Threats Tagged 't1552'
View all threats tagged with 't1552'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1552'
Click on any threat for detailed analysis and mitigation recommendations
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack 0 ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem. Join the discussion | AlienVault OTX General | 08/11/2026, 15:03:12 UTC Added: 08/11/2026, 15:26:15 UTC |
Fake Corepack Site Distributes Infostealer and Proxyware to Developers 0 A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat. Join the discussion | AlienVault OTX General | 07/25/2026, 07:54:44 UTC Added: 07/27/2026, 08:07:08 UTC |
Contagious Interview malware in SVG images: DPRK campaign 0 A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers. Join the discussion | AlienVault OTX General | 07/17/2026, 20:08:00 UTC Added: 07/18/2026, 08:55:18 UTC |
Showing 1 to 3 of 3 results