Threat Actor LARVA-208 Targets Web3 Developers via Fake AI Platform Malware
Sophisticated spearphishing campaign delivers the Fickle infostealer via malicious 'audio driver' download, compromising developer credentials and project supply chains.
Open-Source Registry Polluted by Automated Token Farming Supply Chain Attack
An unprecedented supply chain attack polluted the npm registry with 150,000 malicious packages to exploit a token reward system, demonstrating critical open-source risk.
Malicious Rust Crates Hijack Developer Keys for Solana and Ethereum Wallets
A sophisticated supply chain attack, leveraging typosquatting in Rust's package registry, compromises developer environments to exfiltrate critical blockchain private keys.
Crypto Developers Targeted by Supply Chain Malware via Ethereum Smart Contracts
Exploiting open-source dependencies and blockchain for covert malware delivery represents an advanced supply chain vector, directly compromising developer environments and digital assets.
NPM Supply Chain Compromise Threatens JavaScript Crypto Ecosystem
A pervasive supply chain attack on NPM accounts injects malicious code, covertly swapping cryptocurrency addresses during user-approved transactions.
