Infostealer
Curated coverage and analysis in this editorial area.

VoidStealer Bypasses Chrome Encryption by Attacking Memory
VoidStealer circumvents Chrome's App-Bound Encryption by extracting the master key from memory during decryption. The MaaS infostealer…

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face
OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…

Operation STANDOFF: 44 C2 Servers Mask Traffic With GitHub Redirects
VMRay Labs has mapped a Russian-speaking criminal campaign operating at least 44 command-and-control servers hosted on TimeWeb Ltd. (A…

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector
Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

LiteLLM Open-Source LLM Gateway Distributes Credential-Stealing Malware
Two PyPI versions of the litellm package were compromised by malware that abuses Python .pth files to exfiltrate credentials to an att…

dYdX Hit by Third Supply-Chain Attack: Compromised npm and PyPI Packages Deliver Wallet Stealer and RAT
DeFi protocol with $1.5T cumulative volume compromised on npm and PyPI. Wallet stealer and remote access trojan distributed via mainta…

Iran Weaponizes Its Asymmetric Playbook With Commercial AI
Recorded Future documents how generative AI has become a force multiplier across Iranian cyber and influence operations — compressing…

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents
The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

LastPass Suffers New Breach via Klue: Vaults Safe, Personal Data Exposed
LastPass disclosed an indirect data breach through vendor Klue. Password vaults remain secure, but personal data including names, emai…

FakeGit: 800 AI Repositories on GitHub Turn Agents Into Malware Vectors
Island uncovered 800 malicious GitHub repositories masquerading as AI Skills and MCP servers. AI agents autonomously recommended the m…

TrapDoor: 34+ Malicious Packages Turn AI Assistants Into Insider Threats
The TrapDoor campaign has distributed over 34 packages across npm, PyPI, and Crates.io with multi-stage payloads and hidden instructio…