PROBABLYPWNED
Home/Malware

Malware

180 articles

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

James RiveraMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

James RiveraMay 23, 2026
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

James RiveraMay 19, 2026
DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries
Malware4 min read

DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries

Kaspersky uncovered a supply chain attack on DAEMON Tools official website. Trojanized installers deployed QUIC RAT backdoors to thousands of systems, with a dozen government and manufacturing targets receiving advanced payloads.

James RiveraMay 8, 2026
Needle Stealer Spreads via Fake TradingView AI Tool
Malware4 min read

Needle Stealer Spreads via Fake TradingView AI Tool

Malwarebytes uncovers campaign using fake TradingClaw website to distribute Needle Stealer malware. The infostealer hijacks browsers to harvest credentials, crypto wallets, and financial data from traders.

James RiveraApr 28, 2026
Mirai Variant Targets End-of-Life D-Link Routers
Malware4 min read

Mirai Variant Targets End-of-Life D-Link Routers

Akamai detects active exploitation of CVE-2025-29635 in discontinued D-Link DIR-823X routers. The tuxnokill variant spreads via command injection and launches DDoS attacks from compromised devices.

James RiveraApr 23, 2026
Kyber Ransomware Deploys Post-Quantum Crypto on Windows
Malware4 min read

Kyber Ransomware Deploys Post-Quantum Crypto on Windows

New Kyber ransomware operation uses NIST-standardized Kyber1024 encryption on Windows while targeting VMware ESXi with a separate variant. Rapid7 analysis reveals the ESXi version's claims are false.

James RiveraApr 23, 2026