Live threat intelligence — updated continuously

Open Cyber Threat Intelligence

Structured, AI-extracted threat intel. Free with no login required.

Latest Intelligence

View all →
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack

8h ago · socket-dev

The npm package [email protected] was compromised in a supply chain attack linked to the ChainDrop/Shai-Hulud campaign, delivering a credential-stealing malware payload via a preinstall hook. The malicious code executes during installation, harvesting secrets from local files, CI environments, Kubernetes, Vault, and AI development tools, then exfiltrates them. The payload also establishes persistence using a 'hostage token' mechanism that triggers destructive actions if stolen tokens are revoked, and it propagates by republishing compromised npm packages under the victim's identity.
5 IoCs
Blinder Tunnel Campaign Targets Iraqi Infrastructure

2d ago · unit42

The Blinder Tunnel campaign, attributed to an Iranian state-aligned threat actor, targeted Iraqi critical infrastructure in March 2026 using a sophisticated social engineering lure impersonating Dubai Airports' IT department. The attack delivered trojanized Visual Studio projects that exploited .csproj files, AppDomainManager hijacking, and DLL sideloading to deploy custom malware including ShelbyLoader V2 and Blackwood, a Chisel-based tunneling tool. Command-and-control was conducted via GitHub repositories and issues, with fallback mechanisms using encrypted comments, while infrastructure reuse linked this activity to a parallel credential-harvesting campaign targeting Israel.
18 IoCs 2 Actors
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

11h ago · talos

Cisco Talos identified an APT spear-phishing campaign, tracked as UAT-11985, targeting Taiwan-based research organizations using AI-assisted content generation to create highly personalized and credible phishing emails. The campaign leveraged legitimate event themes and impersonated reputable academic institutions, embedding malicious QR codes in posters (quishing) and using deceptive hyperlinks that mimic legitimate Google Forms URLs to redirect victims to phishing pages. The phishing infrastructure employs a real-time adversary-in-the-middle (AitM) framework with a hybrid HTTP and WebSocket architecture to intercept Google credentials and bypass MFA by dynamically mirroring authentication flows. Technical analysis suggests the phishing kit was developed primarily in Simplified Chinese, indicating a developer with mainland Chinese linguistic patterns.
1 IoCs
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

15h ago · hacker-news

The npm package 'tensorlake' was compromised in a supply chain attack delivering a credential-stealing and self-propagating worm named Shai-Hulud. The malicious version 0.5.144 includes a preinstall hook that executes an obfuscated JavaScript loader, which deploys malware to harvest credentials from npm, GitHub, AWS, Kubernetes, Vault, SSH keys, and cryptocurrency wallets. The malware establishes persistence, exfiltrates data via GitHub repositories, uses Ethereum for C2 resolution, and can trigger destructive actions if stolen tokens are revoked. It also modifies project files in AI development environments to re-execute upon project access.
4 IoCs 1 Malware
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

13h ago · hacker-news

Zhang Yu, a Chinese national and director at Shanghai Firetech Information Science and Technology, is wanted by U.S. authorities for his alleged role in state-sponsored cyber espionage activities linked to the HAFNIUM campaign. He is charged in connection with the 2021 Microsoft Exchange Server attacks that exploited zero-day vulnerabilities, including ProxyLogon, to compromise over 12,700 U.S. organizations. The U.S. State Department is offering up to $10 million for information leading to his identification or location. Zhang allegedly coordinated hacking operations on behalf of China's Ministry of State Security, targeting U.S. universities involved in COVID-19 research and an international law firm, alongside co-conspirator Xu Zewei, who was extradited to the U.S. in April 2026.
1 Actors
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

11h ago · hacker-news

Security researchers identified 16 malicious Firefox extensions designed to impersonate legitimate cryptocurrency wallets, specifically Rabby and OKX Wallets. These extensions intercept and exfiltrate cryptocurrency wallet recovery phrases and private keys by sending them to attacker-controlled Cloudflare Workers domains. The extensions are part of an ongoing campaign that reuses infrastructure and code while rotating names and versions, indicating a persistent threat targeting cryptocurrency users.
17 IoCs
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

10h ago · hacker-news

Wazza is a newly identified phishing kit that targets banking, government, and manufacturing sectors across the US, EU, and Australia. It employs a multi-stage routing infrastructure to filter traffic and evade detection, only delivering the final Adobe-themed Device Code phishing page after validating session tokens and browser telemetry. This layered approach complicates automated analysis and increases investigation time for MSSPs, as the malicious behavior is hidden behind multiple redirects and access controls.
3 IoCs
ASOS links data breach to social engineering attack, credential theft

9h ago · bleeping-computer

ASOS confirmed a data breach resulting from a social engineering attack in which an attacker impersonated a trusted contact to steal an employee's login credentials. The compromised credentials were used to access third-party platforms used by ASOS, leading to the exposure of customers' full names, contact details, and certain non-personal account-related information. The threat actor, identifying itself as 'Xuanye Group,' sent malicious in-app notifications to users, but ASOS confirmed that payment card information and account passwords were not accessed.
1 IoCs
Tensorlake npm Package Compromised: A Worm With a Hostage Token That Wipes Your Machine If You Revoke It

18h ago · step-security

The npm package [email protected] has been compromised and functions as a malicious worm that steals credentials, including GitHub and npm tokens, cloud keys, SSH keys, and AI tool configurations. It spreads by modifying victim repositories with malicious .claude and .vscode files and republishing npm packages using stolen tokens. The malware includes a 'hostage token' mechanism: if the stolen GitHub token is revoked, a background monitor triggers deletion of the user's home directory via rm -rf ~/ or equivalent on Windows. The malicious code was pushed directly to the main branch of the tensorlakeai/tensorlake repository under a maintainer's name and published with a valid npm provenance attestation, making it appear legitimate.
6 IoCs
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

1d ago · hacker-news

A critical arbitrary file access vulnerability, CVE-2026-21589, in multiple Atlassian Data Center products is being actively exploited within hours of public disclosure. The flaw allows unauthenticated attackers to retrieve sensitive files from the webroot directory by exploiting path resolution logic in Atlassian's web-resource handling, requiring only knowledge of the target file's exact path. Exploitation attempts have already been observed from multiple IP addresses, with the potential to extract credentials and gain administrative access, particularly in Crowd and Jira instances. Immediate patching is advised as automated scanning via tools like Nuclei is expected to increase exploitation activity.
3 IoCs