#supply-chain-malware

[ follow ]
#glassworm
fromInfoWorld
1 week ago
Information security

How GlassWorm wormed its way back into developers' code - and what it says about open source security

GlassWorm reinfects VS Code extensions and GitHub repos using invisible Unicode and blockchain C2, spreading globally and threatening developers, enterprises, and critical infrastructure.
fromTechzine Global
3 weeks ago
Information security

Invisible malware spreads via VS Code extensions

GlassWorm is a worm that spreads through infected VS Code extensions using invisible Unicode characters, leverages Solana transactions for command-and-control, and deploys a remote access trojan.
fromInfoWorld
1 week ago
Information security

How GlassWorm wormed its way back into developers' code - and what it says about open source security

Information security
fromThe Hacker News
1 month ago

North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

North Korea-linked actors use multi-platform malware including AkdoorTea to target cryptocurrency and Web3 developers via fake recruiter job offers that install backdoors.
fromInfoWorld
1 month ago

QR codes become the vehicle for malware in new technique

The malicious package, fezbox, is disguised as a utility library and has "layers of obfuscation" including the "innovative, steganographic use" of QR codes. Steganography involves embedding secret data into a cover medium so that it goes undetected. "Steganography is the practice of hiding a secret file in plain sight, something for which QR codes are great," wrote Socket researcher Olivia Brown.
Information security
fromThe Hacker News
2 months ago

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers

"SilentSync is capable of remote command execution, file exfiltration, and screen capturing," Zscaler ThreatLabz's Manisha Ramcharan Prajapati and Satyam Singh said. "SilentSync also extracts web browser data, including credentials, history, autofill data, and cookies from web browsers like Chrome, Brave, Edge, and Firefox." The packages, now no longer available for download from PyPI, are listed below. They were both uploaded by a user named "CondeTGAPIS."
Information security
[ Load more ]