-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

Malware | Breaking Cybersecurity News | The Hacker News

Category — Malware
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

Oct 08, 2026 Artificial Intelligence / Cloud Security
The npm package known as " tensorlake ," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said . Version 0.5.144 is no longer available for download from the npm package registry. An analysis of the compromised release shows that it contains a preinstall hook designed to launch a JavaScript file ("package/lib/setup.mjs"), an obfuscated loader that launches the main credential-stealing and self-propagating worm ("package/lib/Math_Symbol.js") using the Bun runtime. The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources. It also drops the HackBrowserData binary, exfiltrate...
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Oct 07, 2026 Supply Chain / Malware
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx . The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious. The attack is designed to infect Windows systems through three separate pathways - A loader for Overlord , an open-source RAT written in Go that uses Solana transactions to extract the command-and-control (C2) address A chain that installs movinlike, a Node.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets, and A downloader The list of identified malicious packages is below - tlxbnhd tldriver mxdriver img-to-native native-runner function-flag (Still live) function-color (Still live) cdn-img-fet...
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet

Oct 07, 2026 Botnet / Cryptojacking
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet. The financially motivated campaign, dubbed Canto Incognito , has been found to install cryptocurrency miners, including XMRig and Iron, and connects victims to Kryptex, a Russian cryptocurrency mining service. "Compromised hosts are reused to expand the botnet," Lumen Black Lotus Labs said in a report shared with The Hacker News. "Infected servers are turned into scanners and exploit servers, allowing the actor to find and compromise additional vulnerable systems." The malware distributed as part of the campaign has been codenamed PoeLLM owing to what has been described as a "creative" technique that hides the command-and-control (C2) address within a poem the threat actors wr...
cyber security

New Priorities for Critical Infrastructure: A Nation-State Threat Roundtable

websiteSANSCritical Infrastructure / Cybersecurity
Experts from SANS Institute, FirstEnergy, MITRE and Dragos unpack what leaders should prioritize next.
cyber security

AI adoption is outpacing IT visibility

website1PasswordSaaS Security / AI Governance
Individual dashboards only show part of the story. Learn how IT can get a unified view of AI spend and usage.
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Oct 07, 2026 Cybercrime / Network Security
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat actors to harvest and crack authentication data at scale," the agencies said . "Initial findings indicate attackers are continuing to scan internet-exposed Fortinet firewalls using previously obtained compromised credentials." FortiBleed was first documented by SOCRadar in Hudson Rock in June 2026, with the activity targeting thousands of Fortinet firewalls as part of a global campaign. In all, the Russian-speaking operation is estimated to have netted more than 86,644 working device credentials spanning 194 countries as of June 19, 2026. The campaign subsequently pro...
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer

Oct 07, 2026 Malware / Web Security
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer). The activity, which was observed by the agency in September 2026, has been attributed to a threat cluster dubbed UAC-0277. It did not disclose who the victims of the campaign were or if any systems were successfully compromised as a result of these attacks. "When visiting such a site, users were shown a forged Cloudflare verification page that, under the pretext of confirming the visitor is human, prompted them to execute a command," CERT-UA said in an advisory. "Executing the command caused a malicious MSI package to be downloaded and installed from a remote server (the ClickFix technique)." The attacks also make use of the EtherHiding technique to retrieve the domain name of the resource from which the fake verif...
⚡ Top Stories This Week
Expert Insights Articles Videos
Cybersecurity Resources