Infostealer
Curated coverage and analysis in this editorial area.

Miasma: The Malware Turning npm Into a Developer Trap
Miasma compromised 109 npm packages and GitHub Actions using Phantom Gyp and the Bun runtime. It extracts CI/CD secrets from memory an…

CL-STA-1062: From Taiwanese Web Hosting to Power Plants with TinyRCT Backdoor
Unit 42 reveals CL-STA-1062's escalation: from web hosting to state energy infrastructure in Southeast Asia with a custom .NET backdoo…

Ex-Huntress Analyst Accuses Company of Covering Up Insider Who Allegedly Fed FBI Data to DevMan Ransomware Gang
A former SOC analyst claims Huntress concealed an insider who passed U.S. law enforcement communications to the DevMan ransomware grou…

Gaslight: macOS Malware Tricks AI Analyzers with Prompt Injection
SentinelOne researchers have documented Gaslight, a previously unknown Rust-based macOS implant that embeds a prompt-injection payload…

ClickFix macOS: When Users Bypass Gatekeeper Themselves
Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

OXLOADER: Malicious Google Ads Deliver Infostealer
Elastic Security Labs uncovers OXLOADER, a previously undocumented Windows loader distributed via malicious Google Ads impersonating N…

Microsoft Attributes Mastra Supply-Chain Attack to North Korean Sapphire Sleet
Microsoft assesses with high confidence that the supply-chain compromise of more than 140 @mastra npm packages was carried out by the…

CryptoBandits: The USB Clipper-Worm That Adds RCE via Tor
Microsoft disclosed an active Windows clipper malware campaign running since February 2026 that uses malicious LNK files distributed v…

The 'robase' Malware Empties Entire Roblox Games: From Hat Theft to Digital Business Seizure
A malware campaign using the Python package 'robase' steals authenticated session tokens from Roblox developers via Discord social eng…

Malicious JetBrains Plugins Steal AI API Keys: 70,000 Downloads
A coordinated campaign of 15 malicious plugins on the JetBrains Marketplace exfiltrates AI API keys from developers' IDEs. Roughly 70,…

The Gentlemen: LLMs Accelerate the Ransomware Attack Cycle
CERT-AGID reveals that The Gentlemen ransomware group uses LLMs to build platforms in three days and customize extortion. Technical cl…

Algorithmic Exploitation: How TikTok and Instagram Reels Amplify Vidar Malware
ReversingLabs research reveals threat actors are using fake Spotify Premium tutorials to distribute the Vidar infostealer via PowerShe…