Malware Analysis
In-depth supply-chain malware & package research from security blogs — last 90 days.
Source
- Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments.
- StepSecurity threat intelligence tracked 56 open source supply chain attacks from August 2025 to August 2026, roughly one every three days since March. See the data and the defenses.
- Three Rust crates are compromised: arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 each added a typosquatted build-time dependency (proc-macro1, proc-macro-en) whose build script downloads and runs a remote binary during cargo build. Full technical analysis: timeline, dropper dissection, runtime detection, IOCs, and remediation.
- Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.
- Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
- ChainDrop npm worm: 444 packages and 2,212 versions poisoned, starting with [email protected]. Payload analysis, affected package list, IOCs, and remediation steps.
- Team PCP exfiltrated 78,330 secrets from 2,186 organizations via CI/CD pipelines. Analysis of the CloudSEK disclosure, why attackers target CI/CD, and how to defend.
- The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
- TL;DR Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901. The malware uses the same Ethereum wallet address identified by OpenSourceMalware in activity attributed to the DPRK-linked Contagious Interview campaign, usi
- TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed 'Flooding Dropper,' spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases in the 35.x.y range.
- TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version sho
- Engineering organizations deploy dependency scanners, train developers, secure endpoints, and establish policies for open source components. Yet malicious packages still reach developer workstations, build systems, and CI/CD environments.
- An AI agent published a malicious package to PyPI and 15 systems ran it within an hour. What Anthropic's incident means for supply chain security.
- Malicious beta versions of the Joyfill npm packages @joyfill/components and @joyfill/layouts hide an obfuscated remote access trojan and credential stealer. Full analysis, IOCs, and remediation from StepSecurity.
- mrmustard 0.7.4 on PyPI was a credential stealer that ran on import, exfiltrating SSH keys, AWS, and Kubernetes credentials. Here is the analysis, IOCs, and how to respond.
1–15 of 43
Page/ 3