<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Infostealer</title><description>Cybersecurity articles tagged #Infostealer on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Infostealers Target Anthropic Claude Users via Session Theft</title><link>https://runtimerebel.com/blog/infostealers-target-anthropic-claude-users-via-session-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/infostealers-target-anthropic-claude-users-via-session-theft</guid><description>Threat actors are employing various infostealers to compromise Anthropic Claude user accounts via session theft, posing significant risks.</description><pubDate>Tue, 01 Sep 2026 02:42:19 GMT</pubDate><category>Infostealer</category><category>Session Theft</category><category>Anthropic</category><category>Claude</category><category>Credential Theft</category></item><item><title>WordlistLoader Evades Detection, Delivers Amatera Infostealer</title><link>https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordlistloader-evades-detection-delivers-amatera-infostealer</guid><description>WordlistLoader uses a novel text-based obfuscation to bypass security, deploying the Amatera infostealer in ClickFix-style campaigns, posing a significant threat.</description><pubDate>Tue, 25 Aug 2026 08:33:21 GMT</pubDate><category>Infostealer</category><category>Malware</category><category>Obfuscation</category><category>ClickFix</category><category>WordlistLoader</category></item><item><title>Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware</title><link>https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</guid><description>Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.</description><pubDate>Fri, 21 Aug 2026 00:43:46 GMT</pubDate><category>Rust</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DPRK</category><category>Crates Io</category></item><item><title>AmnesiaStealer macOS Malware Hijacks Browser Sessions via Remote Control</title><link>https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control</guid><description>AmnesiaStealer targets macOS users via ClickFix attacks, cloning Chromium profiles to enable live remote control of authenticated browser sessions.</description><pubDate>Sun, 16 Aug 2026 16:14:35 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickFix</category><category>Chromium</category><category>AmnesiaStealer</category></item><item><title>Critical npm Supply Chain Attack Delivers Cross-Platform RAT/Infostealer</title><link>https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-npm-supply-chain-attack-delivers-cross-platform-rat-infostealer</guid><description>Critical npm supply chain attack involving nearly 800 malicious packages delivers WEL1DROPPER RAT and infostealer to Windows, macOS, and Linux users.</description><pubDate>Sat, 08 Aug 2026 00:54:29 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>RAT</category><category>WEL1DROPPER</category></item><item><title>ClickFix Attack Deploys macOS Infostealer for Crypto Theft</title><link>https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attack-deploys-macos-infostealer-for-crypto-theft</guid><description>The ClickFix attack leverages a Go-based macOS infostealer to pilfer cryptocurrency, browser data, and Apple Keychain credentials via a Bash script loader.</description><pubDate>Fri, 07 Aug 2026 02:08:44 GMT</pubDate><category>ClickFix</category><category>macOS</category><category>Infostealer</category><category>Cryptocurrency</category><category>Golang</category></item><item><title>ChainDrop npm Supply Chain Attack Steals Developer Credentials</title><link>https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-supply-chain-attack-steals-developer-credentials</guid><description>Massive ChainDrop npm supply chain attack compromises over 1,300 packages, stealing developer and cloud credentials through malicious preinstall scripts.</description><pubDate>Tue, 04 Aug 2026 17:30:58 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>JavaScript</category><category>ChainDrop</category></item><item><title>Flying Eagle Mobile RAT Builder: China&apos;s Infostealer-as-a-Service</title><link>https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/flying-eagle-mobile-rat-builder-china-s-infostealer-as-a-service</guid><description>Analysis of the &apos;Flying Eagle&apos; mobile RAT builder, a sophisticated malware-as-a-service platform from China, used by threat groups to deploy infostealers targeting…</description><pubDate>Thu, 30 Jul 2026 02:32:07 GMT</pubDate><category>Flying Eagle</category><category>Mobile RAT</category><category>Android Malware</category><category>Infostealer</category><category>Malware as a Service</category><category>Financial Fraud</category><category>China</category></item><item><title>JavaScript Smuggling: In-Memory Malware Assembly Evades Defenses</title><link>https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/javascript-smuggling-in-memory-malware-assembly-evades-defenses</guid><description>Attackers use JavaScript Smuggling and Blob objects to assemble infostealer malware in-memory, bypassing security filters on fake crypto and trading sites.</description><pubDate>Sat, 25 Jul 2026 16:59:37 GMT</pubDate><category>Javascript Smuggling</category><category>Infostealer</category><category>Browser Security</category><category>Vidar</category><category>StealC</category></item><item><title>AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment</title><link>https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</guid><description>An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 18:05:04 GMT</pubDate><category>AI Assisted Phishing</category><category>WebDAV</category><category>Infostealer</category><category>Malware Toolkit</category><category>Mexico</category><category>Windows</category><category>Rapid7</category></item><item><title>ACR Stealer Campaign Targets Microsoft Enterprise Credentials</title><link>https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</guid><description>Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.</description><pubDate>Sat, 18 Jul 2026 16:59:16 GMT</pubDate><category>ACR Stealer</category><category>Infostealer</category><category>Microsoft</category><category>Credential Theft</category></item><item><title>North Korean Actors Use SVG Steganography to Deliver OtterCookie</title><link>https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</guid><description>North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.</description><pubDate>Fri, 17 Jul 2026 17:13:52 GMT</pubDate><category>Lazarus Group</category><category>OtterCookie</category><category>Contagious Interview</category><category>Steganography</category><category>Node Js</category><category>Infostealer</category></item><item><title>OkoBot Framework: Multi-Payload Data &amp; Crypto Theft Attacks</title><link>https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/okobot-framework-multi-payload-data-crypto-theft-attacks</guid><description>The new OkoBot framework deploys over 20 distinct payloads, primarily targeting cryptocurrency seed phrases, credentials, and sensitive data.</description><pubDate>Thu, 16 Jul 2026 21:02:27 GMT</pubDate><category>OkoBot</category><category>Malware</category><category>Infostealer</category><category>Cryptocurrency Theft</category><category>Credential Theft</category><category>Data Exfiltration</category></item><item><title>ClickLock macOS Stealer: How Attackers Coerce Victims via App Kill Loops</title><link>https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</link><guid isPermaLink="true">https://runtimerebel.com/blog/clicklock-macos-stealer-how-attackers-coerce-victims-via-app-kill-loops</guid><description>ClickLock is a new macOS infostealer that terminates essential system processes every 210ms to force users into disclosing their login passwords.</description><pubDate>Thu, 16 Jul 2026 14:03:10 GMT</pubDate><category>macOS</category><category>Infostealer</category><category>ClickLock</category><category>Social Engineering</category><category>Persistence</category></item><item><title>Malicious GitHub Repositories: Infostealer Distribution Threat</title><link>https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</guid><description>Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.</description><pubDate>Tue, 14 Jul 2026 21:03:07 GMT</pubDate><category>GitHub</category><category>Infostealer</category><category>Malware Distribution</category><category>Supply Chain Attack</category><category>Software Impersonation</category></item><item><title>Jscrambler npm Package Backdoored with Infostealer Malware</title><link>https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-npm-package-backdoored-with-infostealer-malware</guid><description>A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.</description><pubDate>Mon, 13 Jul 2026 20:59:06 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Infostealer</category><category>Malware</category><category>Node Js</category></item><item><title>jscrambler 8.14.0 Compromised: Rust Infostealer Supply Chain Attack</title><link>https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/jscrambler-8-14-0-compromised-rust-infostealer-supply-chain-attack</guid><description>The jscrambler 8.14.0 npm release was compromised with a malicious preinstall hook dropping a cross-platform Rust infostealer. Mitigate the threat now.</description><pubDate>Sat, 11 Jul 2026 20:50:45 GMT</pubDate><category>Jscrambler</category><category>NPM</category><category>Supply Chain Attack</category><category>Rust Malware</category><category>Infostealer</category></item><item><title>BusySnake Infostealer Targets Critical Infrastructure: Armored Likho&apos;s TTPs</title><link>https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/busysnake-infostealer-targets-critical-infrastructure-armored-likho-s-ttps</guid><description>BusySnake infostealer, deployed by Armored Likho, infiltrates critical infrastructure in Russia, Brazil, and Kazakhstan. Understand their TTPs and mitigation strategies.</description><pubDate>Tue, 07 Jul 2026 03:34:06 GMT</pubDate><category>BusySnake</category><category>Infostealer</category><category>Armored Likho</category><category>Critical Infrastructure</category><category>Government</category><category>Electrical Power</category><category>Russia</category><category>Brazil</category><category>Kazakhstan</category></item><item><title>Djinn Stealer Targets Cloud &amp; AI Credentials via SimpleHelp CVE-2026-48558</title><link>https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</link><guid isPermaLink="true">https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</guid><description>Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.</description><pubDate>Tue, 30 Jun 2026 09:19:57 GMT</pubDate><category>Djinn Stealer</category><category>CVE-2026-48558</category><category>SimpleHelp</category><category>Infostealer</category><category>Cloud Security</category><category>AI Credentials</category><category>Authentication Bypass</category></item><item><title>Amadey &amp; StealC Malware C2 Infrastructure Disrupted</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</guid><description>Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.</description><pubDate>Wed, 24 Jun 2026 16:52:14 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Malware</category><category>Botnet</category><category>Infostealer</category><category>Cybercrime</category><category>C2 Takedown</category><category>Microsoft</category></item><item><title>Amadey &amp; StealC Malware Operations Disrupted by Operation Endgame</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-operations-disrupted-by-operation-endgame</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-operations-disrupted-by-operation-endgame</guid><description>Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.</description><pubDate>Wed, 24 Jun 2026 16:51:44 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Operation Endgame</category><category>Malware</category><category>Infostealer</category><category>Cybercrime</category><category>Law Enforcement</category></item><item><title>Phantom Stealer: Fileless Credential Theft &amp; Evasion</title><link>https://runtimerebel.com/blog/phantom-stealer-fileless-credential-theft-evasion</link><guid isPermaLink="true">https://runtimerebel.com/blog/phantom-stealer-fileless-credential-theft-evasion</guid><description>Phantom Stealer uses fileless execution and advanced anti-analysis to steal browser credentials. Learn its TTPs and how to detect this evasive malware.</description><pubDate>Wed, 17 Jun 2026 05:47:27 GMT</pubDate><category>Phantom Stealer</category><category>Fileless Malware</category><category>Credential Theft</category><category>Infostealer</category><category>Browser Credentials</category><category>Anti Analysis</category></item><item><title>Lumma Stealer Distributed via Fake EditPro AI Image Generator</title><link>https://runtimerebel.com/blog/lumma-stealer-distributed-via-fake-editpro-ai-image-generator</link><guid isPermaLink="true">https://runtimerebel.com/blog/lumma-stealer-distributed-via-fake-editpro-ai-image-generator</guid><description>Threat actors are leveraging a fake AI image generator website to distribute Lumma Stealer malware targeting both Windows and macOS systems.</description><pubDate>Sat, 13 Jun 2026 09:17:02 GMT</pubDate><category>Lumma Stealer</category><category>EditPro AI</category><category>Infostealer</category><category>macOS Malware</category><category>Social Engineering</category></item><item><title>400+ Arch Linux AUR Packages Hijacked: eBPF Rootkit and Infostealer</title><link>https://runtimerebel.com/blog/400-arch-linux-aur-packages-hijacked-ebpf-rootkit-and-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/400-arch-linux-aur-packages-hijacked-ebpf-rootkit-and-infostealer</guid><description>Attackers compromised over 400 Arch User Repository (AUR) packages to deploy Rust-based infostealers and eBPF rootkits, targeting developer credentials.</description><pubDate>Fri, 12 Jun 2026 20:51:23 GMT</pubDate><category>Arch Linux</category><category>AUR</category><category>Supply Chain Attack</category><category>eBPF Rootkit</category><category>Infostealer</category><category>Rust Malware</category></item><item><title>AUR Compromise: 400+ Packages Distributing Rootkits and Infostealers</title><link>https://runtimerebel.com/blog/aur-compromise-400-packages-distributing-rootkits-and-infostealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/aur-compromise-400-packages-distributing-rootkits-and-infostealers</guid><description>Over 400 Arch User Repository (AUR) packages compromised to deploy Linux rootkits and harvest credentials, tokens, and sensitive developer data.</description><pubDate>Fri, 12 Jun 2026 17:06:24 GMT</pubDate><category>Arch Linux</category><category>AUR</category><category>Supply Chain Attack</category><category>Rootkit</category><category>Infostealer</category></item><item><title>OnyxC2 Stealer: Enterprise-Grade Info-Theft for $250/Month</title><link>https://runtimerebel.com/blog/onyxc2-stealer-enterprise-grade-info-theft-for-250-month</link><guid isPermaLink="true">https://runtimerebel.com/blog/onyxc2-stealer-enterprise-grade-info-theft-for-250-month</guid><description>OnyxC2 stealer targets over 200 applications and extensions, using encrypted payloads, DLL sideloading, and in-memory execution to evade detection.</description><pubDate>Thu, 11 Jun 2026 13:35:59 GMT</pubDate><category>OnyxC2</category><category>Infostealer</category><category>DLL Side Loading</category><category>Encrypted Payloads</category><category>Malware as a Service</category></item><item><title>GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware</title><link>https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</guid><description>GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.</description><pubDate>Tue, 09 Jun 2026 17:00:46 GMT</pubDate><category>GitHub</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DevSecOps</category></item><item><title>Python-Based Infostealer Masked as PDF Targets Browser Credentials</title><link>https://runtimerebel.com/blog/python-based-infostealer-masked-as-pdf-targets-browser-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-based-infostealer-masked-as-pdf-targets-browser-credentials</guid><description>Technical analysis of a PyInstaller-compiled infostealer using Discord webhooks to exfiltrate browser credentials, crypto wallets, and session tokens.</description><pubDate>Tue, 09 Jun 2026 09:19:02 GMT</pubDate><category>Infostealer</category><category>Pyinstaller</category><category>Discord Webhook</category><category>Credential Theft</category><category>Malware Analysis</category></item><item><title>IronWorm Malware: 36 npm Packages Identified in Supply Chain Attack</title><link>https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/ironworm-malware-36-npm-packages-identified-in-supply-chain-attack</guid><description>Security researchers discover a campaign delivering IronWorm infostealer malware via 36 malicious npm packages using preinstall script execution hooks.</description><pubDate>Thu, 04 Jun 2026 17:09:30 GMT</pubDate><category>NPM</category><category>IronWorm</category><category>Infostealer</category><category>Supply Chain Attack</category><category>JavaScript</category></item><item><title>ACR Stealer Distributed via Fake Claude AI Desktop Site</title><link>https://runtimerebel.com/blog/acr-stealer-distributed-via-fake-claude-ai-desktop-site</link><guid isPermaLink="true">https://runtimerebel.com/blog/acr-stealer-distributed-via-fake-claude-ai-desktop-site</guid><description>Threat actors are distributing ACR Stealer malware through a fraudulent Claude AI desktop application site, targeting browser credentials and crypto wallets.</description><pubDate>Tue, 26 May 2026 00:55:39 GMT</pubDate><category>ACR Stealer</category><category>Claude AI</category><category>Infostealer</category><category>Phishing</category><category>Credential Theft</category></item><item><title>Analysis of Cross-Platform NPM Stealer Using Discord Webhooks</title><link>https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-cross-platform-npm-stealer-using-discord-webhooks</guid><description>Technical teardown of an obfuscated Node.js infostealer targeting Discord tokens, crypto wallets, and browser credentials via cross-platform scripts.</description><pubDate>Fri, 22 May 2026 09:17:57 GMT</pubDate><category>NPM</category><category>Node Js</category><category>Infostealer</category><category>Discord Webhook</category><category>Obfuscation</category></item><item><title>Ukraine Identifies Odesa-Based Infostealer Operator</title><link>https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</link><guid isPermaLink="true">https://runtimerebel.com/blog/ukraine-identifies-odesa-based-infostealer-operator</guid><description>Ukrainian cyberpolice and US law enforcement identify an 18-year-old in Odesa suspected of compromising 28,000 accounts for dark web monetization.</description><pubDate>Thu, 21 May 2026 00:58:31 GMT</pubDate><category>Infostealer</category><category>Ukraine Cyberpolice</category><category>Data Theft</category><category>Credential Stuffing</category><category>Odesa</category></item><item><title>SHub macOS Infostealer Spoofs Apple Security Updates, Installs Backdoor</title><link>https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</link><guid isPermaLink="true">https://runtimerebel.com/blog/shub-macos-infostealer-spoofs-apple-security-updates-installs-backdoor</guid><description>A new SHub macOS infostealer variant employs fake Apple security update prompts via AppleScript to install a backdoor, threatening user data and system integrity.</description><pubDate>Tue, 19 May 2026 00:57:05 GMT</pubDate><category>SHub</category><category>macOS</category><category>Infostealer</category><category>AppleScript</category><category>Backdoor</category><category>Phishing</category></item><item><title>Shai-Hulud Infostealer Surfaces in Malicious npm Package Campaign</title><link>https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/shai-hulud-infostealer-surfaces-in-malicious-npm-package-campaign</guid><description>Leaked Shai-Hulud malware is targeting Node.js developers via malicious npm packages, exfiltrating sensitive data and credentials to Telegram-based C2.</description><pubDate>Mon, 18 May 2026 20:37:20 GMT</pubDate><category>NPM</category><category>Shai Hulud</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Malicious Packages</category></item><item><title>Malicious Windows 11 ISOs Deliver Vidar Infostealer — Analysis</title><link>https://runtimerebel.com/blog/malicious-windows-11-isos-deliver-vidar-infostealer-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-windows-11-isos-deliver-vidar-infostealer-analysis</guid><description>Security researchers warn of fake Windows 11 ISO installers delivering Vidar and RedLine infostealers through sophisticated DLL side-loading techniques.</description><pubDate>Tue, 12 May 2026 05:19:19 GMT</pubDate><category>Vidar Stealer</category><category>Windows 11</category><category>Iso Malware</category><category>DLL Side Loading</category><category>Infostealer</category></item><item><title>Compromised Checkmarx Jenkins Plugin Spreads Infostealer</title><link>https://runtimerebel.com/blog/compromised-checkmarx-jenkins-plugin-spreads-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-checkmarx-jenkins-plugin-spreads-infostealer</guid><description>Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.</description><pubDate>Tue, 12 May 2026 00:48:58 GMT</pubDate><category>Checkmarx AST</category><category>Jenkins</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Software Supply Chain</category><category>Plugin Compromise</category><category>Credential Theft</category></item><item><title>Fake OpenAI Privacy Filter Repository Distributes Rust Info-Stealer</title><link>https://runtimerebel.com/blog/fake-openai-privacy-filter-repository-distributes-rust-info-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-openai-privacy-filter-repository-distributes-rust-info-stealer</guid><description>A malicious Hugging Face repository impersonating OpenAI&apos;s privacy tool reached 244k downloads, delivering a Rust-based information stealer to Windows users.</description><pubDate>Mon, 11 May 2026 09:17:45 GMT</pubDate><category>Hugging Face</category><category>OpenAI</category><category>Infostealer</category><category>Rust</category><category>Supply Chain Attack</category><category>Malicious Repositories</category></item><item><title>Claude.ai Malvertising: How Attackers Abuse Shared Chats for macOS Malware</title><link>https://runtimerebel.com/blog/claude-ai-malvertising-how-attackers-abuse-shared-chats-for-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-ai-malvertising-how-attackers-abuse-shared-chats-for-macos-malware</guid><description>Threat actors are leveraging Google Ads and legitimate Claude.ai shared chats to distribute macOS infostealers, effectively bypassing traditional web filters.</description><pubDate>Sun, 10 May 2026 20:19:55 GMT</pubDate><category>macOS Malware</category><category>Claude AI</category><category>Google Ads</category><category>Malvertising</category><category>Infostealer</category><category>Cuckoo</category></item><item><title>Fake OpenAI Hugging Face Repository Distributes Infostealer Malware</title><link>https://runtimerebel.com/blog/fake-openai-hugging-face-repository-distributes-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-openai-hugging-face-repository-distributes-infostealer-malware</guid><description>Attackers leveraged a fraudulent OpenAI repository on Hugging Face to distribute infostealers. Learn to detect and mitigate these AI supply chain threats.</description><pubDate>Sat, 09 May 2026 16:22:38 GMT</pubDate><category>Hugging Face</category><category>OpenAI</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Social Engineering</category></item><item><title>ClickFix Attacks Distribute Vidar Stealer: ACSC Warning &amp; Mitigation</title><link>https://runtimerebel.com/blog/clickfix-attacks-distribute-vidar-stealer-acsc-warning-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/clickfix-attacks-distribute-vidar-stealer-acsc-warning-mitigation</guid><description>The ACSC warns Australian organizations of active ClickFix social engineering attacks deploying Vidar Stealer malware, risking data theft. Learn detection and mitigation.</description><pubDate>Thu, 07 May 2026 20:33:35 GMT</pubDate><category>Vidar Stealer</category><category>ClickFix</category><category>Social Engineering</category><category>ACSC</category><category>Infostealer</category><category>Australia</category></item><item><title>Google Chrome ABE Bypass: Heightened Infostealer Threat</title><link>https://runtimerebel.com/blog/google-chrome-abe-bypass-heightened-infostealer-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-abe-bypass-heightened-infostealer-threat</guid><description>VoidStealer Trojan authors bypass Google Chrome&apos;s App-Bound Encryption (ABE), enabling infostealers to exfiltrate cookies and credentials from users.</description><pubDate>Thu, 07 May 2026 00:51:02 GMT</pubDate><category>Google Chrome</category><category>App Bound Encryption</category><category>ABE Bypass</category><category>VoidStealer</category><category>Infostealer</category><category>Data Exfiltration</category></item><item><title>LofyGang Targets Minecraft Players with LofyStealer Malware</title><link>https://runtimerebel.com/blog/lofygang-targets-minecraft-players-with-lofystealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/lofygang-targets-minecraft-players-with-lofystealer-malware</guid><description>Brazilian cybercrime group LofyGang resurfaces after three years, deploying LofyStealer (GrabBot) disguised as a Minecraft &apos;Slinky&apos; hack to steal player credentials.</description><pubDate>Tue, 28 Apr 2026 20:34:56 GMT</pubDate><category>LofyGang</category><category>LofyStealer</category><category>GrabBot</category><category>Minecraft</category><category>Infostealer</category><category>Cybercrime</category></item><item><title>Malicious PyPI Package elementary-data Hijacked for Infostealer</title><link>https://runtimerebel.com/blog/malicious-pypi-package-elementary-data-hijacked-for-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-pypi-package-elementary-data-hijacked-for-infostealer</guid><description>High-profile supply chain attack on the elementary-data PyPI package compromises developer credentials and crypto wallets via account takeover. Patch now.</description><pubDate>Mon, 27 Apr 2026 16:40:27 GMT</pubDate><category>PyPI</category><category>Elementary Data</category><category>Infostealer</category><category>Python Security</category><category>Account Takeover</category></item><item><title>Python Infostealer Targeting Browser Credentials and Discord Tokens</title><link>https://runtimerebel.com/blog/python-infostealer-targeting-browser-credentials-and-discord-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-infostealer-targeting-browser-credentials-and-discord-tokens</guid><description>Technical analysis of a Python-based infostealer leveraging Discord webhooks for exfiltration, targeting browser credentials and session tokens.</description><pubDate>Tue, 21 Apr 2026 08:46:00 GMT</pubDate><category>Python Malware</category><category>Infostealer</category><category>Discord Webhooks</category><category>Credential Theft</category><category>Browser Security</category></item><item><title>Lumma Stealer and Sectop RAT Dual Infection Chain Analysis</title><link>https://runtimerebel.com/blog/lumma-stealer-and-sectop-rat-dual-infection-chain-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/lumma-stealer-and-sectop-rat-dual-infection-chain-analysis</guid><description>Technical breakdown of the Lumma Stealer and Sectop RAT (ArechClient2) infection chain, detailing C2 communication and persistence mechanisms.</description><pubDate>Fri, 17 Apr 2026 08:45:30 GMT</pubDate><category>Lumma Stealer</category><category>Sectop RAT</category><category>Arechclient2</category><category>Infostealer</category><category>Threat Intelligence</category></item><item><title>Storm Infostealer: Bypassing Local Decryption for Session Hijacking</title><link>https://runtimerebel.com/blog/storm-infostealer-bypassing-local-decryption-for-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/storm-infostealer-bypassing-local-decryption-for-session-hijacking</guid><description>Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.</description><pubDate>Mon, 13 Apr 2026 16:33:45 GMT</pubDate><category>Storm</category><category>Infostealer</category><category>Session Hijacking</category><category>Credential Theft</category><category>Varonis</category></item><item><title>Chrome DBSC: Securing Session Cookies with Device Binding — Analysis</title><link>https://runtimerebel.com/blog/chrome-dbsc-securing-session-cookies-with-device-binding-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/chrome-dbsc-securing-session-cookies-with-device-binding-analysis</guid><description>Google introduces Device Bound Session Credentials in Chrome to combat session hijacking by cryptographically linking authentication cookies to local hardware.</description><pubDate>Fri, 10 Apr 2026 08:38:17 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Cookie Theft</category><category>Infostealer</category></item><item><title>Infinity Stealer macOS Malware: Analyzing ClickFix Lures and Payloads</title><link>https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</link><guid isPermaLink="true">https://runtimerebel.com/blog/infinity-stealer-macos-malware-analyzing-clickfix-lures-and-payloads</guid><description>Infinity Stealer targets macOS via ClickFix social engineering. Learn how this Nuitka-compiled malware steals browser data, crypto wallets, and Keychain info.</description><pubDate>Sat, 28 Mar 2026 16:13:39 GMT</pubDate><category>macOS</category><category>Infinity Stealer</category><category>Infostealer</category><category>Nuitka</category><category>ClickFix</category><category>Social Engineering</category></item><item><title>Backdoored Telnyx PyPI Package Uses Steganography to Deliver Malware</title><link>https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/backdoored-telnyx-pypi-package-uses-steganography-to-deliver-malware</guid><description>Security researchers discovered malicious versions of the Telnyx PyPI package delivering infostealers via steganography hidden in WAV audio files.</description><pubDate>Sat, 28 Mar 2026 00:36:31 GMT</pubDate><category>PyPI</category><category>Telnyx</category><category>Steganography</category><category>Infostealer</category><category>TeamPCP</category><category>Python Security</category></item><item><title>GitHub Malware Campaign: Fake VS Code Alerts Target Developers</title><link>https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</guid><description>Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.</description><pubDate>Fri, 27 Mar 2026 20:15:23 GMT</pubDate><category>GitHub</category><category>Visual Studio Code</category><category>Phishing</category><category>Malware</category><category>Infostealer</category><category>Developer Security</category></item></channel></rss>