Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes WiperThe Hacker News·Mar 25, 14:32 UTC · Mar 25, 2026MalwareCVE-2026-33634160
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm PackagesThe Hacker News·Mar 23, 07:53 UTC · Mar 23, 2026Malware42
⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreThe Hacker News·Mar 26, 15:38 UTC · Mar 26, 2026Malware in the wildCVE-2026-33017CVE-2026-2013160
‘CanisterWorm’ Springs Wiper Attack Targeting IranKrebs on Security·Mar 23, 19:04 UTC · Mar 23, 2026Malware42
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV FilesThe Hacker News·Mar 28, 06:25 UTC · Mar 28, 2026Malware42
Cybercrime goes subscription: AI, malware and infrastructure on demandHelp Net Security·Jul 31, 00:00 UTC · Jul 31, 2026Malware42
Dozens of Red Hat packages backdoored through its official NPM channelArs Technica · Security·Jun 1, 19:49 UTC · Jun 1, 2026Malware42
Shai-Hulud worm copycats emerge after source code leakSecurity Affairs·May 19, 07:29 UTC · May 19, 2026Malware42
Widely used Daemon Tools disk app backdoored in monthlong supplyArs Technica · Security·May 5, 19:46 UTC · May 5, 2026Malware42
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply ChainThe Hacker News·Apr 24, 04:35 UTC · Apr 24, 2026Malware42
SentinelOne autonomous detection blocks trojaned LiteLLM triggered by Claude CodeSecurity Affairs·Apr 1, 08:59 UTC · Apr 1, 2026Malware42
Axios npm packages backdoored in supply chain attackHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2026Malware42
TeamPCP strikes again: Backdoored Telnyx PyPI package delivers malwareHelp Net Security·Mar 27, 00:00 UTC · Mar 27, 2026Malware42
New Npm 'Ghost Campaign' Uses Fake Install Logs to Hide MalwareInfosecurity Magazine·Mar 24, 14:30 UTC · Mar 24, 2026Malware42
Self-propagating malware poisons open source software and wipes IranArs Technica · Security·Mar 24, 12:38 UTC · Mar 24, 2026Malware42