Skip to main content
← All Articles

Tag

#Malware

105 articles

Advertisement

HIGH
Supply Chain

Jscrambler NPM Packages Poisoned in Supply Chain Attack

Attackers poisoned official Jscrambler NPM packages to distribute cross-platform credential stealers. Learn the impact and how to remediate the threat.

Runtime Rebel Intel
4 min read · Jul 14, 2026
HIGH
Supply Chain

Jscrambler npm Package Backdoored with Infostealer Malware

A malicious version of the Jscrambler npm package, 5.0.0-beta-1, was backdoored with infostealer malware, affecting 1,500 downloads. Immediate action needed.

Runtime Rebel Intel
4 min read · Jul 13, 2026
ModHeader Extension Pulled Over Dormant Browsing Data Collector
MEDIUM
Supply Chain

ModHeader Extension Pulled Over Dormant Browsing Data Collector

ModHeader, a popular browser extension with 1.6M installs on Chrome and Edge, was pulled by Google and Microsoft after a dormant browsing history collector was found.

Runtime Rebel Intel
4 min read · Jul 13, 2026
HIGH
Supply Chain

Injective SDK npm Compromise: Crypto Wallet Stealer Detected

A malicious version of the Injective SDK (injective-js) on npm was published via a GitHub compromise, deploying a crypto wallet stealer. Developers are at risk.

Runtime Rebel Intel
4 min read · Jul 10, 2026
HIGH
Supply Chain

Fake Paysafe/Skrill SDKs on npm & PyPI Steal Credentials

Malicious packages impersonating Paysafe and Skrill SDKs on npm and PyPI platforms are stealing credentials from developers and users. Threat intelligence analysis.

Runtime Rebel Intel
4 min read · Jul 8, 2026
HalluSquatting: AI Coding Assistants Tricked into Botnet Malware
HIGH
Threat Intel

HalluSquatting: AI Coding Assistants Tricked into Botnet Malware

New HalluSquatting research reveals how attackers can register fake project names hallucinated by AI coding assistants to deploy botnet malware onto developer systems.

Runtime Rebel Intel
5 min read · Jul 8, 2026

Advertisement

HIGH
Threat Intel

EtherRAT Malware via Microsoft Teams IT Support Impersonation

Threat actors leverage fake IT support calls on Microsoft Teams to deploy EtherRAT malware, gaining initial access to corporate networks.

Runtime Rebel Intel
5 min read · Jul 6, 2026
MEDIUM
Threat Intel

Google Disrupts NetNut Malicious Residential Proxy Network

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.

Runtime Rebel Intel
4 min read · Jul 3, 2026
ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
HIGH
Malware

ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse

Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.

Runtime Rebel Intel
5 min read · Jul 2, 2026
Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets
MEDIUM
Malware

Silent Swap Crypto Clipper: Fake Google Notes Ext Steals Wallets

Analysis of Silent Swap crypto clipper campaign using a fake Google Notes extension to surreptitiously replace cryptocurrency wallet addresses during transactions.

Runtime Rebel Intel
5 min read · Jun 30, 2026
CRITICAL
Vulnerabilities

Critical SimpleHelp Vulnerability Exploited for Malware Delivery

A critical vulnerability in SimpleHelp is actively exploited to deploy malware, targeting credentials, SSH keys, and crypto wallets. Immediate patching is essential.

Runtime Rebel Intel
4 min read · Jun 30, 2026
HIGH
Threat Intel

Turla APT Deploys StockStay Backdoor in Ukraine Espionage Campaign

Russian APT Turla targets Ukrainian government and military entities with the custom StockStay backdoor for persistent access and cyber espionage.

Runtime Rebel Intel
4 min read · Jun 26, 2026
Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen
HIGH
Malware

Amadey & StealC Malware Infrastructure Disrupted, 27M Credentials Stolen

Law enforcement and private sector dismantled infrastructure for Amadey and StealC malware, leading to 27M stolen credentials recovery. Learn impact & defense.

Runtime Rebel Intel
5 min read · Jun 24, 2026
HIGH
Malware

Amadey & StealC Malware C2 Infrastructure Disrupted

Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
HIGH
Malware

Amadey & StealC Malware Operations Disrupted by Operation Endgame

Operation Endgame, led by Europol and Microsoft, has disrupted infrastructure supporting Amadey and StealC info-stealer malware, impacting cybercriminal services.

Runtime Rebel Intel
5 min read · Jun 24, 2026
MEDIUM
Malware

Gentlemen Ransomware: EDR Evasion Tactics and Mitigation Strategies

Runtime Rebel details Gentlemen ransomware's advanced EDR killer suite, analyzing its impact and providing actionable strategies to defend against sophisticated evasion.

Runtime Rebel Intel
4 min read · Jun 19, 2026
HIGH
Malware

Infostealers: Millions of Devices Compromised for Credential Theft

Infostealers are increasingly enabling ransomware and cybercrime operations by compromising millions of devices to harvest credentials and sensitive data.

Runtime Rebel Intel
4 min read · Jun 11, 2026
HIGH
Supply Chain

Shai-Hulud Attack: Trojanized PyPI Packages Steal Developer Secrets

New Shai-Hulud supply chain attack compromises 19 science-focused PyPI packages, distributing malware to steal developer credentials and secrets.

Runtime Rebel Intel
4 min read · Jun 8, 2026
npm Supply Chain Attack: IronWorm and Miasma Malware Analysis
HIGH
Supply Chain

npm Supply Chain Attack: IronWorm and Miasma Malware Analysis

Threat actors target npm developers with the IronWorm info stealer and Miasma worm, utilizing eBPF rootkits to exfiltrate secrets and ensure persistence.

Runtime Rebel Intel
3 min read · Jun 5, 2026
HIGH
Supply Chain

Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain

Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.

Runtime Rebel Intel
4 min read · Jun 5, 2026
HIGH
Malware

ChatGPT Share Link Abuse: Fake Outages Deliver Malware

Threat actors leverage ChatGPT share links to host deceptive outage pages, prompting users to download malware disguised as an official desktop app.

Runtime Rebel Intel
4 min read · May 29, 2026
FortiClient EMS Critical Flaw Exploited for Credential Stealing
CRITICAL
Vulnerabilities

FortiClient EMS Critical Flaw Exploited for Credential Stealing

Threat actors are actively exploiting a critical, patched FortiClient EMS vulnerability to deploy credential-stealing malware, bypassing trusted endpoint security.

Runtime Rebel Intel
5 min read · May 28, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Supply Chain

PyPI Supply Chain Threat: Deceptive Packages Target Developers

Analysis of malicious Python packages such as cryptography-util using deceptive naming to exfiltrate Discord tokens and system metadata via webhooks.

Runtime Rebel Intel
3 min read · May 11, 2026