Credential Theft
-
Malicious npm packages found posing as PostCSS tools to deliver Windows RAT
Researchers found three malicious npm packages posing as PostCSS tools that delivered a Windows remote access trojan. The campaign used a multi-stage install chain to steal Chrome credentials, run commands and contact an external server.
-
Malicious JetBrains plugins stole AI provider keys, researchers say
Researchers say 15 JetBrains Marketplace plugins posed as AI assistants while stealing user API keys for services such as OpenAI and DeepSeek. The campaign has run since October 2025 and included two plugins with more than 25,000 downloads each.
-
Malicious PyPI packages tied to Hades attack wave, researchers say
Researchers said a new Hades supply chain campaign poisoned 37 wheel artifacts across 19 PyPI packages, using startup hooks to run Bun-based malware that sought cloud, repository and developer credentials.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
Fake LinkedIn emails abuse Adobe service in phishing campaign
A phishing campaign is using fake LinkedIn business emails and Adobe Target to hide credential theft, with attackers disguising HTML attachments as PDFs and redirecting victims to a real LinkedIn page after login.
-
TrapDoor supply chain attack spreads across npm, PyPI and Crates.io
A coordinated supply chain campaign has spread malicious packages across npm, PyPI and Crates.io, targeting developers with code that steals credentials, wallets, SSH keys and cloud secrets.
-
Malicious node-ipc versions found stealing cloud and developer secrets
Three malicious node-ipc npm versions were found stealing developer and cloud secrets, according to a technical analysis by Socket. The code targets dozens of credential types and uses a direct exfiltration path to a fake Azure domain.
-
New Linux PamDOORa backdoor sold on cybercrime forum, researchers say
Researchers disclosed PamDOORa, a Linux backdoor sold on a Russian cybercrime forum for up to $1,600. The PAM-based tool can provide persistent SSH access, harvest credentials and tamper with logs, though no real-world use has been seen.
-
PCPJack credential stealer targets cloud systems and removes TeamPCP traces
Researchers said PCPJack is a new cloud-focused credential stealer that targets exposed services, removes TeamPCP-related artifacts and uses multiple exploits to spread across compromised environments.
-
CloudZ malware used Phone Link to target Windows data, researchers say
Researchers said CloudZ malware used a Pheno plugin to abuse Windows Phone Link on Windows 10 and 11, aiming to steal credentials and one-time passwords in an intrusion active since at least January 2026.







