On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages ...
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack ...
Valentić told The Hacker News that the use of fake progress indicators mimicking legitimate installation progress and the ...
North Korean hackers published backdoored versions of the Axios NPM package using a compromised long-lived access token.
Attackers stole a long-lived npm token from the lead axios maintainer and published two poisoned versions that drop a ...
Hackers infiltrated Axios maintainers using fake Slack channels and Teams calls, then published infected packages.
Microsoft warns of a WhatsApp based malware attack targeting billions of users through fake files and social engineering ...
The activity begins with the attackers distributing malicious VBS files via WhatsApp messages that, when executed, create ...
We found fake “verify you are human” pages on hacked WordPress sites that trick Windows users into installing the Vidar infostealer.
The attack chain relies on delayed execution, trusted Windows utilities, and legitimate hosting services to maintain ...
Developers using the axios package from npm may have downloaded a malicous version that drops a Remote Access Trojan ...
5don MSN
Latest malware scam weaponizes ‘I’m not a robot’ verification tests against users, experts warn
There’s a new scam to look out for in a place you wouldn’t expect. Security experts at the Identity Theft Resource Center ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results