⤷ Title: Malicious “Hex Visualizer” Chrome Extension Targeting imToken Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:37:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Chrome Extension Phishing #Crypto Wallet Drainer #Cryptocurrency Security #Homoglyph Attack #ImToken Chromophore #infosec #Malware Analysis #Seed Phrase Theft #Socket Threat Research #Web3 security
Daily CyberSecurity
Malicious "Hex Visualizer" Chrome Extension Targeting imToken Users
Socket researchers uncover "ImToken Chromophore," a malicious Chrome extension using fake branding and homoglyphs to steal crypto wallet seed phrases.
⤷ Title: “Cyber Reconnaissance: Building a Banner Grabber Tool in Python”
════════════════════════
𐀪 Author: Akhilswami
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 02:52:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #reconnaissance #socket_programming #python
════════════════════════
𐀪 Author: Akhilswami
════════════════════════
ⴵ Time: Fri, 13 Mar 2026 02:52:20 GMT
════════════════════════
⌗ Tags: #cybersecurity #ethical_hacking #reconnaissance #socket_programming #python
Medium
“Cyber Reconnaissance: Building a Banner Grabber Tool in Python”
Subtitle:
⤷ Title: Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 01:01:10 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #FUNNULL Technology #infosec #JavaScript Injection #malware #OphimCMS #Packagist #PHP Composer #Socket Threat Research #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 01:01:10 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #FUNNULL Technology #infosec #JavaScript Injection #malware #OphimCMS #Packagist #PHP Composer #Socket Threat Research #supply chain attack
Daily CyberSecurity
Malicious Packagist Themes Target Vietnamese OphimCMS Sites with Trojanized JS
Socket uncovers a Packagist supply chain attack targeting Vietnamese OphimCMS streaming sites with trojanized themes linked to sanctioned entity FUNNULL.
⤷ Title: GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:11:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #GlassWorm #malware #Open VSX #Remote Code Execution #Socket Research #Solana Blockchain #supply chain attack #threat intelligence #VS Code Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:11:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #GlassWorm #malware #Open VSX #Remote Code Execution #Socket Research #Solana Blockchain #supply chain attack #threat intelligence #VS Code Extensions
Daily CyberSecurity
GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks
Socket Research exposes how GlassWorm malware abuses Open VSX dependencies for transitive delivery of an RCE backdoor using Solana blockchain dead drops.
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Daily CyberSecurity
The 1,700-Package Blitz: North Korea’s "Contagious Interview" Infiltrates Every Major Dev Registry
North Korea’s "Contagious Interview" campaign expands to 1,700+ malicious packages across npm, PyPI, and more. Learn how to protect your dev environment.
⤷ Title: 108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 15 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #browser security #C2 Infrastructure #Chrome extensions #cybersecurity #Google OAuth #infosec #malware #Session Hijacking #Socket Research #Telegram
Daily CyberSecurity
108 Coordinated Chrome Extensions Hijack Your Private Telegram Sessions
Socket identifies 108 malicious Chrome extensions stealing Telegram sessions and Google IDs. 20,000 installs hit—audit your browser extensions immediately!
⤷ Title: The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
Penetration Testing Tools
The Trojan Update: How "GlassWorm" Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
⤷ Title: The Sleeper in Your IDE: Unmasking the 73-Extension “GlassWorm” Espionage Campaign
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 08:01:51 +0000
════════════════════════
⌗ Tags: #Malware #.node binaries #Cursor AI #cyber_espionage #GlassWorm #IDE Security #infosec #Malware Analysis #Open VSX #Sleeper Extensions #Socket #VS Code #WindSurf
Daily CyberSecurity
The Sleeper in Your IDE: Unmasking the 73-Extension "GlassWorm" Espionage Campaign
Socket uncovers GlassWorm: a 73-extension sleeper campaign on Open VSX targeting VS Code and Cursor. Stealthy .node binaries turn trusted tools into malware.
⤷ Title: Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 03:23:31 +0000
════════════════════════
⌗ Tags: #Malware #BufferZoneCorp #CI/CD security #Credential Theft #cybersecurity #Go Modules #infosec #knot_theory #malware #RubyGems #Socket #supply chain attack
Daily CyberSecurity
Waking the Sleepers: The BufferZoneCorp Campaign Poisoning Ruby and Go Ecosystems
Socket uncovers a BufferZoneCorp "sleeper" campaign targeting Ruby and Go. Malicious packages steal SSH keys and subvert CI/CD pipelines. Patch now!
⤷ Title: The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 02 May 2026 02:52:05 +0000
════════════════════════
⌗ Tags: #Malware #Bun runtime #Composer Exploit #cybersecurity #infosec #Intercom_PHP #Mini Shai_Hulud #Packagist #PHP Malware #Secret Theft #Socket #supply chain attack
Daily CyberSecurity
The Worm Turns to PHP: Mini Shai-Hulud’s 20-Million-Install Hijack of Intercom
Socket uncovers a massive Mini Shai-Hulud breach in the Intercom PHP SDK. Malicious version 5.0.2 steals cloud secrets and GitHub tokens. Rotate keys now!