Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen
Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs...
LokiBot Returns: Multi-Stage JScript Campaign Uses Process Injection to Steal Credentials
LokiBot, the decade-old credential stealer, has resurfaced with a sophisticated multi-stage attack chain: a JScript email dropper, in-memory .NET injection, and process hollowing inside aspnet_compiler.exe to silently harvest...
Shai-Hulud Malware Expands to npm Ecosystem, Stealing Cloud and CI/CD Credentials From Developers
A credential-stealing malware campaign known as Shai-Hulud has expanded to target developers using the Leo/RStreams npm package ecosystem, harvesting GitHub tokens, cloud access keys, CI/CD secrets, and SSH...
Operation Endgame Strikes Again: Europol Seizes StealC, Amadey and SocGholish Infrastructure — 326 Servers Down, $47M Frozen
Europol's Operation Endgame has dismantled the infrastructure behind StealC, Amadey, and SocGholish malware, seizing 326 servers, freezing USD 47 million in crypto, and recovering 27 million stolen credentials....
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Covert Attack Proxy Network
Researchers have uncovered AryStinger, a stealthy botnet that has hijacked over 4,300 legacy Linksys and D-Link routers by exploiting decade-old vulnerabilities. Unlike DDoS botnets, AryStinger is purpose-built for...
International Authorities Dismantle SocGholish (FakeUpdates) Malware Network — 106 Servers and 101 Domains Seized
International law enforcement agencies from the US, Netherlands, Canada, and Germany have dismantled the SocGholish malware network under Operation Endgame, seizing 106 servers and 101 domains while remediating...
Supply Chain Attack Compromises 140+ Mastra npm Packages, Targeting Developer Credentials and Crypto Wallets
A sophisticated supply chain attack has compromised over 141 packages in the Mastra-AI npm ecosystem, including @mastra/core which sees 918,000 weekly downloads. Detected on June 17, 2026, the...
Chinese Hackers (UNC6508) Spent Over a Year Spying on US Medical Research Institutions via REDCap
Google GTIG has attributed a 2+ year Chinese cyber-espionage campaign to UNC6508, which exploited REDCap medical research servers across North America. The group deployed a novel modular malware...