Malware Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in devplatform-react-mcp (npm) 0 The npm package devplatform-react-mcp version 35.5.6 is a malicious dropper disguised as a React MCP SDK. When loaded, it dynamically assembles hostnames to download and execute attacker-controlled binaries on the host system. It uses runtime string concatenation to evade static detection and spawns these binaries detached from the main process. The package has no legitimate native build purpose and its only observable behavior is fetching and running opaque payloads. Join the discussion | GCVE Database | 08/07/2026, 12:12:04 UTC Added: 08/07/2026, 15:17:38 UTC |
Malicious code in dolyame-ui-progresscircle (npm) 0 The npm package dolyame-ui-progresscircle (version 35.8.1) is a malicious package that masquerades as a UI progress-circle or monitoring SDK but contains no legitimate functionality. Instead, it unconditionally loads a module that downloads platform-specific executables from hardcoded Cloudflare workers.dev hosts and fallback domains, writes them to temporary directories under decoy names, sets executable permissions, and spawns them detached. The package uses string splitting and base64 encoding to evade static detection. This behavior constitutes malicious code execution upon package import or require. Join the discussion | GCVE Database | 08/07/2026, 12:14:33 UTC Added: 08/07/2026, 15:17:38 UTC |
Malicious code in dolyame-ui-clickoutsidehoc (npm) 0 The npm package dolyame-ui-clickoutsidehoc version 35.8.1 is a malicious package masquerading as a legitimate UI utility. Upon requiring the package, it loads obfuscated code that assembles hostnames to download a platform-specific executable from Cloudflare Workers domains and fallback DNS TXT covert channels. The executable is written to temporary directories under disguised names, given executable permissions, and spawned detached to run attacker-controlled native code on the host system. This package contains no legitimate UI functionality and acts as a dropper for malicious native code. Join the discussion | GCVE Database | 08/07/2026, 12:24:04 UTC Added: 08/07/2026, 15:17:38 UTC |
Malicious code in dolyame-ui-selectaccount (npm) 0 The npm package dolyame-ui-selectaccount version 35.8.1 contains malicious code that downloads and executes attacker-controlled native binaries on the host system during import. The malicious code uses obfuscated hostnames and runtime string assembly to evade detection, fetches payloads without integrity checks, and executes them detached from the parent process. This behavior is disguised under the guise of an 'Analytics SDK' or 'telemetry' module but actually performs unconditional remote code execution. Join the discussion | GCVE Database | 08/07/2026, 12:24:12 UTC Added: 08/07/2026, 15:17:38 UTC |
Malicious code in dolyame-boxy-independent-bnpl-faq (npm) 0 The npm package dolyame-boxy-independent-bnpl-faq version 35.8.7 contains malicious code that downloads and executes opaque native binaries from obfuscated Cloudflare Workers hosts and fallback DNS-TXT records. The payload is saved to temporary directories and executed detached from the main process, bypassing static detection methods. The package's stated purpose is unrelated to this behavior, indicating deliberate malicious intent. Join the discussion | GCVE Database | 08/07/2026, 12:25:15 UTC Added: 08/07/2026, 15:17:37 UTC |
Malicious code in sui-migration-audit-cli (npm) 0 The npm package sui-migration-audit-cli version 1.0.0 is identified as malicious. Although no install-time hooks or direct credential exfiltration mechanisms were observed in the scanned files, the package is considered fully compromising to any system where it is installed or running. Immediate removal of the package and rotation of all secrets and keys from a different, trusted system is strongly advised. There is no guarantee that removing the package will eliminate all malicious software introduced by its installation. Join the discussion | GCVE Database | 08/06/2026, 18:06:12 UTC Added: 08/07/2026, 15:17:37 UTC |
Malicious code in svelte-visual-map (npm) 0 The npm package svelte-visual-map version 1.0.0 contains malicious code. Installation or execution of this package can lead to a full compromise of the affected system. Secrets and keys stored on the compromised system should be rotated immediately from a separate, secure machine. Removal of the package alone may not fully remediate the compromise due to potential additional malicious software installed. Join the discussion | GCVE Database | 08/06/2026, 17:40:22 UTC Added: 08/07/2026, 15:17:37 UTC |
Malicious code in flasq (PyPI) 0 The PyPI package 'flasq' is a malicious typosquatting artifact that impersonates the popular 'requests' library by using a similar name 'requestss'. During installation, it executes obfuscated code that downloads a binary from an unrelated GitHub account, saves it to /tmp, makes it executable, and runs it detached. This binary is reported to exfiltrate cryptocurrency wallet data and potentially other sensitive information. The malicious behavior is unrelated to the advertised functionality of HTTP client utilities. The affected versions are 0.1.1, 0.1.2, 0.2.0, and 0.3.0. Join the discussion | GCVE Database | 08/07/2026, 07:01:59 UTC Added: 08/07/2026, 15:17:37 UTC |
Malicious code in dolyame-ui-buttonstore (npm) 0 The npm package dolyame-ui-buttonstore version 35.8.1 is identified as a malicious dropper. It loads a setup script that dynamically constructs URLs to fetch and execute opaque binary payloads from multiple evasive hosts. The payload is saved to hidden temporary files with execution permissions and launched detached from the parent process. If HTTPS fetching fails, a DNS TXT record fallback mechanism reconstructs a base64 payload from subdomains. The package masquerades as a legitimate TypeScript definitions library but contains only the dropper and a telemetry script. The author field is empty, and the runtime behavior indicates intentional evasion techniques. Join the discussion | GCVE Database | 08/07/2026, 12:27:20 UTC Added: 08/07/2026, 15:17:36 UTC |
Malicious code in dolyame-ui-inputrange (npm) 0 The npm package dolyame-ui-inputrange version 35.8.1 contains malicious code that downloads and executes a platform-specific binary from obfuscated Cloudflare Workers hostnames and a DNS-TXT fallback domain. The binary is saved under disguised filenames in temporary directories with executable permissions and launched detached from the main process. The package also includes a telemetry module that uses similar techniques to persist execution under the guise of an Analytics SDK. The code employs runtime string reassembly and environment variable gates to evade static analysis and hide repeated executions. Join the discussion | GCVE Database | 08/07/2026, 12:28:43 UTC Added: 08/07/2026, 15:17:36 UTC |
Showing 1 to 10 of 397 results