⤷ Title: Vidar Infostealer Hits npm for the First Time via 17 Typosquatted Packages and Postinstall Scripts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:22:56 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #Infostealer #MUT_4831 #npm #Postinstall Script #supply chain attack #Typosquatting #Vidar
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:22:56 +0000
════════════════════════
⌗ Tags: #Malware #Cryptocurrency Theft #Infostealer #MUT_4831 #npm #Postinstall Script #supply chain attack #Typosquatting #Vidar
Daily CyberSecurity
Vidar Infostealer Hits npm for the First Time via 17 Typosquatted Packages and Postinstall Scripts
Datadog exposed MUT-4831, a cluster that deployed Vidar Infostealer via 17 malicious npm packages. The malware uses postinstall scripts to download and execute the payload, stealing credentials and crypto wallets.
⤷ Title: “TanStack”: Malicious Name-Squatting Campaign Steals Environment Secrets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:58:40 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #data exfiltration #DevSecOps #infosec #npm malware #Postinstall Script #supply chain attack #Svix #TanStack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:58:40 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #cybersecurity #data exfiltration #DevSecOps #infosec #npm malware #Postinstall Script #supply chain attack #Svix #TanStack #Typosquatting
Daily CyberSecurity
"TanStack": Malicious Name-Squatting Campaign Steals Environment Secrets
A malicious unscoped "tanstack" npm package used live-debugged postinstall scripts to steal .env secrets via Svix webhooks. Check your dependencies now.
⤷ Title: Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 23 May 2026 04:32:47 +0000
════════════════════════
⌗ Tags: #Malware #CI/CD Poisoning #Cross_Ecosystem Malice #Cyber Security #devdojo/wave #GitHub Actions Backdoor #infosec #package.json Exploit #PHP Composer #Postinstall Script #Socket Security #Starter Kits #supply chain attack
Daily CyberSecurity
Malicious JS Lifecycle Hooks Found Hiding Inside PHP Composer Packages
Socket exposes a clever cross-ecosystem supply chain attack targeting PHP packages by hiding a malicious JS postinstall backdoor inside package.json.