Related Threat Clusters
-
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
36 Malicious Strapi npm Packages Deliver Redis RCE and C2 Malware
A coordinated supply chain attack has been discovered involving 36 malicious npm packages that impersonate Strapi CMS plugins. These packages were published to the npm registry and are designed to exploit Redis for…
2 articles · Updated April 6, 2026 -
GitLab 2FA Bypass Vulnerability Patched
GitLab has patched a critical two-factor authentication bypass vulnerability, tracked as CVE-2026-0723, affecting both Community and Enterprise editions of its application development platform. The flaw allows attackers…
3 articles · Updated January 21, 2026 -
GoPlus Alerts on 26 Malware Packages from North Korean Hackers
GoPlus has issued a warning regarding 26 malware packages released by North Korean hackers on the npm registry. These packages include an installation script that executes malicious code, which downloads and runs a…
3 articles · Updated March 3, 2026 -
Malware Campaigns Target U.S. Manufacturing and Healthcare via DNS Poisoning
APT group Evasive Panda is using DNS poisoning to deliver MgBot malware, targeting U.S. and allied manufacturing and healthcare organizations. Additionally, a spearphishing campaign is exploiting the npm registry to…
2 articles · Updated January 4, 2026 -
Malicious npm Packages Target Developers to Steal Credentials
Three malicious npm packages, bitcoin-main-lib, bitcoin-lib-js, and bip40, have been uploaded to the public npm registry, targeting JavaScript developers to steal sensitive data such as browser logins, API keys, and…
3 articles · Updated January 8, 2026 -
PhantomRaven Malware Campaign Targets npm Packages
A malware campaign named PhantomRaven has been active since August 2025, compromising 126 npm packages and stealing developer credentials, including npm tokens and GitHub credentials. Researchers at Koi Security…
8 articles · Updated November 15, 2025 -
Trust Wallet Users Lose $8.5 Million in Shai-Hulud Supply Chain Attack
Trust Wallet reported that approximately $8.5 million in cryptocurrency was stolen from over 2,500 users due to a cyberattack linked to the Shai-Hulud npm supply chain attack. The attackers accessed Trust Wallet’s…
6 articles · Updated January 2, 2026 -
Over 150,000 Malicious npm Packages Flood Registry in Token Farming Attack
A coordinated token farming campaign has resulted in over 150,000 malicious packages flooding the npm registry, targeting the tea.xyz protocol. Discovered by Amazon Inspector researchers, this incident is described as…
5 articles · Updated November 15, 2025 -
PhantomRaven Malware Targets npm with 126 Credential-Stealing Packages
Researchers at Koi Security discovered a malware campaign named PhantomRaven that has been active since August 2025, compromising 126 npm packages. The malicious packages have been downloaded over 86,000 times and are…
4 articles · Updated October 31, 2025
Recent Intelligence Reports
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026
- 36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware — Cybersecuritynews · April 6, 2026
- GoPlus Warns of 26 Malware Packages by North Korean Hackers — Phemex · March 3, 2026
- GoPlus: Beware of 26 malware packages released by North Korean hackers that can ... — Panewslab · March 3, 2026
- GitLab 2FA login protection bypass lets attackers take over accounts — Csoonline · January 21, 2026
- Three Malicious NPM Packages Attacking Developers to Steal Login Credentials — Cybersecuritynews · January 8, 2026
- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 78 — Securityaffairs.Co · January 4, 2026
- Trust Wallet links $8.5 million crypto theft to Shai — Bleepingcomputer · January 2, 2026