ReversingLabs

Malicious npm campaign targets developers integrating Twilio

The volume of malware on public repositories hasn’t decreased. ReversingLabs (RL) has never seen more malicious packages published on public repositories, and the overall count of malicious software is steadily rising. Looking at the metrics, npm saw around 5308 unique malicious packages published in 2024 (excluding spam). By August of this year, the number of malicious npm packages reached 5723, exceeding the total for all of 2024 in just eight months. And the number of malicious packages cont

Read More
ReversingLabs

What RL Found Before Anthropic’s Midnight Blizzard Report

Anthropic’s September report revealed that a Russia-linked threat actor was rebuilding flagged software implants with AI, making it hard to detect.However, ReversingLabs (RL) flagged the rebuilt malware two months before Anthropic did. And our data on the same malware shows that, while impressive, such AI powered tactics are not decisive. Instead, threat context behaviors and history are more critical than ever in spotting malware and improving the outcomes for targeted organizations.Here’s the

Read More
Krebs

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion groupShinyHuntershas been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle “Rey,” was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace companyBoeing, which manufactures the fleet of planes used by the employer of Rey’s fat

Read More
ReversingLabs

CRA compliance will be judged by the binary you ship

Many organizations still talk about the EU Cyber Resilience Act (CRA) as a 2027 problem. It stopped being one on Sept. 11, 2026. Since that date, manufacturers must report actively exploited vulnerabilities and severe incidents in products already on the EU market, legacy releases included. Full applicationfollows on Dec. 11, 2027, when every new product must meet the Annex I essential requirements, carry technical documentation, and bear the CE mark.Most CRA programs are being built from polici

Read More
ReversingLabs

Dependency installation security measure already defeated on npm

Key takeawaysnpm’s July fix has already been bypassed.Version 12 stopped running install scripts by default, but the malicious indexed-btree package hides its trigger in a prototype method. The malware runs when the app uses the library, not when it’s installed.A clean package.json is no longer a trust signal.Having no install hooks gave reviewers false comfort. This campaign targets that blind spot, and it backs the package with a fake GitHub repo and developer profile.Install-time checks aren’

Read More
Krebs

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud providerSnowflake.Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.A surveillance photo of Connor Riley Moucka, a.k.a. “Judische” and “Waifu,” dated Oct 21, 2024, 9 days before Mouck

Read More
Krebs

Microsoft Plugs Nearly 400 Security Holes

Microsofttoday released updates to remedy at least 398 security vulnerabilities in itsWindowsoperating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.Image: Shutterstock, Mallika Home Studio.August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release ofmore than 570 security updates last month, but it is double June’s then-record batch ofnearly 200

Read More
Krebs

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service calledDecryptAdsscrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that a

Read More