient-ems-critical-flaw-exploited-for-credential-stealing</guid><description>Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.</description><pubDate>Thu, 28 May 2026 17:21:27 GMT</pubDate><category>FortiClient EMS</category><category>Credential Stealer</category><category>Endpoint Security</category><category>Exploitation</category><category>Malware</category></item><item><title>Laravel-Lang PHP Packages Compromised: Credential Stealer Alert</title><link>https://runtimerebel.com/blog/laravel-lang-php-packages-compromised-credential-stealer-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/laravel-lang-php-packages-compromised-credential-stealer-alert</guid><description>Multiple Laravel-Lang PHP packages have been compromised to deliver a cross-platform credential stealer. Learn how to detect and mitigate this supply chain threat.</description><pubDate>Sat, 23 May 2026 12:28:26 GMT</pubDate><category>Laravel Lang</category><category>PHP</category><category>Credential Stealer</category><category>Supply Chain Attack</category><category>Composer</category></item><item><title>Nx Console 18.95.0 Compromise: VS Code Extension Credential Stealer</title><link>https://runtimerebel.com/blog/nx-console-18-95-0-compromise-vs-code-extension-credential-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/nx-console-18-95-0-compromise-vs-code-extension-credential-stealer</guid><description>Security researchers have identified a compromised version of the Nx Console VS Code extension (18.95.0) containing a malicious credential stealer.</description><pubDate>Tue, 19 May 2026 09:18:11 GMT</pubDate><category>Nx Console</category><category>VS Code</category><category>Supply Chain Attack</category><category>Rwl Angular Console</category><category>Credential Stealer</category></item><item><title>Shai-Hulud Supply Chain Attack: Malicious npm and Mistral Packages</title><link>https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-supply-chain-attack-malicious-npm-and-mistral-packages</guid><description>The Shai-Hulud campaign targets developers with over 300 signed npm and PyPI packages impersonating TanStack and Mistral to steal sensitive credentials.</description><pubDate>Tue, 12 May 2026 12:48:53 GMT</pubDate><category>Shai Hulud</category><category>NPM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Mistral AI</category><category>TanStack</category><category>Credential Stealer</category></item><item><title>PCPJack Credential Stealer: Cloud System Exploitation &amp; Spread</title><link>https://runtimerebel.com/blog/pcpjack-credential-stealer-cloud-system-exploitation-spread</link><guid isPermaLink="true">https://runtimerebel.com/blog/pcpjack-credential-stealer-cloud-system-exploitation-spread</guid><description>PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…</description><pubDate>Thu, 07 May 2026 20:32:23 GMT</pubDate><category>PCPJack</category><category>Credential Stealer</category><category>Cloud Security</category><category>Worm</category><category>TeamPCP</category></item><item><title>Backdoored PyTorch Lightning Package Drops Credential Stealer</title><link>https://runtimerebel.com/blog/backdoored-pytorch-lightning-package-drops-credential-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/backdoored-pytorch-lightning-package-drops-credential-stealer</guid><description>A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials.</description><pubDate>Mon, 04 May 2026 20:35:32 GMT</pubDate><category>PyTorch Lightning</category><category>PyPI</category><category>Credential Stealer</category><category>Supply Chain Attack</category><category>Python</category><category>Malware</category></item></channel></rss>