FakeGit campaign returns with 17,610 GitHub repos pushing SmartLoader and StealC
Apiiro says the FakeGit operation re-aimed thousands of GitHub repositories, many posing as AI tools and MCP servers, to deliver SmartLoader and the StealC infostealer.
The latest cybersecurity news in Malware.
Apiiro says the FakeGit operation re-aimed thousands of GitHub repositories, many posing as AI tools and MCP servers, to deliver SmartLoader and the StealC infostealer.
Version 0.5.144 of the tensorlake npm package shipped a credential-stealing worm that can wipe a developer's home directory if the stolen GitHub token is revoked.
Lumen's Black Lotus Labs says the PoeLLM malware has compromised more than 3,400 servers, including LiteLLM and Ollama hosts, to mine cryptocurrency and spread further.
Checkmarx says a single actor has used npm packages since August 2023 to deliver Overlord RAT and a Node.js stealer; three packages were still live on October 1.
CERT-UA says a ClickFix campaign tracked as UAC-0277 compromised more than 100 Ukrainian websites to push Lunex, a stealer sold as malware-as-a-service.
Island researchers found fake AI product sites that lure advertising staff into a fake Google sign-in window, where a human operator harvests passwords and MFA codes in real time.
Microsoft Threat Intelligence says fake CAPTCHA pages now pre-load a script into the browser cache disguised as a PNG, sidestepping both download monitoring and the Windows Run dialog's character limit.
Group-IB says the Milk Dragon kit has produced 258 phishing pages hitting victims in 66 countries, using fake 3D Secure screens to capture one-time passcodes in real time.
FortiGuard Labs and Nozomi Networks describe a Linux botnet that disguises its command channel as replies from a Google STUN server and spreads through router and DVR flaws.
Rapid7 documented a new modular Linux implant called AVERAT alongside fresh BPFDoor variants, both abusing TCP port 25 to blend command-and-control traffic into ordinary mail flows.
Socket says four theme extensions on the VS Code Marketplace and Open VSX are tied to the GlassWorm campaign, two of them confirmed malicious and using a Solana blockchain dead drop for command and control.
Jamf Threat Labs says a new macOS backdoor, CloudSyncD, poses as a Zoom installer, tricks users into entering their password and uses it with sudo to run a persistent implant as root.