Skip to main content
← All Articles

Tag

#Infostealer

68 articles

Advertisement

HIGH
Supply Chain

Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware

Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.

Runtime Rebel Intel
3 min read · Mar 28, 2026
HIGH
Threat Intel

GitHub Malware Campaign: Fake VS Code Alerts Target Developers

Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.

Runtime Rebel Intel
4 min read · Mar 27, 2026
HIGH
Threat Intel

Alleged RedLine Infostealer Admin Extradited to US

US extradites Hambardzum Minasyan, suspected administrator of RedLine Malware, following Operation Magnus. Analysis of RedLine MaaS and defense strategies.

Runtime Rebel Intel
4 min read · Mar 26, 2026
HIGH
Malware

Torg Grabber Infostealer: Threat to 728 Crypto Wallets

Analysis of Torg Grabber infostealer, detailing its methods for exfiltrating sensitive data from 728 cryptocurrency wallets and 850 browser extensions.

Runtime Rebel Intel
4 min read · Mar 25, 2026
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
HIGH
Supply Chain

Malicious GitHub OpenClaw Deployer Repos Deliver Trojans

Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.

Runtime Rebel Intel
4 min read · Mar 24, 2026
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
HIGH
Supply Chain

Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows

A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.

Runtime Rebel Intel
4 min read · Mar 24, 2026

Advertisement

Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys
HIGH
Threat Intel

Lumma Stealer Phishing Campaign: Avoiding Copyright Notice Decoys

Phishing campaign targets healthcare and government sectors with copyright infringement decoys to deliver Lumma Stealer via legitimate cloud services.

Runtime Rebel Intel
4 min read · Mar 23, 2026
Trivy Supply Chain Attack: Malicious Docker Hub Images Identified
HIGH
Supply Chain

Trivy Supply Chain Attack: Malicious Docker Hub Images Identified

Attackers hijacked Trivy Docker Hub images (v0.69.4-0.69.6) to distribute infostealers and Kubernetes wipers. Learn how to detect and remediate this threat.

Runtime Rebel Intel
4 min read · Mar 23, 2026
HIGH
Malware

VoidStealer: Bypassing Chrome ABE via Remote Debugging Protocol

VoidStealer malware uses a novel debugger technique to bypass Google Chrome’s Application-Bound Encryption and exfiltrate browser-stored credentials.

Runtime Rebel Intel
3 min read · Mar 22, 2026
HIGH
Supply Chain

Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub

Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.

Runtime Rebel Intel
3 min read · Mar 21, 2026
Credential Theft Surge: Understanding Infostealer & AI Social Engineering
HIGH
Identity & Access

Credential Theft Surge: Understanding Infostealer & AI Social Engineering

Credential theft surged in late 2025, driven by sophisticated infostealer malware and AI-enhanced social engineering.

Runtime Rebel Intel
4 min read · Mar 18, 2026
GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions
MEDIUM
Malware

GlassWorm Malware: Detecting Obfuscated Payloads in Browser Extensions

Technical analysis of GlassWorm (ChromeLoader) evolution, detailing how the malware hides malicious JavaScript within legitimate browser extension dependencies.

Runtime Rebel Intel
4 min read · Mar 17, 2026
2025 Identity Threat Report: Analyzing the Infostealer Economy
HIGH
Identity & Access

2025 Identity Threat Report: Analyzing the Infostealer Economy

Recorded Future's 2025 Identity Threat Landscape Report examines how infostealer malware and session cookie theft drive the modern credential threat economy.

Runtime Rebel Intel
3 min read · Mar 16, 2026
ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools
HIGH
Threat Intel

ClickFix Campaigns Deliver MacSync macOS Infostealer via Fake AI Tools

Threat actors use ClickFix social engineering tactics to deploy the MacSync infostealer on macOS systems via fraudulent AI software installers.

Runtime Rebel Intel
4 min read · Mar 16, 2026
HIGH
Malware

Fake Chrome Update Campaigns Deploying NetSupport RAT

Technical analysis of phishing campaigns using JavaScript-injected websites to distribute NetSupport RAT via fake browser update overlays.

Runtime Rebel Intel
4 min read · Mar 16, 2026
HIGH
Malware

InstallFix Campaign: Cloned AI Tool Sites Distribute Info-Stealers

The InstallFix campaign uses cloned AI tool websites and malicious PowerShell commands to distribute info-stealers like Lumma and Vidar. Stay protected.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Supply Chain

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.

Runtime Rebel Intel
4 min read · Mar 7, 2026
HIGH
Malware

Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers

Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.

Runtime Rebel Intel
4 min read · Mar 6, 2026
MEDIUM
Malware

Arkanix Stealer: Rapid Disappearance of C++ & Python Malware

Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.

Runtime Rebel Intel
4 min read · Feb 25, 2026
MEDIUM
Malware

Arkanix Stealer: Analysis of AI-Assisted Infostealer Development Patterns

A technical evaluation of the Arkanix Stealer operation, highlighting its AI-driven code characteristics and credential-harvesting capabilities.

Runtime Rebel Intel
2 min read · Feb 23, 2026