#credential


Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

Jun 9, 2026 // 14:07

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the […]

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

May 23, 2026 // 12:58

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing […]

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

May 19, 2026 // 10:54

Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The […]

Avada Builder WordPress plugin flaws allow site credential theft

May 15, 2026 // 19:16

Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive […]

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

May 7, 2026 // 20:49

Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP […]

Backdoored PyTorch Lightning package drops credential stealer

May 4, 2026 // 20:36

A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a credential-stealing payload targeting browsers, environment files, and cloud […]

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

May 1, 2026 // 12:52

A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, […]

DORA and operational resilience: Credential management as a financial risk control

Apr 24, 2026 // 19:18

Author: Eirik Salmi, System Analyst at Passwork When a threat actor walks into your network using a legitimate username and password, which control stops them? […]

Automated credential theft exploits targeting React2Shell vulnerability.

Apr 5, 2026 // 17:37

A widespread hacking campaign is underway, utilizing automation to pilfer login details by exploiting a React2Shell vulnerability (CVE-2025-55182) in susceptible Next.js applications. Compromised systems, numbering […]

33 Brazilian Banks Targeted by New Rust-Based VENON Credential Stealer

Mar 12, 2026 // 22:48

Cybersecurity researchers from the Brazilian firm ZenoX have disclosed details of a new banking malware codenamed VENON that targets users of 33 financial institutions in Brazil.  Key Technical […]