Threats Tagged 'credential theft'
View all threats tagged with 'credential theft'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'credential theft'
Click on any threat for detailed analysis and mitigation recommendations
ChainDrop npm Attack Compromises Hundreds of Packages 0 A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm. Join the discussion | AlienVault OTX General | 08/06/2026, 12:57:28 UTC Added: 08/06/2026, 16:41:13 UTC |
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources 0 Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management. Join the discussion | AlienVault OTX General | 08/06/2026, 12:38:45 UTC Added: 08/06/2026, 16:41:13 UTC |
Here We Go Again - JavaScript Payload Analysis 0 A 710 KB JavaScript payload was discovered in the compromised [email protected] package, representing a newer variant of Shai-Hulud with enhanced obfuscation techniques. The malicious code operates with four primary objectives: harvesting credentials from local systems, CI environments, cloud platforms, Kubernetes, and Vault; exfiltrating encrypted data through dynamic HTTPS endpoints or public GitHub repositories; leveraging stolen npm credentials to publish infected patch releases across accessible packages; and exploiting GitHub credentials with GitHub Actions to compromise repositories and extract additional credentials. The campaign demonstrates sophisticated supply chain attack capabilities, targeting the npm ecosystem and development infrastructure. Multiple components were identified including obfuscated JavaScript files, VS Code configuration files, and injected GitHub Actions workflows, indicating a comprehensive approach to credential theft and lateral movement across development environments. Join the discussion | AlienVault OTX General | 08/06/2026, 09:43:34 UTC Added: 08/06/2026, 10:56:12 UTC |
npm Packages Hijacked in Supply Chain Attack 0 Multiple npm packages in the keyv/cacheable ecosystem were compromised after attackers gained control of a GitHub maintainer account. Beginning at 9:00 UTC on August 4, 2026, the attacker introduced IDE persistence mechanisms and published malicious versions that propagated to over 400 distinct packages. The payload is a descendant of the 'Mini' Shai-Hulud malware family, sharing similarities with TeamPCP and antv campaigns. It targets sensitive data including cloud credentials, infrastructure secrets, developer credentials, AI configuration files, and cryptocurrency wallets. The malware uniquely retrieves command-and-control domains from an Ethereum smart contract rather than embedding them, allowing infrastructure updates without modifying the payload. Data is exfiltrated through GitHub repositories created under compromised identities. The campaign demonstrates sophisticated supply chain attack techniques targeting developer environments and CI/CD pipelines. Join the discussion | AlienVault OTX General | 08/04/2026, 18:15:36 UTC Added: 08/05/2026, 09:26:29 UTC |
Phishing Email Delivers ScreenConnect Malware 0 A sophisticated phishing campaign targets Windows users with fraudulent Bank of America emails, delivering ScreenConnect remote monitoring software as malware. The attack begins with convincing emails mimicking Bank of America branding, directing victims to fake security pages. Windows users receive AccountGuard.zip containing a VBS file with multiple layers of base64-encoded content. The attack chain deploys complex decoding scripts and employs a UAC bypass exploit via ICMLuaUtil COM interface to install ScreenConnect with administrator privileges. Additional components use SDDL and ACLs to hide the installation, prevent uninstallation, and conceal the malicious service. The installed client connects to command-and-control infrastructure in the UAE. Mac users encounter traditional credential phishing pages requesting banking credentials and personal information instead of receiving malware payloads. Join the discussion | AlienVault OTX General | 08/04/2026, 18:14:35 UTC Added: 08/05/2026, 09:26:29 UTC |
Supply Chain Compromise Affecting keyv and cacheable npm Packages 0 An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. The attack began on August 4, 2026, when the maintainer account Jaredwray was compromised, enabling attackers to publish malicious code across multiple packages. The malware deploys through a preinstall hook that downloads a Bun runtime and executes obfuscated payloads designed to harvest cloud credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. The threat exhibits worm-like behavior by using stolen npm tokens to republish trojanized versions of additional packages beyond the original namespaces. Stolen credentials are exfiltrated to attacker-controlled GitHub repositories via DNS-resolved destinations, with persistence mechanisms planted in developer environments through .claude and .vscode hooks. Join the discussion | AlienVault OTX General | 08/06/2026, 09:04:56 UTC Added: 08/05/2026, 08:56:25 UTC |
Analysis of a Phishing Email Attack Case 0 The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation. Join the discussion | AlienVault OTX General | 08/03/2026, 16:50:56 UTC Added: 08/04/2026, 08:34:07 UTC |
ClickFix Keeps Evolving: Rundll32 Ordinal Execution over WebDAV 0 A sophisticated ClickFix campaign variant uses social engineering to trick victims into executing commands via the Windows Run dialog. The technique leverages rundll32.exe to load remote non-DLL payloads by ordinal export #1 over WebDAV connections tunneled through HTTPS port 443. Multiple incidents at a single organization show evolving obfuscation methods including WMI process spawning, caret insertion, and runtime string assembly to evade detection. The attack chain utilizes trusted Windows binaries like pcalua.exe to break process lineage tracking. No files are dropped to disk, and payloads are invoked by ordinal rather than named functions. Successful attacks exfiltrated browser credentials and sensitive documents totaling 13MB. The most obfuscated variant evaded automated EDR detection entirely, being discovered only through proactive threat hunting focused on ordinal execution patterns rather than keyword detection. Join the discussion | AlienVault OTX General | 07/29/2026, 02:59:33 UTC Added: 07/29/2026, 12:07:07 UTC |
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon 0 Flying Eagle is an Android remote access tool (RAT) whose source code was leaked in early 2026, leading to a fractured criminal ecosystem with about 170 active servers. The malware is distributed via Telegram channels offering modified versions and operational support, targeting Chinese users primarily with phishing overlays aimed at financial, adult, and government services. A successor platform called Night Dragon was introduced in June 2026, enhancing credential theft capabilities for Chinese banking apps, cryptocurrency wallets, and social media. The threat leverages social engineering and impersonation tactics, including malicious APKs mimicking official Chinese government apps. While primarily focused on China, the platform's templates suggest potential for broader international targeting. Join the discussion | AlienVault OTX General | 07/28/2026, 21:18:53 UTC Added: 07/29/2026, 12:07:07 UTC |
AI-Native security platform 0 Between May and July 2026, security researchers deployed an unauthenticated Model Context Protocol (MCP) honeypot server to observe how threat actors exploit AI agent infrastructure. Of approximately 1,000 sources that reached the decoy, 596 spoke the protocol and 24 proceeded to actively exploit it. These operators executed 628 shell commands, 255 file reads, and 248 secrets-store lookups, with 19 hunting credentials and 4 attempting container escapes. Activity escalated from 39 tool calls in May to 877 by mid-July. Three stolen credentials were subsequently used against a live AWS account, with two cases involving Bedrock model invocation for LLMjacking. The attacks demonstrated automated reconnaissance, credential harvesting, container escape attempts, backdoor account creation, and Kubernetes enumeration, revealing that exposed MCP servers represent a growing attack surface as AI agent infrastructure proliferates. Join the discussion | AlienVault OTX General | 07/27/2026, 16:59:18 UTC Added: 07/28/2026, 10:22:27 UTC |
Showing 1 to 10 of 22 results