Attackers targeted a Ukrainian civil society representative with a personalized collaboration email sent from a genuine Gmail account, withholding the malicious link until the recipient replied. A Codeberg-hosted archive contained an LNK file disguised as…
« Reports in 2026
593 reports
Attackers compromised a crates.io maintainer account and poisoned arrayref, internment, and append-only-vec with a malicious proc-macro1 build dependency that executed during compilation. The resulting implant stole browser credentials, established cross-…
DPRK espionage groups Konni and Kimsuky have expanded into cryptocurrency-focused operations using distinct but increasingly sophisticated infection chains. Konni targeted crypto professionals with disguised AppleScript files, fake macOS password dialogs,…
A DPRK-linked fake recruiter sent a Bitso developer a malicious coding challenge containing cross-platform PowerShell and Bash stagers. The scripts created a hidden `.vscode` directory, inspected or updated Node.js, and installed a previously unseen obfus…
Attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref, internment, and append-only-vec that pulled in a typosquatted dependency whose build script executed during compilation. The second stage harvested browse…
North Korean operatives use stolen or synthetic identities, AI assistance, domestic facilitators, VPNs, and laptop farms to obtain legitimate remote-work access inside companies and government agencies. A joint BCA LTD, NorthScan, and ANY.RUN investigatio…
A compromised crates.io account published `arrayref` 0.3.10 with a dependency on the typosquatted `proc-macro1` crate, causing malicious code to run automatically during Cargo builds. The dependency's build script reconstructed an obfuscated URL, download…
An unidentified attacker compromised versions of the popular Rust crates `arrayref` and `append-only-vec` by injecting a dependency on the typosquatted `proc-macro1` package. Its Cargo build script downloads and executes cross-platform malware that steals…
An attacker compromised a Rust maintainer account and poisoned `arrayref 0.3.10`, `internment 0.8.7`, and `append-only-vec 0.1.9` with a dependency on a build-time dropper. Compiling an affected dependency downloaded and executed a second-stage payload fr…
The Rust Security Response Team removed malicious crates from crates.io after confirming that `proc-macro1` used a build script to download a payload. A compromised computer or account likely enabled attackers to republish `arrayref`, `internment`, and `a…
Malicious releases of three Rust crates introduced a typosquatted dependency whose build script executed a cross-platform backdoor during compilation, exposing developer workstations and CI runners. The implant collected system and browser-profile informa…
Kimsuky targeted organizations in South Korea and Japan during the first half of 2026 with OneDrive-delivered spearphishing links leading to malicious LNK files. The infection chain established scheduled PowerShell execution, collected system information …
Kimsuky targeted organizations in South Korea and Japan during the first half of 2026 with OneDrive-delivered spearphishing links leading to malicious LNK files. The infection chain established scheduled PowerShell execution, collected system information …
North Korean IT-worker operators openly solicited U.S.-based laptop hosting, aged LinkedIn accounts, stolen identities, and bulk job applications in public Discord channels. Observed offers included $500 per month to host an employer laptop in Texas, a ha…
North Korea has industrialized remote-employment fraud, using stolen or fabricated identities, deepfakes, proxy interviewers, and U.S.-based laptop farms to place operatives inside organizations and generate state revenue. Abnormal says it flagged roughly…