⤷ Title: 108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
Daily CyberSecurity
108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
Socket identifies 108 malicious Chrome extensions stealing Telegram sessions and Google IDs. 20,000 installs hit—audit your browser extensions immediately!
⤷ Title: The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
Penetration Testing Tools
The Trojan Update: How "GlassWorm" Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
⤷ Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Daily CyberSecurity
The Sleeper in Your IDE: Unmasking the 73-Extension "GlassWorm" Espionage Campaign
Socket uncovers GlassWorm: a 73-extension sleeper campaign on Open VSX targeting VS Code and Cursor. Stealthy .node binaries turn trusted tools into malware.
⤷ Title: Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
Daily CyberSecurity
Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
Socket uncovers a BufferZoneCorp "sleeper" campaign targeting Ruby and Go. Malicious packages steal SSH keys and subvert CI/CD pipelines. Patch now!
⤷ Title: The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
Daily CyberSecurity
The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
Socket uncovers a massive Mini Shai-Hulud breach in the Intercom PHP SDK. Malicious version 5.0.2 steals cloud secrets and GitHub tokens. Rotate keys now!
⤷ Title: Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 01:37:03 +0000
════════════════════════
⌗ Tags: #Malware #@tanstack/react_router #CI/CD security #credential stealer #GitHub Actions #infosec #JavaScript Security #Malware Analysis #npm Security #Socket Threat Research #supply chain attack #TanStack
Daily CyberSecurity
Supply Chain Siege: 84 TanStack Packages Compromised to Steal GitHub Secrets
Urgent: 84 TanStack npm packages hijacked to harvest GitHub Actions secrets. Over 12M weekly downloads impacted. Audit your CI/CD pipelines and rotate tokens.
⤷ Title: GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 04:21:32 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #data exfiltration #GemStuffer #infosec #Malware Analysis #ModernGov #Ruby Security #RubyGems #Socket #supply chain attack #UK Council Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 04:21:32 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Security #data exfiltration #GemStuffer #infosec #Malware Analysis #ModernGov #Ruby Security #RubyGems #Socket #supply chain attack #UK Council Security
Daily CyberSecurity
GemStuffer: Attackers Weaponize RubyGems as a Covert Data Drop for UK Gov Scraping
GemStuffer exploits RubyGems as an illicit data transport to scrape UK council portals. Discover how this supply chain attack bypasses standard defenses.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.
⤷ Title: Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 09:01:53 +0000
════════════════════════
⌗ Tags: #Malware #DNS TXT backdoor #Go module #proxy.golang.org #rce #Remote Code Execution #shopspring/decimal #shopsprint/decimal #Socket Security #supply chain attack #typosquat
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 25 May 2026 09:01:53 +0000
════════════════════════
⌗ Tags: #Malware #DNS TXT backdoor #Go module #proxy.golang.org #rce #Remote Code Execution #shopspring/decimal #shopsprint/decimal #Socket Security #supply chain attack #typosquat
Daily CyberSecurity
Poisoned Code: Stealthy Malicious Go Module Backdoor Discovered in Long-Running Typosquat
Security researchers have exposed a malicious Go module backdoor hidden inside the shopsprint/decimal package that executes code using stealthy DNS TXT records.
⤷ Title: Sicoob SDK Banking Malware Exploits NuGet Developer Channels
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 08:12:31 +0000
════════════════════════
⌗ Tags: #Malware #Financial Cybercrime #NuGet Malware #Sicoob.Sdk #Socket Security #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 08:12:31 +0000
════════════════════════
⌗ Tags: #Malware #Financial Cybercrime #NuGet Malware #Sicoob.Sdk #Socket Security #supply chain attack
Daily CyberSecurity
Sicoob SDK Banking Malware Exploits NuGet Developer Channels
A dangerous Sicoob SDK banking malware campaign triggers a major NuGet supply chain attack. Learn how it exfiltrates private financial certificates.
⤷ Title: Malicious Chrome Extensions Exposed in Mass Production Traffic Fraud Scheme
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 02:34:42 +0000
════════════════════════
⌗ Tags: #Malware #adware #browser security #Chrome extensions #Socket #traffic fraud
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 13 Jun 2026 02:34:42 +0000
════════════════════════
⌗ Tags: #Malware #adware #browser security #Chrome extensions #Socket #traffic fraud
Daily CyberSecurity
Malicious Chrome Extensions Exposed in Mass Production Traffic Fraud Scheme
Discover how malicious Chrome extensions engage in traffic laundering while lying to users about collecting data on the official store.
⤷ Title: 152 Chrome Wallpaper Extensions Hid Ad Tracking
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:27:13 +0000
════════════════════════
⌗ Tags: #Malware #Ad Tracking #Browser Malware #Chrome extensions #Chrome Web Store #Live Wallpaper #Socket Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 03:27:13 +0000
════════════════════════
⌗ Tags: #Malware #Ad Tracking #Browser Malware #Chrome extensions #Chrome Web Store #Live Wallpaper #Socket Security
Information Security News
152 Chrome Wallpaper Extensions Hid Ad Tracking
Socket found 152 Chrome live wallpaper extensions secretly faking Google search traffic and harvesting user data for ad networks.
⤷ Title: Mastra Supply Chain Attack Compromises 140+ npm Packages
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 08:04:43 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Socket #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 08:04:43 +0000
════════════════════════
⌗ Tags: #Malware #easy_day_js #Infostealer #Mastra #npm #Socket #supply chain attack #Typosquatting
Daily CyberSecurity
Mastra Supply Chain Attack Compromises 140+ npm Packages
A Mastra supply chain attack compromised 140+ npm packages, using the typosquatted easy-day-js dependency to drop a crypto-stealing infostealer.
⤷ Title: 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 12:24:28 +0000
════════════════════════
⌗ Tags: #Security #Scams and Fraud #Chrome #Cybersecurity #Fraud #Google #google search #Malware #Scam #Socket #Wallpaper
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 12:24:28 +0000
════════════════════════
⌗ Tags: #Security #Scams and Fraud #Chrome #Cybersecurity #Fraud #Google #google search #Malware #Scam #Socket #Wallpaper
Hackread
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
Socket says the extensions worked as wallpaper tools, but also logged user data, disguised install traffic as Google clicks, and fed ad sites.
⤷ Title: North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
Daily CyberSecurity
North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
At a Glance Actor / group Suspected North Korean actors in the Contagious Interview / Famous Chollima cluster (Socket assessment) Activity type Open-source supply chain campaign; hidden JavaScript…
⤷ Title: Fake Braintree NuGet Package Skims Credit Cards and Steals Merchant API Keys
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 14:00:11 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #Braintree.Net #Credit Card Skimmer #DependencyInjector.Core #NuGet #Socket #supply chain attack #typosquat
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 14:00:11 +0000
════════════════════════
⌗ Tags: #Malware #.NET malware #Braintree.Net #Credit Card Skimmer #DependencyInjector.Core #NuGet #Socket #supply chain attack #typosquat
Daily CyberSecurity
Fake Braintree NuGet Package Skims Credit Cards and Steals Merchant API Keys
At a Glance Malware family Braintree.Net typosquat, a multi-stage .NET implant with a companion harvester (DependencyInjector.Core) Threat actor Unattributed; financially motivated (suspected) Tar…
⤷ Title: Malicious Go Module Exposes a 222-Repository GitHub Lure Network
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #GitHub lure network #malicious Go module #Operation Muck and Load #Socket #Software Supply Chain #Vidar Infostealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #GitHub lure network #malicious Go module #Operation Muck and Load #Socket #Software Supply Chain #Vidar Infostealer
Daily CyberSecurity
Malicious Go Module Exposes a 222-Repository GitHub Lure Network
Actor / group Unnamed actor tracked as “Operation Muck and Load”; overlaps with the ischhfd83 cluster Activity type Software supply-chain lures and Windows malware staging Targets / vi…
⤷ Title: npm Supply Chain Attack Delivers a Cross-Platform RAT to Alibaba Developers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 08:03:44 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Cross_Platform RAT #DingTalk #malicious npm packages #npm Supply Chain Attack #Socket #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 08:03:44 +0000
════════════════════════
⌗ Tags: #Malware #Alibaba #Cross_Platform RAT #DingTalk #malicious npm packages #npm Supply Chain Attack #Socket #Supply Chain Security
Daily CyberSecurity
npm Supply Chain Attack Delivers a Cross-Platform RAT to Alibaba Developers
At a glance Malware family Unnamed cross-platform RAT (final payload “aone-cli”) Threat actor Unattributed; suspected Chinese-speaking actor Target Developers at Alibaba Group units, i…