Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
800 Malicious npm Packages Delivering Cross-Platform RAT and Infostealer: Supply Chain Detection and Remediation Guide
A Supply Chain Shotgun Blast: 800 Malicious npm Packages in One Campaign OpenSourceMalware researcher Paul has disclosed a cluster of nearly...
npm Supply Chain Compromise: keyv & cacheable Packages Poisoned with Ethereum C2 Credential Stealer — OTX Pulse Analysis
npm Supply Chain Compromise: keyv & cacheable Packages Poisoned with Ethereum C2 Credential Stealer Threat Summary AlienVault OTX pulse data...
NullReceiver EtherHiding Attack: Trojanized npm Packages bianira-ui and fluid-type-ui Hide C2 IPs in Empty Ethereum Transfers — Detection and Removal Guide
Introduction Security researchers have identified an evolution of the EtherHiding command-and-control technique — now codenamed NullReceiver...
Powercat Java Stealer via Fake Xeno Roblox Cheats + keyv/cacheable npm Supply Chain Compromise: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Two concurrent OTX pulses published on 2026-08-05 reveal a broad infostealer and credential-theft wave hitting both consumer ...
The Gentlemen's EtherRAT & Shai-Hulud npm Supply Chain: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Intelligence indicates two concurrent high-severity campaigns targeting enterprise environments. The Gentlemen ransomware aff...
RMM Exploitation & Supply Chain Worms: TaskWeaver, Djinn Stealer, and npm Attacks
Threat Intelligence Briefing Threat Summary Current OTX pulse data indicates a surge in credential theft campaigns utilizing diverse entry v...
Bumblebee, npm Supply Chain, and ClickFix: OTX Pulse Analysis — Credential Theft & Akira Ransomware
Threat Intelligence Briefing: Multi-Vector Credential Theft & Ransomware Delivery Threat Summary OTX Pulse data from 2026-07-29 indicates a ...
ViteVenom Supply Chain Attack: Detecting Blockchain C2 in Malicious npm Packages
Introduction A sophisticated software supply chain attack, codenamed ViteVenom, has been uncovered targeting the Vite frontend tooling ecosy...
Injective Labs GitHub Compromise: Detecting and Blocking Malicious npm Packages Targeting Crypto Wallets
Recently, the GitHub account of Injective Labs was compromised, leading to the publication of malicious npm packages designed to steal crypt...