Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > malware
#malware

Popular npm Package With Nearly 2 Million Weekly Downloads Hid Malware That Talks to Attackers Through Ethereum

22 September 2026  |  dark6  |  Malware

Researchers at Checkmarx uncovered a supply-chain campaign hiding inside a widely used npm package that impersonates a legitimate data-structure library. Rather than infecting machines at install time, the...

>> read more

New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools

22 August 2026  |  dark6  |  Malware

Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels...

>> read more

Researchers Show How Malware Can Hijack Windows Hello Keys to Slip Into Microsoft Entra ID

9 August 2026  |  dark6  |  Malware

New research demonstrates that malware running inside an active, unlocked Windows session can abuse Windows Hello for Business cryptographic keys to authenticate to Microsoft Entra ID, without ever...

>> read more

ChainDrop Worm Spreads Through 400+ npm Packages, Raiding Developer and Cloud Credentials

9 August 2026  |  dark6  |  Malware

A self-propagating worm dubbed ChainDrop has infected more than 400 npm packages by hijacking trusted publishing accounts, quietly harvesting npm, GitHub, cloud, and SSH credentials from developer machines...

>> read more

The Gentlemen Ransomware Uses a Malicious Kernel Driver to Blind Security Tools Before Striking

4 August 2026  |  dark6  |  Ransomware

A ransomware operation dubbed The Gentlemen is using a custom kernel-level driver to silently kill nearly 180 security processes before it starts encrypting files. Researchers say the driver...

>> read more

North Korean Hackers Hide Malware Instructions Inside Ethereum Smart Contracts to Drain Crypto Wallets

4 August 2026  |  dark6  |  Malware

A North Korean-linked campaign is using fake macOS update screens to trick victims into pasting a malicious command into Terminal, kicking off an infection chain that hunts for...

>> read more

New ‘Pass-ta-key’ Attacks Show How Malware Can Silently Hijack Google’s Synced Passkeys

4 August 2026  |  dark6  |  Malware

Unit 42 researchers have detailed three escalating attack techniques that let malware already on a Windows PC take over Google-synced passkeys without ever triggering a password, PIN, or...

>> read more

Malicious ClawHub Skills Compromise AI Agents With Hidden Backdoors — 247,000 Installs, $2.3M Stolen

30 June 2026  |  dark6  |  Malware

Researchers scanning 50,000 ClawHub skills — the official marketplace for the OpenClaw AI agent platform — found working remote control backdoors, credential stealers, and autonomous malware that installs...

>> read more