⤷ Title: GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
Penetration Testing Tools
GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
GuardDog is a CLI tool that uses heuristics and Semgrep rules to scan for malicious npm, PyPI, Go, and VSCode packages, helping to secure the software supply chain.
⤷ Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
Daily CyberSecurity
Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
The malicious PyPI package SoopSocks masqueraded as a SOCKS5 proxy but secretly installed a Go-based backdoor with SYSTEM privileges, leaking system data to a Discord webhook.
⤷ Title: Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
Daily CyberSecurity
Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
Malicious packages across npm, PyPI, and RubyGems are exploiting Discord webhooks as stealthy, resilient C2 endpoints to exfiltrate developer config files and sensitive host data.
⤷ Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Daily CyberSecurity
PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
A malicious PyPI typosquat (spellcheckers) infected 950+ users. The package deploys an XOR-encrypted Python RAT via a hidden index file, granting full remote execution (exec()) and is linked to crypto scams.
⤷ Title: Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
Daily CyberSecurity
Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
Critical dYdX supply chain attack: Compromised npm & PyPI packages steal seed phrases & deploy RATs. Remove @dydxprotocol/v4-client-js immediately.
⤷ Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
Penetration Testing Tools
Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
Security analysts at Socket have unmasked a surgical supply chain incursion targeting the libraries associated with the dYdX
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Daily CyberSecurity
The 1,700-Package Blitz: North Korea’s "Contagious Interview" Infiltrates Every Major Dev Registry
North Korea’s "Contagious Interview" campaign expands to 1,700+ malicious packages across npm, PyPI, and more. Learn how to protect your dev environment.
⤷ Title: Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:13:16 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Azure #Cloud Security #Credential Theft #GCP #Kubernetes #MLOps Security #PyPI #Python Security #supply chain attack #TeamPCP #Xinference
Daily CyberSecurity
Supply Chain Alert: TeamPCP Strikes Popular AI Framework Xinference
Critical supply chain attack hits Xinference (v2.6.0-2.6.2). TeamPCP’s malware siphons cloud credentials and MLOps secrets. Audit your MLOps pipeline today.
⤷ Title: The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular “Elementary-Data” Library
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:30:10 +0000
════════════════════════
⌗ Tags: #Malware #2026 Tech News #cloud security #Credential Stealer #Data Engineering #dbt #Docker #Elementary_data #GitHub Actions #GITHUB_TOKEN #PyPI #Python Security #supply chain attack
Penetration Testing Tools
The Poisoned Pipeline: How a GitHub Actions Flaw Infiltrated the Popular "Elementary-Data" Library
The ubiquitous Python library elementary-data has emerged as a conduit for the exfiltration of sensitive developer telemetry. The
⤷ Title: AI’s Supply Chain Nightmare: The Lightning Framework Worm and the “Silence Developer” Meme
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:10:13 +0000
════════════════════════
⌗ Tags: #Malware #AI security #Cloud Secrets #cyber_espionage #GitHub Compromise #infosec #LAPSUS$ #Lightning AI #malware #PyPI Security #supply chain attack #TEAM PCP
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:10:13 +0000
════════════════════════
⌗ Tags: #Malware #AI security #Cloud Secrets #cyber_espionage #GitHub Compromise #infosec #LAPSUS$ #Lightning AI #malware #PyPI Security #supply chain attack #TEAM PCP
Daily CyberSecurity
AI's Supply Chain Nightmare: The Lightning Framework Worm and the "Silence Developer" Meme
Lightning framework v2.6.2 & 2.6.3 are malicious. The "TEAM PCP" worm steals cloud secrets and poisons repos. Downgrade to 2.6.1 and rotate keys immediately!
⤷ Title: New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
⌗ Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 08:11:06 +0000
════════════════════════
⌗ Tags: #Malware #AWS Credentials #DevOps Security #eBPF Rootkit #Fileless Malware #infosec #Linux RAT #npm Security #PyPI #QLNX #Quasar Linux #supply chain attack #Trend Micro
Daily CyberSecurity
New Quasar Linux (QLNX) RAT Hijacks Cloud Keys and NPM Tokens
Trend Micro uncovers QLNX, a fileless Linux RAT targeting AWS, NPM, and Kubernetes keys. Learn how its eBPF rootkit hides from even the deepest system scans.
⤷ Title: OceanLotus Hijacks PyPI to Deploy “ZiChatBot” via Enterprise Chat APIs
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 07 May 2026 09:00:27 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #cybersecurity #infosec #kaspersky #malware #OceanLotus #PyPI #Python Security #Shared Libraries #supply chain attack #ZiChatBot #Zulip API
Daily CyberSecurity
OceanLotus Hijacks PyPI to Deploy "ZiChatBot" via Enterprise Chat APIs
OceanLotus targets Python developers worldwide via PyPI supply chain attacks. New ZiChatBot malware hijacks Zulip APIs for invisible C2 traffic. Patch now!
⤷ Title: Google Says Hackers Used AI to Develop a Zero-Day Exploit
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Mon, 11 May 2026 22:00:41 +0000
════════════════════════
⌗ Tags: #Security #Artificial Intelligence #0day #AI #Android #backdoor #Cyber Attack #Cybersecurity #GitHub #Google #Malware #PyPI #Vulnerability
Hackread
Google Says Hackers Used AI to Develop a Zero-Day Exploit
Google researchers say hackers used AI to develop zero-day exploits, Android backdoors, and automated supply chain attacks targeting GitHub and PyPI.
⤷ Title: TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 13 May 2026 15:18:47 +0000
════════════════════════
⌗ Tags: #Security #Malware #Cyber Attack #Mini Shai_Hulud #NPM #PyPI #Supply Chain #TeamPCP
Hackread
TeamPCP Used Mini Shai-Hulud Worm to Poison Over 400 npm and PyPI Packages
TeamPCP hijacked OIDC tokens to poison hundreds of TanStack, Mistral AI, and UiPath packages with the self-propagating Mini Shai-Hulud worm.
⤷ Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
Hackread
TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack
TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems.
⤷ Title: Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 14 May 2026 08:12:28 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack #GitHub Actions #InfoSec 2026 #Mini Shai_Hulud #npm security #OIDC #PyPI malware #supply chain attack #tanstack_runner.js #TeamPCP #Trusted Publishing
Penetration Testing Tools
Mini Shai-Hulud Alert: TeamPCP Hijacks @tanstack and PyPI to Poison 12 Million Weekly Downloads
The Mini Shai-Hulud incursion has once again laid siege to the software supply chain. While the initial offensive
⤷ Title: TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack (Updated)
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 14 May 2026 00:37:05 +0000
════════════════════════
⌗ Tags: #Data Breaches #Security #AI #Cyber Attack #Cyber Crime #Cybersecurity #Mistral AI #NPM #PyPI #Supply Chain #TeamPCP
Hackread
TeamPCP Claims Sale of Mistral AI Repositories Amid Mini Shai-Hulud Attack (Updated)
TeamPCP claims to be selling alleged Mistral AI repositories on a hacker forum after the Mini Shai-Hulud attack targeted npm and PyPI ecosystems.
⤷ Title: Dependabot and PyPI Add Supply Chain Cooldowns
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 06:34:12 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Dependabot #Github #PyPI #Supply Chain Security
Information Security News
Dependabot and PyPI Add Supply Chain Cooldowns
GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. D…
⤷ Title: Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 20:01:51 +0000
════════════════════════
⌗ Tags: #Data Breaches #Artificial Intelligence #Hacking News #Security #Anthropic #Claude #Claude Mythos 5 #Claude Opus 4.7 #Cyber Attack #Cybersecurity #hacking #Hugging Face #Mythos #OpenAI #PyPI #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 20:01:51 +0000
════════════════════════
⌗ Tags: #Data Breaches #Artificial Intelligence #Hacking News #Security #Anthropic #Claude #Claude Mythos 5 #Claude Opus 4.7 #Cyber Attack #Cybersecurity #hacking #Hugging Face #Mythos #OpenAI #PyPI #Vulnerability
Hackread
Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.