An unidentified attacker compromised versions of the popular Rust crates `arrayref` and `append-only-vec` by injecting a dependency on the typosquatted `proc-macro1` package. Its Cargo build script downloads and executes cross-platform malware that steals…
« Reports in 2026
553 reports
An attacker compromised a Rust maintainer account and poisoned `arrayref 0.3.10`, `internment 0.8.7`, and `append-only-vec 0.1.9` with a dependency on a build-time dropper. Compiling an affected dependency downloaded and executed a second-stage payload fr…
The Rust Security Response Team removed malicious crates from crates.io after confirming that `proc-macro1` used a build script to download a payload. A compromised computer or account likely enabled attackers to republish `arrayref`, `internment`, and `a…
Malicious releases of three Rust crates introduced a typosquatted dependency whose build script executed a cross-platform backdoor during compilation, exposing developer workstations and CI runners. The implant collected system and browser-profile informa…
Kimsuky targeted organizations in South Korea and Japan during the first half of 2026 with OneDrive-delivered spearphishing links leading to malicious LNK files. The infection chain established scheduled PowerShell execution, collected system information …
Kimsuky targeted organizations in South Korea and Japan during the first half of 2026 with OneDrive-delivered spearphishing links leading to malicious LNK files. The infection chain established scheduled PowerShell execution, collected system information …
North Korea has industrialized remote-employment fraud, using stolen or fabricated identities, deepfakes, proxy interviewers, and U.S.-based laptop farms to place operatives inside organizations and generate state revenue. Abnormal says it flagged roughly…
Recorded Future links PurpleDelta to a state-directed network of North Korean IT workers that used at least 22 fabricated personas to apply to more than 1,100 companies and likely obtained employment at ten or more organizations. Operators combined illici…
Lazarus Group reportedly exploited the Windows `afd.sys` privilege-escalation flaw CVE-2026-68820 as a zero-day during an Operation Dream Job campaign targeting defense and aerospace organizations in four countries. Fake Enveil recruitment material delive…
North Korea's PolinRider campaign has expanded from more than 300 affected GitHub owners in March 2026 to over 2,000 owners and 4,000 compromised repositories by July. It infects developers through fake Contagious Interview coding tests, trojanized packag…
An on-chain researcher documented a suspected DPRK IT worker who applied as "Ming Cheng" using the hodlwarden persona and supplied inconsistent employment and location details. The researcher linked the hodlwarden GitHub account to the Contagious Trader c…
Moonlock Lab analyzed an active Contagious Interview chain targeting macOS users with a fake Git helper shell script that downloads a Node.js runner and an obfuscated OtterCookie payload. The payload steals browser passwords and Keychain data, scans files…
A fake Web3 recruiter compromised a cryptocurrency employee through a Google Apps Script assessment that delivered a signed ClickOnce package, two credential stealers, and a persistent Go RAT with hVNC. Exact overlap in an SSL.com signing certificate and …
A suspected North Korean IT worker applying to Ump Labs used questionable names and locations but demonstrated credible blockchain-engineering and smart-contract security knowledge during an undercover interview. Researchers linked his profiles, email add…
The Wall Street Journal used leaked browser histories, emails, calendars, screen recordings, interviews, and previously unseen videos to trace a North Korean remote-worker cell that infiltrated at least eight U.S. companies within months. Thousands of DPR…