Skip to main content
← All Articles

Tag

#malware

19 articles

Advertisement

Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
HIGH
Malware

Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets

Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.

Runtime Rebel Intel
5 min read·Jun 30, 2026
MA
HIGH
Malware

Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies

Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.

Runtime Rebel Intel
4 min read·Jun 19, 2026
MA
HIGH
Malware

Infostealers: Millions of Devices Compromised for Credential Theft

Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.

Runtime Rebel Intel
4 min read·Jun 11, 2026
MA
HIGH
Malware

ChatGPT Share Link Abuse: Fake Outages Deliver Malware

Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.

Runtime Rebel Intel
4 min read·May 29, 2026
SU
HIGH
Supply Chain

PyPI Supply Chain Threat: Deceptive Packages Target Developers

Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.

Runtime Rebel Intel
3 min read·May 11, 2026
MA
HIGH
Malware

PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access

New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.

Runtime Rebel Intel
4 min read·May 7, 2026
SU
HIGH
Supply Chain

Backdoored PyTorch Lightning Package Drops Credential Stealer

A malicious PyTorch Lightning package on PyPI delivers a credential stealer, targeting browser data, environment variables, and cloud service credentials. Urgent action

Runtime Rebel Intel
4 min read·May 4, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
CRITICAL
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
3 min read·Apr 29, 2026
Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified
CRITICAL
Supply Chain

Bitwarden CLI Supply Chain Attack: Malicious NPM Package Identified

Researchers have discovered a malicious payload in version 2026.4.0 of the Bitwarden CLI, targeting sensitive vault credentials in build environments.

Runtime Rebel Intel
3 min read·Apr 23, 2026
CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft
HIGH
Supply Chain

CanisterSprawl Worm: npm Package Supply Chain Hijack & Token Theft

New CanisterSprawl worm compromises npm packages, propagates by stealing developer tokens via an ICP canister. Threatens software supply chain integrity.

Runtime Rebel Intel
4 min read·Apr 22, 2026
MA
HIGH
Malware

Malicious Crypto Apps on Apple App Store Target Private Keys

Dozens of fake cryptocurrency wallet applications have been found in the Apple App Store, designed to phish users' recovery phrases and private keys, leading to

Runtime Rebel Intel
5 min read·Apr 21, 2026
MA
HIGH
Malware

Malicious Crypto Wallets Infiltrate China's Apple App Store

26 fake cryptocurrency wallet apps infiltrated China's Apple App Store, impersonating popular brands to steal seed phrases and drain user funds.

Runtime Rebel Intel
4 min read·Apr 21, 2026