Infostealer
Curated coverage and analysis in this editorial area.

Atomic Arch: 1,500 AUR Packages Hijacked, Targeting Developers and CI
The Atomic Arch operation hijacked over 1,500 Arch User Repository packages via orphaned-package ownership transfers to deliver a Rust…

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions
Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

Malicious AI Skills: 3,000 Evade Scanning, Enterprises Exposed
ESET detected over 3,000 malicious skills among nearly 900,000 analyzed. The SkillCloak technique bypasses static scanners in more tha…

Armored Likho Targets Governments and Power Operators with BusySnake Stealer
The Armored Likho APT group, uncovered by Kaspersky, is conducting cyber-espionage and financially motivated attacks against governmen…

FortiBleed Fuels INC and Lynx: One Operator Serving Two Ransomware Clients
SOCRadar has documented the link between FortiBleed and the INC and Lynx ransomware groups. A single operator accessed the negotiation…

BusySnake Stealer: The APT That Generates Malware With AI
Armored Likho uses LLMs to write first-stage payloads and PyArmor Pro to obfuscate them. Kaspersky's report reveals an infostealer tar…

Medtronic Begins Breach Notifications: 369,200+ Confirmed Victims vs. 9 Million Claimed by ShinyHunters
Medtronic has started notifying individuals affected by an April 2026 corporate IT breach. State regulator filings confirm over 369,20…

ChocoPoC RAT: How Fake PoCs on PyPI Infected Vulnerability Researchers
ChocoPoC, a Python RAT, spreads via GitHub repositories posing as proof-of-concept exploits that hide the payload in transitive PyPI d…

VEIL#DROP: How Blogger Became an Infostealer Armorer
Securonix uncovers VEIL#DROP, a multi-stage malware chain that weaponizes Google Blogger to deliver the PureLogs Stealer filelessly, b…

CVE-2026-48558: Djinn Stealer Exploited In-the-Wild on SimpleHelp
Threat actors exploit CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver. The new infostealer targets AI and cloud credentials. Rou…

Amadey/StealC: 27M Credentials Recovered, $47M in Crypto Seized
Operation Endgame dismantled two malware-as-a-service networks. Here's why the RICO legal theory changes the game and what it means fo…

OpenClaw: 5 Malicious Skills Evade AI Scanners for Months
Unit 42 reveals evasive skills on ClawHub exploiting semantic instruction hijacking. 80% of 49,943 skills analyzed show behavioral dev…