Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.
Researchers at Truffle Security reported that after four years of collecting leaked Amazon Web Services keys, they found 768 that still grant full control over a company's cloud account, with a median age of about five years. The keys were exposed in places like public code and configuration and were never rotated, so they remain live long after the people who created them have likely forgotten them. A single valid key with broad permissions can let an attacker read data, spin up resources, and move through a cloud environment. The finding is a reminder that leaked long-lived credentials remain one of the most durable and overlooked paths into cloud accounts.
Attackers briefly poisoned arrayref, a foundational Rust crate with about 245 million downloads that sits underneath widely used graphics and blockchain libraries, along with two sibling crates from the same maintainer account. The crate code itself was clean; each added a dependency on a typosquat of a popular package whose build script ran during compilation, pulling and executing an infostealer that grabbed host data and browser credentials. Because the malicious code lived in a build script, simply compiling a project that resolved the crate ran it, with nothing from the library needing to be called. The bad versions were pulled within about ninety minutes, but any build during that window was exposed.
Researchers at Socket found 40 malicious Firefox extensions, part of a wider set of 77, that impersonate cryptocurrency wallets like OKX, Rabby, and TronLink to steal users' funds. Dubbed the Offside Wallet Theft Factory and active since March, the campaign uses lookalike names with subtle character swaps, cloned wallet code, and reused extension identities. Some variants capture recovery phrases as a user sets up or imports a wallet; others copy the wallet's keyring before it is encrypted locally, so on-device encryption offers no protection. Stolen data goes out through Cloudflare Workers, attacker databases, and hardcoded servers. Removing an extension after theft does not secure the wallet, so victims must move funds.
Varonis disclosed a flaw in Microsoft Copilot Personal, the consumer assistant, that could let a single click exfiltrate data from connected apps, and the way they found it is striking. Tracked as CVE-2026-24301 and named CoSnitch, the technique had the researchers repeatedly ask Copilot why a prompt could not run without user interaction; each refusal added a technical justification, until the assistant named a hidden parameter, the exact session conditions where it worked, and the protections meant to block it. Building the request as described, the bypass ran. Varonis said Copilot was not breached but played. Related research showed attacker pages persisting unwanted memory in Copilot through indirect prompt injection.
Researchers, including teams at Anthropic and EPFL, demonstrated that self-propagating instructions can spread from one AI agent to another through the editable prompt and state files that autonomous agent harnesses use to carry context between sessions. In simulated multi-agent coding setups, a payload written into a shared file could infect the next agent that read it. The researchers call the risk real but currently limited, noting there is no sign of it spreading in the wild and that compromising one agent usually already grants machine access. Encouragingly, adding a single short warning paragraph to an agent's system prompt cut propagation to nearly zero across the payloads they tested.
Researchers flagged a typosquatting campaign, tracked as StubMaker, that planted sixteen malicious packages on RubyGems to deliver a Windows information stealer. The packages imitate popular Ruby dependencies with clumsy misspellings, betting that a developer will mistype a name during installation. Once installed, the malware harvests browser credentials, cryptocurrency wallets and seed phrases, and Telegram data from the developer's machine. The campaign's name refers to its trick of faking a build toolchain so a malicious install looks like a routine one. It is the latest reminder that open-source package registries remain an easy delivery route for stealers aimed at developers.
Researchers at Wiz found that a public Snowflake code repository could be hijacked through nothing more than a crafted GitHub issue title. A workflow that ran when issues were opened dropped the attacker-controlled title straight into a command, so an unauthenticated user could run code on the GitHub Actions runner and steal a Jira API token used by the automation. The notable twist is how the bug arrived: it was introduced days earlier by an AI tool meant to fix security issues, and an AI code reviewer approved the change. Snowflake fixed it by passing the title safely as an argument rather than expanding it into a command.
A new Mirai-based modular Linux botnet called Evooo1Bot is compromising internet-facing gateway devices and turning them into traffic relay nodes. Once installed, it runs a SOCKS5 proxy on the infected device, letting the operators route their own traffic through the victim's connection to hide the true origin of other activity. Building on the widely reused Mirai code base and a modular design, it targets the kind of routers and gateways that sit exposed at the network edge, often running outdated firmware and weak credentials. Relay botnets like this quietly monetize compromised devices and complicate attribution for whatever traffic passes through them.
Jamf detailed a new macOS information stealer, AmnesiaStealer, spread through ClickFix lures that trick users into running a command from a fake download page. Beyond harvesting the login password, keychain, browser data, and cryptocurrency wallets, it includes a module that clones the victim's Chromium browser profile, including its logged-in state, into a hidden browser on the infected Mac and gives the attacker live remote control of it through the browser's debugging protocol. Because the session runs on the victim's own device with their real identifiers, this lets the attacker use authenticated accounts while sidestepping multi-factor authentication. Jamf calls it the first macOS malware to combine profile cloning with live remote browser control.