Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 't1552'

View all threats tagged with 't1552'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1552

Threats Tagged 't1552'

Click on any threat for detailed analysis and mitigation recommendations

Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
0

ChainDrop is a self-propagating worm that has compromised over 400 npm packages in a major software supply chain attack. It exploits stolen npm publishing credentials to modify and republish legitimate software releases automatically. The malware targets developer workstations and CI/CD environments, stealing credentials from multiple platforms including npm, GitHub, AWS, Kubernetes, and HashiCorp Vault. It uses preinstall lifecycle scripts for automatic execution and persists by modifying repository configurations and abusing GitHub Actions OIDC workflows. After stealing credentials, ChainDrop autonomously propagates by inserting malicious payloads into packages and republishing them with incremented versions, enabling widespread compromise of the software ecosystem.

Join the discussion
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
0

A fraudulent website impersonating Corepack, the Node.js package manager tool, is distributing malware to developers. The attackers exploit timing around Corepack's removal from Node.js bundling, targeting developers searching for installation instructions. The site offers Windows executables that deliver OpenShield infostealer and proxyware, enrolling victim machines in bandwidth-sharing networks without consent. The payload steals browser credentials, SSH keys, establishes persistence, and routes third-party traffic through compromised systems. An alternative download path delivers adware and trojan components disguised as OperaGX installer. The site features AI-generated content with obvious errors, including confusing Yarn package manager with textile crafts. The domain has been reported to registrars for takedown after community members identified the threat.

Join the discussion
Contagious Interview malware in SVG images: DPRK campaign
0

A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: t1552
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses