Related Threat Clusters
-
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
Bybit Suffers $1.46 Billion Loss in North Korean Hacking Incident
On February 21, 2025, Bybit experienced a significant security breach involving a routine transfer from an Ethereum cold wallet to a warm wallet. The attack, attributed to North Korea's Lazarus Group, exploited the user…
2 articles · Updated August 9, 2026 -
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
12 articles · Updated August 7, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
Malicious Joyfill npm Packages Distribute DEV#POPPER RAT and Credential Stealer
On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon…
5 articles · Updated July 29, 2026 -
New ViteVenom Malware Targets Developers with Blockchain C2 RAT
Checkmarx researchers have identified a cluster of seven malicious npm packages named ViteVenom, targeting the Vite frontend ecosystem. The campaign, attributed to the threat actor SuccessKey, builds on tactics from the…
3 articles · Updated July 20, 2026 -
Echo Protocol Exploit Results in $76M Loss Due to Compromised Admin Key
On May 19, 2026, Echo Protocol, a Bitcoin DeFi platform, suffered a significant exploit on the Monad blockchain, leading to the unauthorized minting of 1,000 eBTC valued at approximately $76 million. The breach was…
13 articles · Updated May 19, 2026 -
Aptos Fixes Critical Vulnerability with $70 Billion Risk Exposure
Aptos Labs patched a critical vulnerability in its Move virtual machine that could have exposed up to $70 billion in crypto assets. Discovered by Hexens in February 2026, the flaw allowed attackers to manipulate core…
25 articles · Updated July 5, 2026 -
Switchboard Network Services Suspended Amid Security Concerns
On August 30, 2026, the decentralized oracle Switchboard announced the suspension of its services on Aptos, Sui, Iota, and Movement due to reports of a potential compromise in its network implementation using the Move…
2 articles · Updated August 30, 2026 -
Aave Restructures Bug Bounty Program with Increased Rewards
On May 15, 2026, Aave Labs proposed a significant restructuring of its bug bounty program, dividing it into multiple independent programs managed by Immunefi, Sherlock, and Cantina. The maximum bounty for critical…
11 articles · Updated May 14, 2026
Recent Intelligence Reports
- Switchboard Network Services Suspended on Aptos, Sui, Iota, and Movement Due to ... — Kucoin · August 30, 2026
- June preprint — arxiv.org · August 10, 2026
- Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs — Decrypt.Co · August 7, 2026
- Two Joyfill npm Packages Found Delivering DEV#POPPER Malware — Thecyberexpress · July 29, 2026
- New npm malware cluster targets Vite ecosystem | brief — Scworld · July 20, 2026
- Chaincatcher — www.chaincatcher.com · July 5, 2026
- Aptos Blockchain Discloses Critical Vulnerability That Could Have Exposed $700 Billion in Assets — Kucoin · July 5, 2026
- Hexens Reveals Aptos Fixed a Critical Vulnerability with Theoretical Exposure of Up to $70 Billion — Kucoin · July 5, 2026