18 May PhantomBot: A Typosquat Campaign That Pivoted From Credential Theft to a Turnkey Botnet Kit
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident....
An npm dependency confusion attack used eight malicious packages to fingerprint hosts and send RCE telemetry to Telegram....
A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files....
FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking....
DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust....
Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption....
LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them....
Explore the security breach of LiteLLM, affecting millions of users with multi-stage payloads and devastating consequences....
Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption....
Malicious npm package abuses a Baileys fork to inject runtime spam behavior through a GitHub-controlled payload....
allintext:login filetype:log exposes public log files with credentials and tokens. Learn how to stop log-based data leaks....