Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: socket-dev Clear filter
Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages

1mo ago · socket-dev

The Miasma Mini Shai-Hulud supply chain campaign has expanded to compromise legitimate @immobiliarelabs npm packages, specifically Backstage plugins for GitLab and LDAP authentication. Malicious versions were published on June 26, 2026, using a hidden root-level index.js to execute a multi-stage payload that steals developer and CI/CD secrets, including tokens, SSH keys, and cloud credentials. The attack leverages GitHub Actions deployment triggers and may have originated from a compromised third-party GitHub Action, codfish/semantic-release-action, enabling further propagation through poisoned workflows and exfiltration to attacker-controlled repositories.

71 IoCs
Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates

1mo ago · socket-dev

Malicious Chrome and Firefox browser extensions branded as 'VPN Go: Free VPN' have been distributing clipboard-stealing malware through staged updates. Initially appearing as legitimate free VPN tools, the extensions later added functionality to monitor and exfiltrate clipboard data, including passwords, API keys, and cryptocurrency addresses. The stolen data is sent to hardcoded IP addresses using HTTP GET requests with chunked encoding and session identifiers. Both extensions use obfuscated JavaScript and share infrastructure, indicating a coordinated campaign targeting user privacy under the guise of security.

11 IoCs
Risky Biz Podcast: AI Agents Are Raising the Stakes for Software Supply Chain Security

1mo ago · socket-dev

The article discusses a surge in software supply chain attacks, where threat actors compromise popular open source packages and leverage trusted development workflows to distribute malicious code. The rise of AI coding agents exacerbates the risk by automatically pulling in dependencies without sufficient review, increasing the speed and scale of potential compromise. Attackers are targeting development tools such as package registries, IDE extensions, and source repositories, often evading traditional security measures.

← Previous