Scworld Domain Resurrection Attacks Target Linux Users via Snap Store
Article Content
Browse articles
Cybercriminals are exploiting expired web domains to hijack developer accounts and publish malware on the Canonical Snap Store, affecting Linux users. This technique, known as domain resurrection attacks, has already led to the compromise of at least two developer accounts, allowing the distribution of crypto-stealing malware through fake cryptocurrency wallet apps.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
More articles in this cluster (4)
Following this threat?
Track Shai-hulud in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Tensorlake npm Package Compromised by Shai-Hulud Worm On October 8, 2026, the Tensorlake npm package version 0.5.144 was compromised, delivering a credential-stealing worm known as Shai-Hulud. The malware, which was published through a compromised maintainer account, executes a preinstall hook that runs an obfuscated loader to harvest credentials from local files and CI…
Rise of Malicious npm Packages Threatens Developer Trust As of Q2 2026, Sonatype Research logged 1.8 million malicious packages, with npm accounting for 96.6% of this total. The quarter saw a surge in repository abuse, trojan-class malware, and maintainer compromises, indicating a shift towards targeting trusted developer workflows. ReversingLabs reported a specific…