⤷ Title: Network traffic analysis: Koi Loader/Stealer
════════════════════════
𐀪 Author: Pavol Kluka
════════════════════════
ⴵ Time: Tue, 28 Jan 2025 19:33:16 GMT
════════════════════════
⌗ Tags: #koi_loader #malware #koi_stealer #cybersecurity #pcap_analysis
════════════════════════
𐀪 Author: Pavol Kluka
════════════════════════
ⴵ Time: Tue, 28 Jan 2025 19:33:16 GMT
════════════════════════
⌗ Tags: #koi_loader #malware #koi_stealer #cybersecurity #pcap_analysis
Medium
Network traffic analysis: Koi Loader/Stealer
After a long break I decided to write another article about network traffic analysis. If I want to practice my skills in this area, the…
⤷ Title: North Korean Hackers Deploy RustDoor and Koi Stealer to Target Cryptocurrency Developers on macOS
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 28 Feb 2025 02:12:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Alluring Pisces #BlueNoroff #CL_STA_240 #Contagious Interview #Koi Stealer #macOS #Rustdoor #Sapphire Sleet #visual studio
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Fri, 28 Feb 2025 02:12:23 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Alluring Pisces #BlueNoroff #CL_STA_240 #Contagious Interview #Koi Stealer #macOS #Rustdoor #Sapphire Sleet #visual studio
Cybersecurity News
North Korean Hackers Deploy RustDoor and Koi Stealer to Target Cryptocurrency Developers on macOS
Discover the Koi Stealer & RustDoor malware and how it threatens macOS users in the cryptocurrency sector with sophisticated cyberattacks.
⤷ Title: Betrayal of Trust: “Featured” Urban VPN Extension Caught Stealing Private AI Chat Logs from 8M Users
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:19:43 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Chatbots #Browser Extensions #ChatGPT #Data Exfiltration #data privacy #Google Chrome #Koi Security #malware #microsoft edge #Urban VPN Proxy
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:19:43 +0000
════════════════════════
⌗ Tags: #Data Leak #AI Chatbots #Browser Extensions #ChatGPT #Data Exfiltration #data privacy #Google Chrome #Koi Security #malware #microsoft edge #Urban VPN Proxy
Penetration Testing Tools
Betrayal of Trust: "Featured" Urban VPN Extension Caught Stealing Private AI Chat Logs from 8M Users
Browser extensions have long been a familiar way to boost productivity and add useful features, yet another incident
⤷ Title: Hidden in Plain Sight: How the GhostPoster Campaign Injected Malware Into 50,000 Firefox Users
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:36:09 +0000
════════════════════════
⌗ Tags: #Malware #Ad Fraud #browser security #cybersecurity #Firefox Extensions #GhostPoster #JavaScript Loader #Koi Security #Malware_as_a_Service #Mozilla #Steganography
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:36:09 +0000
════════════════════════
⌗ Tags: #Malware #Ad Fraud #browser security #cybersecurity #Firefox Extensions #GhostPoster #JavaScript Loader #Koi Security #Malware_as_a_Service #Mozilla #Steganography
⤷ Title: VPN Betrayal: Popular “Free” Extensions Caught Siphoning 8 Million Users’ Private AI Chats
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:05:33 +0000
════════════════════════
⌗ Tags: #Data Leak #1ClickVPN #AI Privacy #BiScience #Browser Extensions #ChatGPT #Claude #Data Broker #Gemini #KOI Security #Urban Browser Guard #Urban VPN
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:05:33 +0000
════════════════════════
⌗ Tags: #Data Leak #1ClickVPN #AI Privacy #BiScience #Browser Extensions #ChatGPT #Claude #Data Broker #Gemini #KOI Security #Urban Browser Guard #Urban VPN
Daily CyberSecurity
VPN Betrayal: Popular "Free" Extensions Caught Siphoning 8 Million Users’ Private AI Chats
Security firm KOI warns: Urban VPN extensions are secretly harvesting full AI chat transcripts for data brokers. Uninstall immediately to protect your data.
⤷ Title: The Silent Sync: How the “lotusbail” npm Package Hijacks WhatsApp Accounts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:36:24 +0000
════════════════════════
⌗ Tags: #Malware #Baileys library #Cybersecurity 2025 #JavaScript #Koi Security #lotusbail #malware #npm #Session Hijacking #supply chain attack #WhatsApp
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Dec 2025 02:36:24 +0000
════════════════════════
⌗ Tags: #Malware #Baileys library #Cybersecurity 2025 #JavaScript #Koi Security #lotusbail #malware #npm #Session Hijacking #supply chain attack #WhatsApp
Information Security News
The Silent Sync: How the “lotusbail” npm Package Hijacks WhatsApp Accounts
A malicious package named lotusbail has been uncovered in the npm repository, masquerading as a library for working with WhatsApp Web while quietly siphoning conversations and granting attackers p…
⤷ Title: “LotusBail” Trap: 56,000 Developers Downloaded a Fake WhatsApp API That Works perfectly—While Stealing Everything
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:41:07 +0000
════════════════════════
⌗ Tags: #Malware #@whiskeysockets/baileys #backdoor #data exfiltration #JavaScript Security #KOI Security #lotusbail #malware #npm #Open Source Security #supply chain attack #WhatsApp API
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:41:07 +0000
════════════════════════
⌗ Tags: #Malware #@whiskeysockets/baileys #backdoor #data exfiltration #JavaScript Security #KOI Security #lotusbail #malware #npm #Open Source Security #supply chain attack #WhatsApp API
Daily CyberSecurity
“LotusBail” Trap: 56,000 Developers Downloaded a Fake WhatsApp API That Works perfectly—While Stealing Everything
A new investigation by Koi Security has exposed a highly sophisticated supply chain attack lurking in the npm registry. For six months, a package named lotusbail masqueraded as a legitimate WhatsA…
⤷ Title: Popular NPM Package lotusbail Exposed as Trojan Stealing WhatsApp Chats
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 14:58:49 +0000
════════════════════════
⌗ Tags: #Privacy #Security #Cyber Attack #Cybersecurity #Koi Security #Koi Security uncovers lotusbail #lotusbail #Malware #NPM #WhatsApp
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 26 Dec 2025 14:58:49 +0000
════════════════════════
⌗ Tags: #Privacy #Security #Cyber Attack #Cybersecurity #Koi Security #Koi Security uncovers lotusbail #lotusbail #Malware #NPM #WhatsApp
Hackread
Popular NPM Package lotusbail Exposed as Trojan Stealing WhatsApp Chats
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 00:06:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Browser Extensions #chrome #cyber_espionage #DarkSpectre #Edge #firefox #GhostPoster #KOI Security #malware #ShadyPanda #state_sponsored #Zoom Stealer
Daily CyberSecurity
The Sleeper in Your Browser: How DarkSpectre Turned 8.8 Million Extensions into State-Aligned Spies
Koi Security unmasks DarkSpectre, a Chinese threat group that used 300+ browser extensions to spy on 8.8M users and steal corporate meeting data.
⤷ Title: The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:23:01 +0000
════════════════════════
⌗ Tags: #Malware #Browser Extensions #Chrome Malware #Corporate Espionage #DarkSpectre #GhostPoster #InfoSec 2026 #Koi Security #ShadyPanda #Steganography #Zoom Stealer
Penetration Testing Tools
The DarkSpectre Files: How a 7-Year Extension Campaign Hijacked 8.8 Million Browsers
A hacking group operating under the name DarkSpectre has, for seven years, systematically infected the computers of users
⤷ Title: GlassWorm’s macOS Gambit: The Invisible Worm Draining Developer Wallets via Open VSX
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:05:20 +0000
════════════════════════
⌗ Tags: #Malware #Crypto_Stealer #GlassWorm #Koi Security #macOS Security #Open VSX #Prettier Pro #Solana C2 #supply chain attack #Vibe_Coding #VS Code #ZOMBI RAT
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 05 Jan 2026 03:05:20 +0000
════════════════════════
⌗ Tags: #Malware #Crypto_Stealer #GlassWorm #Koi Security #macOS Security #Open VSX #Prettier Pro #Solana C2 #supply chain attack #Vibe_Coding #VS Code #ZOMBI RAT
Penetration Testing Tools
GlassWorm’s macOS Gambit: The Invisible Worm Draining Developer Wallets via Open VSX
A new wave of malicious extensions has been uncovered in the Open VSX extension marketplace, which is used
⤷ Title: macOS Developers in the Crosshairs: GlassWorm’s Wave 4 Exploits VS Code to Trojanize Hardware Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 00:17:01 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_CBC #AppleScript #Developer Tools #GlassWorm #Hardware Wallets #KOI Security #Ledger #macOS security #malware #supply chain attack #Trezor #VS Code Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 06 Jan 2026 00:17:01 +0000
════════════════════════
⌗ Tags: #Malware #AES_256_CBC #AppleScript #Developer Tools #GlassWorm #Hardware Wallets #KOI Security #Ledger #macOS security #malware #supply chain attack #Trezor #VS Code Extensions
Daily CyberSecurity
macOS Developers in the Crosshairs: GlassWorm’s Wave 4 Exploits VS Code to Trojanize Hardware Wallets
The resilient “GlassWorm” threat actor, known for embedding malicious code into Visual Studio Code extensions, has returned with a sophisticated fourth wave of attacks. A new report fr…