Malicious npm package indexed-btree hid its loader in runtime code, avoiding install hooks after logging millions of downloads.
A malicious npm package reached over 2 million weekly downloads by hiding its payload in a routine library function rather than an install script.
Worker move goods for despatch in a redistribution centre of US online retail giant Amazon in Horn-Bad Meinberg, western Germany, on December 9, 2024. INA FASSBENDER/AFP via Getty Images Cloudflare's ...
AdBlock blocks known crypto miners by default, but c/side found 3,500+ sites running stealth WebSocket miners in 2025. What each extension still misses.
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency services.
A new ClickFix malware-as-a-service (MaaS) framework called Exvicy has been built on code lifted from a rival service, ErrTraffic.
A ClickFix campaign has shifted from tricking users into running commands on their computers to persuading them to inject ...
A few days ago I saw a screenshot on X of someone talking to what looks like a McDonald's support chatbot.They wanted to ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results