The Trusted Download Is the Attack Vector

CPUID's official site served a malicious installer for hours. A fake WakaTime extension has been spreading across dev machines for months. Two separate campaigns, one shared trick: they got inside the thing you already trusted.

Read More

This Malware Hides Its Command Server in the Blockchain, and Borrows Google Calendar Too

GlassWorm targets developers through compromised npm, PyPI, and GitHub packages. Its C2 address is hidden in a Solana blockchain memo. You can't take down a blockchain transaction.

Read More

GlassWorm Is Hiding Malware in Invisible Code and Pushing It Into Your Python Repos

GlassWorm steals GitHub tokens, then injects malicious code written in invisible Unicode characters into repos developers already trust. 151 packages hit in one week.

Read More