Threats Tagged 'mal-2026-13688'
View all threats tagged with 'mal-2026-13688'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-13688'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @kuperka/chainguard-sdk (npm) 0 The npm package @kuperka/chainguard-sdk versions 1.0.1 and 1.0.2 contains malicious code that exfiltrates sensitive user data. Upon loading, it collects cookies, localStorage/sessionStorage data, form inputs, CSRF/auth tokens, and Web3 wallet identifiers, encoding and sending them to a hardcoded external endpoint. It also scans the page content for credential patterns such as Stripe keys, AWS keys, GitHub tokens, JWTs, and OpenAI keys. Additionally, it captures keystrokes with context and intercepts fetch requests to steal authorization headers and request bodies. The malicious code then displays a fake security overlay to conceal its activity. The package impersonates a legitimate security tool by using the 'chainguard' name and branding. Join the discussion | GCVE Database | 08/10/2026, 12:24:28 UTC Added: 08/10/2026, 15:39:48 UTC |
Showing 1 to 1 of 1 result