⤷ Title: Developer Alert: Fake VS Code Extension Deploys OctoRAT via Multi-Stage Anivia Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:08:51 +0000
════════════════════════
⌗ Tags: #Malware #Anivia Loader #Credential Theft #Developer Security #OctoRAT #Prettier_vscode_plus #supply chain attack #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:08:51 +0000
════════════════════════
⌗ Tags: #Malware #Anivia Loader #Credential Theft #Developer Security #OctoRAT #Prettier_vscode_plus #supply chain attack #VS Code
Penetration Testing Tools
Developer Alert: Fake VS Code Extension Deploys OctoRAT via Multi-Stage Anivia Loader
At the end of November, a team of bug hunters uncovered an infection chain that began with a
⤷ Title: CVE-2026-22718: EOL Spring CLI Tool for VS Code Found Vulnerable to Command Injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 23:48:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_22718 #developer security #end_of_life #EOL #Spring CLI #VS Code Extension #vulnerability management #Yue Liu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 13 Jan 2026 23:48:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_22718 #developer security #end_of_life #EOL #Spring CLI #VS Code Extension #vulnerability management #Yue Liu
Daily CyberSecurity
CVE-2026-22718: EOL Spring CLI Tool for VS Code Found Vulnerable to Command Injection
Urgent: Uninstall the EOL Spring CLI VS Code extension now. CVE-2026-22718 (CVSS 6.6) allows command injection and will not be patched.
⤷ Title: The Developer’s Trap: EmEditor Supply Chain Attack Drains Credentials
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:57:05 +0000
════════════════════════
⌗ Tags: #Malware #Developer Security #EmEditor #Emurasoft #Google Drive Caching #InfoSec 2026 #Infostealer #PowerShell #supply chain attack #Trend Micro #Watering Hole
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 07:57:05 +0000
════════════════════════
⌗ Tags: #Malware #Developer Security #EmEditor #Emurasoft #Google Drive Caching #InfoSec 2026 #Infostealer #PowerShell #supply chain attack #Trend Micro #Watering Hole
Penetration Testing Tools
The Developer’s Trap: EmEditor Supply Chain Attack Drains Credentials
In late December 2025, the architects of the renowned text editor EmEditor issued a formal advisory regarding the
⤷ Title: Shattering the Trust: The “GlassWorm” Supply Chain Attack Hijacking Open VSX Extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:53:08 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Developer Security #GlassWorm #Infostealer #macOS Malware #oorzc #Open VSX #Socket Security #Solana blockchain #supply chain attack #VS Code extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:53:08 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Developer Security #GlassWorm #Infostealer #macOS Malware #oorzc #Open VSX #Socket Security #Solana blockchain #supply chain attack #VS Code extensions
Penetration Testing Tools
Shattering the Trust: The "GlassWorm" Supply Chain Attack Hijacking Open VSX Extensions
A sophisticated supply chain incursion has been documented within the Open VSX extension registry, precipitated by the illicit
⤷ Title: CVE-2025-65717: Critical Vulnerability in VS Code’s Live Server Extension Puts 72 Million Developers at Risk, No Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 02:52:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_65717 #Cyber Security #developer security #IDE Vulnerability #infosec #Live Server #Localhost Exfiltration #OX Security #VS Code Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 02:52:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_65717 #Cyber Security #developer security #IDE Vulnerability #infosec #Live Server #Localhost Exfiltration #OX Security #VS Code Security
Daily CyberSecurity
CVE-2025-65717: Critical Vulnerability in VS Code's Live Server Extension Puts 72 Million Developers at Risk, No Patch
Critical VS Code Live Server flaw CVE-2025-65717 (CVSS 9.1) lets attackers steal source code and credentials via malicious links. Protect your workspace now.
⤷ Title: The Invisible Switch: North Korean Hackers Use “Contagious Interviews” to Trojanize Your MetaMask
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:59:27 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Chrome Security #Contagious Interview #Crypto Theft #Developer Security #InvisibleFerret #malware #MetaMask #North Korea #OtterCookie #Secure Preferences #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:59:27 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Chrome Security #Contagious Interview #Crypto Theft #Developer Security #InvisibleFerret #malware #MetaMask #North Korea #OtterCookie #Secure Preferences #Tech News 2026
Penetration Testing Tools
The Invisible Switch: North Korean Hackers Use "Contagious Interviews" to Trojanize Your MetaMask
North Korean cyber-adversaries are endeavoring to surreptitiously supplant the MetaMask cryptocurrency wallet extension directly upon a victim’s workstation—an
⤷ Title: The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #malware #Microsoft Defender #Next.js #npm Security #social engineering #supply chain attack #Technical Interview Scam #VS Code Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #malware #Microsoft Defender #Next.js #npm Security #social engineering #supply chain attack #Technical Interview Scam #VS Code Security
Daily CyberSecurity
The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
Microsoft warns of a new campaign targeting engineers via fake Next.js technical assessments. Malware hides in VS Code tasks and npm scripts to steal secrets.
⤷ Title: The Fake Job Trap: Microsoft Exposes the ‘Contagious Interview’ Campaign Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 03:19:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #developer security #DevSecOps #infosec #Invisible Ferret #Microsoft Defender Experts #OtterCookie #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 03:19:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #developer security #DevSecOps #infosec #Invisible Ferret #Microsoft Defender Experts #OtterCookie #phishing #social engineering
Daily CyberSecurity
The Fake Job Trap: Microsoft Exposes the 'Contagious Interview' Campaign Targeting Developers
Microsoft exposes the "Contagious Interview" campaign. Fake recruiters trick developers into installing Invisible Ferret malware during coding tests.
⤷ Title: Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 13:03:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CORS Misconfiguration #CVE_2026_28792 #CVSS 9.7 #cybersecurity #developer security #Drive_by Attack #File Exfiltration #infosec #Path Traversal #TinaCMS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 13:03:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CORS Misconfiguration #CVE_2026_28792 #CVSS 9.7 #cybersecurity #developer security #Drive_by Attack #File Exfiltration #infosec #Path Traversal #TinaCMS
Daily CyberSecurity
Critical 9.7 CVSS TinaCMS Flaw Exposes Local Developer Machines
Critical 9.7 CVSS flaw in TinaCMS (CVE-2026-28792) lets attackers hijack local developer machines via CORS and path traversal. Patch to 2.1.8 immediately.
⤷ Title: Developer Alert: “CursorJack” Technique Weaponizes Deeplinks to Hijack Cursor IDE
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 08:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Cursor IDE #CursorJack #cybersecurity #developer security #infosec #MCP Deeplinks #Proofpoint #supply chain attack #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Mar 2026 08:03:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #Cursor IDE #CursorJack #cybersecurity #developer security #infosec #MCP Deeplinks #Proofpoint #supply chain attack #threat intelligence
Daily CyberSecurity
Developer Alert: "CursorJack" Technique Weaponizes Deeplinks to Hijack Cursor IDE
Proofpoint details 'CursorJack', a novel exploit using malicious MCP deeplinks in the Cursor AI editor to execute arbitrary code on developer machines.
⤷ Title: The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
Penetration Testing Tools
The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
An ostensibly innocuous package for validating Google Gemini tokens manifested within the npm repository, yet beneath its rudimentary
⤷ Title: Alert: Social Engineering Campaign Targets Open Source Developers via Slack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:01:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #Linux Foundation #macOS Malware #malware #phishing #Root Certificate #Slack #social engineering #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 04:01:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #Linux Foundation #macOS Malware #malware #phishing #Root Certificate #Slack #social engineering #Windows Security
Daily CyberSecurity
Alert: Social Engineering Campaign Targets Open Source Developers via Slack
Attackers are impersonating Linux leaders on Slack to drop malware via fake Google Workspace links. Protect your dev environment—verify before acting!
⤷ Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Daily CyberSecurity
North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
North Korean hackers are now targeting AI tools like Cursor and Claude. The OtterCookie malware steals API keys and conversation logs. Is your dev environment safe?
⤷ Title: The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
Daily CyberSecurity
The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
Panther Research exposes a massive 2026 DPRK npm campaign using blockchain dead-drops to steal crypto keys and AI secrets. Secure your CI/CD pipelines now.
⤷ Title: The Trojan Update: How “GlassWorm” Developers are Using Sleeper Extensions to Hijack Workspaces
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 07:32:31 +0000
════════════════════════
⌗ Tags: #Malware #Cyber Espionage #Developer Security #extension security #GlassWorm #malware #OpenVSX #Socket #supply chain attack #Trojan Update #Visual Studio Code #VS Code
Penetration Testing Tools
The Trojan Update: How "GlassWorm" Developers are Using Sleeper Extensions to Hijack Workspaces
The GlassWorm campaign has resurfaced within the developer community, though the adversaries have adopted a more surreptitious operational
⤷ Title: Minirat’s Stealth Supply Chain Attack Targets macOS Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 01:59:57 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #2026 #cybersecurity #developer security #go #infosec #macOS #Malware Analysis #Minirat #npm #Remote Access Trojan #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 01:59:57 +0000
════════════════════════
⌗ Tags: #Malware #@velora_dex/sdk #2026 #cybersecurity #developer security #go #infosec #macOS #Malware Analysis #Minirat #npm #Remote Access Trojan #supply chain attack
Daily CyberSecurity
Minirat’s Stealth Supply Chain Attack Targets macOS Developers
Minirat, a Go-based macOS RAT, exploits npm supply chains to bypass security. It features VM detection, AES encryption, and persistence. Secure your dev tools.
⤷ Title: GitHub Was Breached Through a Single VS Code Extension.
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Thu, 21 May 2026 05:21:13 GMT
════════════════════════
⌗ Tags: #supply_chain_security #github #infosec #developer_security #cybersecurity
════════════════════════
𐀪 Author: Sai kiran
════════════════════════
ⴵ Time: Thu, 21 May 2026 05:21:13 GMT
════════════════════════
⌗ Tags: #supply_chain_security #github #infosec #developer_security #cybersecurity
Medium
GitHub Was Breached Through a Single VS Code Extension.
One employee. One poisoned extension. One click on the VS Code Marketplace. And TeamPCP walked out with 3,800 of GitHub’s internal…
⤷ Title: Global Malicious AI Installer Campaign Targets Developer Workstations
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 06:37:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Claude Code #developer security #EclecticIQ #Fileless Malware #Gemini CLI #Infostealer Campaign #SEO Poisoning
⤷ Title: North Korea-Aligned Void Dokkaebi Evolves with Binary Obfuscation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 08:36:07 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Cryptocurrency Theft #Cython Malware #developer security #Famous Chollima #InvisibleFerret #Void Dokkaebi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 08:36:07 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Cryptocurrency Theft #Cython Malware #developer security #Famous Chollima #InvisibleFerret #Void Dokkaebi
Daily CyberSecurity
North Korea-Aligned Void Dokkaebi Evolves with Binary Obfuscation
TrendAI Research exposes the new Void Dokkaebi Cython malware campaign. Learn how InvisibleFerret uses binary compilation to evade security teams.
⤷ Title: Supply Chain Trojan Targets Software Developers Through Project Files
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 06:04:07 +0000
════════════════════════
⌗ Tags: #Malware #crypto wallet theft #developer security #Doctor Web #malware #Software Supply Chain #Supply Chain Trojan #XMRig
Daily CyberSecurity
Supply Chain Trojan Targets Software Developers Through Project Files
At a glance Malware family Multi-stage trojan (Doctor Web: Trojan.DownLoader49, BackDoor.Siggen2.5906, Trojan.BtcMine.3956) Threat actor Unknown; not attributed Target / victims Software developer…