Malicious

Threat Actors Publish Malicious dYdX Packages to npm and PyPI Repositories

Cybersecurity firm Socket uncovered a supply chain attack where threat actors published malicious versions of dYdX client packages to npm and PyPI ecosystems. This...

New RecoverIt Tool Exploits Windows Service Recovery to Execute Malicious Payload

A new tool called RecoverIt gives red teamers a sneaky way to move sideways in networks and stay persistent. It abuses Windows' built-in service...

State-Sponsored Hackers Hijack Notepad++ Update Servers to Push Users to Malicious Sites

Notepad++, one of the world's most widely used text editors, fell victim to a sophisticated supply chain attack orchestrated by state-sponsored threat actors who...

Malicious Open VSX Extension with 5000+ Users Spreading Malware

A popular-looking extension  angular-studio.ng-angular-extension has been caught delivering sophisticated malware to developers. Masquerading as a legitimate "Angular Language Service," the extension provided actual IntelliSense and...

eScan Antivirus Update Server Breached to Distribute Malicious Update Packages

MicroWorld Technologies' eScan antivirus platform fell victim to a sophisticated supply chain attack on January 20, 2026, when threat actors compromised legitimate update infrastructure...

Popular

Subscribe