zsh - Tool

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 11, 2025
Last Seen
August 19, 2026

Zsh (the Z Shell) is a widely used Unix shell that provides advanced features for command interpretation, scripting, and interactive use.

Overview

Zsh (the Z Shell) is a widely used Unix shell that provides advanced features for command interpretation, scripting, and interactive use. In threat intelligence, it is typically a legitimate tool rather than an attack framework, though shell environments can be leveraged in certain post-exploitation or scripting contexts. The supplied article does not mention zsh directly; it reports phishing links in Polymarket’s private markets, illustrating phishing as an active threat vector in crypto/private-market environments.

Related Threat Clusters

  • North Korean Hackers Target Open Source Software Supply Chain via npm Packages

    Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…

    11 articles · Updated July 29, 2026
  • MacSync Infostealer Exploits Google Search for Claude Installation

    A malvertising campaign has emerged, using Google search results for Claude installation to deliver a macOS infostealer named MacSync. Victims are misled to a legitimate claude.ai shared conversation page, where they…

    2 articles · Updated August 19, 2026
  • CrowdStrike Enhances AI Security for Endpoints Amid Rising Threats

    CrowdStrike announced new AI security features at RSA 2026, focusing on endpoint protection as AI applications proliferate. The Falcon platform now includes EDR AI Runtime Protection, which monitors commands and…

    104 articles · Updated March 25, 2026
  • Microsoft Identifies Over 30 Domains Linked to MacSync Stealer Malware

    Microsoft has linked more than 30 rotating domains to the MacSync Stealer, a malware targeting macOS systems. This infrastructure supports various malicious activities, including credential theft and data exfiltration.…

    4 articles · Updated August 19, 2026
  • Tirith Tool Launches to Combat Homoglyph Attacks in Command Line

    The open-source tool Tirith has been launched to detect homoglyph attacks in command-line environments. By analyzing URLs in typed commands, it prevents execution of deceptive commands that use similar-looking…

    2 articles · Updated February 10, 2026
  • Polymarket Users Lose $500,000 in Phishing Attack

    Polymarket has experienced a significant phishing attack that has resulted in users losing over $500,000. The attack exploited vulnerabilities within the platform's section, affecting individual investors and…

    2 articles · Updated November 11, 2025
  • Polymarket Faces Security Breach Amid Phishing Attack

    Polymarket has experienced a significant security breach due to a phishing attack, resulting in users losing over $500,000. The attack has raised alarms among traders, particularly as the platform prepares to re-enter…

    2 articles · Updated November 11, 2025

Recent Intelligence Reports

  • Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data — Gbhackers · August 19, 2026
  • MacSync Stealer: How a Google Search for Claude Led to a macOS Infostealer — Huntress · August 17, 2026
  • Sapphire Sleet — cloud.google.com · August 4, 2026
  • Tirith tool detects homoglyph attacks in command line — Scworld · February 10, 2026
  • Polymarket users sound alarm over phishing links in private markets — Cryptorank · November 11, 2025

CVSS v3.1 Breakdown