Related Threat Clusters
-
Supply Chain Attack Compromises Laravel Lang Packages with Credential Stealer
On May 22, 2026, a supply chain attack targeted Laravel Lang localization packages, compromising 233 versions across four repositories. Attackers exploited GitHub's version tagging system to redirect legitimate tags to…
17 articles · Updated May 23, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
New Crypto Clipper Malware Uses USB and Tor for Stealthy Attacks
Microsoft has identified a new cryptocurrency-stealing malware named Crypto Clipper, active since February 2026. This malware spreads primarily through malicious Windows shortcut files (.lnk) on USB drives, targeting…
28 articles · Updated June 18, 2026 -
Gootloader Malware Evades Detection with Malformed ZIP Archives
Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…
5 articles · Updated January 16, 2026
Recent Intelligence Reports
- Microsoft Warns of New Crypto Clipper Malware That Acts Like a Worm — Coinedition · June 18, 2026
- Laravel Lang Supply Chain Advisory — Snyk · May 23, 2026
- axios was compromised on npm with ~100 million weekly downloads — Reddit · March 31, 2026
- How Gootloader uses malformed ZIP archives to evade detection — Scmagazine · January 16, 2026