Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
The ClickFix campaign has compromised 31 organizations by leveraging the Polygon blockchain as an infrastructure tool, specifically using EtherHiding to dynamically update command-and-control servers. By abusing the blockchain as an attacker-controlled address book, the threat actors can maintain persistent communication channels that are difficult to disrupt through traditional takedown methods.
Iranian threat actor Nimbus Manticore has been observed impersonating recruiters to distribute previously undocumented cross-platform remote access trojans targeting Linux and macOS systems alongside Windows infrastructure. The malware families, developed using Node.js and JavaScript, represent an expansion of the group's toolset and delivery tactics, leveraging fake coding assessments as a social engineering vector. This campaign demonstrates the actor's effort to broaden its operational capabilities across multiple operating systems.
Iranian cyber spies have deployed a new malware called NodeRabbit targeting aviation and fintech developers, according to Kaspersky's latest report. The threat actor first deployed the malware on a system in Afghanistan, with subsequent variants identified in Egypt and Ethiopia.
A malicious GitHub repository impersonating Anthropic distributes RevStealer, a Windows information-stealing malware that targets passwords, cryptocurrency wallets, and login credentials while operating stealthily. The campaign exploits social engineering tactics, luring victims with promises of free access to a non-existent "Claude Opus 5" application. RevStealer is designed to execute quietly while harvesting sensitive user data.