Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
September 17 technical disclosure explaining how a removed npm package waited for normal application calls before activating, ...
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by ...
Hackers used a malicious worker to inject scripts into more than 100,000 websites via the Brevo supply chain attack.
PROMPTFLUX uses AI to regenerate obfuscated malware code, creating 70+ variants in under four hours to evade detection.
Google found AI malware that can rewrite itself to evade detection as newer attacks show how quickly cyberthreats are ...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results