Microsoft spots XCSSET macOS malware variant used for crypto theftA new variant of the XCSSET macOS modular malware has emerged in attacks that target users' sensitive information, including digital wallets and data from the legitimate Notes app.#bleepingcomputer#EN#2025#Apple#Malware#Supply-Chain-Attack#Xcode#XCSSET#Security·bleepingcomputer.com·Feb 18, 2025Microsoft spots XCSSET macOS malware variant used for crypto theft
Supply Chain Attack on Rspack npm Packages Injects Cryptojac...A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.#socket.dev#EN#2024#Supply-Chain-Attack#Rspack#malware#npm·socket.dev·Dec 20, 2024Supply Chain Attack on Rspack npm Packages Injects Cryptojac...
Info Stealing Packages Hidden in PyPIAn info-stealing PyPI malware author was identified discreetly uploading malicious packages.#FortiGuard-Labs-Threat-Research#fortinet#2024#EN#PyPI#malware#Supply-chain-attack·fortinet.com·Jan 23, 2024Info Stealing Packages Hidden in PyPI
Trojanized Free Download Manager found to contain a Linux backdoorKaspersky researchers analyzed a Linux backdoor disguised as Free Download Manager software that remained under the radar for at least three years.#securelist#EN#2023#Backdoor#Linux#Malware#Supply-chain-attack#Download-Manager·securelist.com·Sep 14, 2023Trojanized Free Download Manager found to contain a Linux backdoor
PyPI Attackers Still At It: Malicious Packages Drop Trojans and Info-stealersSonatype's malicious open source and malware detection systems found hundreds of malicious PyPI packages.#sonatype#EN#2023#PyPI#malware#Supply-Chain-Attack·blog.sonatype.com·Jun 23, 2023PyPI Attackers Still At It: Malicious Packages Drop Trojans and Info-stealers