Advertisement
Axios npm Package Hijacked: Cross-Platform Malware Distribution
Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.
Apple Camera Indicator Design: Mitigating Covert Surveillance
Examines Apple's camera indicator light system, its robust hardware-software integration, and how it protects users from malware-enabled covert surveillance and

China-Linked APT Clusters Target SE Asian Government via HIUPAN
Three China-linked threat clusters targeted a Southeast Asian government in 2025 using HIUPAN, PUBLOAD, and EggStremeFuel malware in a complex espionage operation.
GitHub Malware Campaign: Fake VS Code Alerts Target Developers
Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.

npm Malware @openclaw-ai/openclawai: macOS Credential Theft Alert
Security alert for @openclaw-ai/openclawai, a malicious npm package targeting macOS users to deploy remote access trojans and steal sensitive credentials.

APT36 Leverages AI for Mass-Produced Malware: Overwhelming Defenses
APT36, a Pakistan-linked threat actor, is using AI 'vibe-coding' to generate malware at scale, posing a significant challenge to conventional defenses.
Arkanix Stealer: Rapid Disappearance of C++ & Python Malware
Arkanix Stealer, a C++ and Python-based info-stealer, emerged briefly, exfiltrating system data, browser credentials, and files before vanishing. Analysis of its TTPs.