A trojanized NuGet package reportedly masqueraded as Newtonsoft.Json, stayed useful for ordinary .NET apps, and only turned hostile inside a betting backend where integrity mattered most.
A newly named phishing tactic turns hallucinated URLs into real infrastructure, giving criminals a fresh path to impersonate brands and stage malware delivery.
A malicious package campaign tied to Telegram bot development shows how a trusted Python repository can become the delivery layer for server-side compromise.
A Chromium extension posing as an AI search helper shows how browser trust can be bent with branding, redirect rules, and page-level scripting.
A compromised AI extension marketplace shows how trust, rankings, and package names can be turned into a delivery system for hostile code.
Three lookalike npm packages aimed at frontend developers underscore how package-name trust and installer-time execution can collide on a developer workstation.
A small cluster of PostCSS-themed npm packages shows how name confusion and install-time trust can turn routine dependency work into a Windows malware risk.
A typosquatted package in the npm ecosystem shows how a single confusing name can hand attackers a path from dependency install to Windows-native execution.
A deceptive package name in the PostCSS orbit shows how open-source trust can be abused before any code ever reaches production.
Typosquatted domains, AI-built lure pages, and a ClickFix prompt can turn a routine web visit into PowerShell execution and a banking trojan dropper.
More than 140 packages in the Mastra namespace were reported as part of a supply-chain compromise, with a typosquatting dependency, easy-day-js, used in a way that could fit install-time malware delivery.
Malicious lookalike packages in the npm ecosystem can turn routine dependency installs into a supply-chain execution event for Web3 teams and crypto wallet operators.
A Solana-themed package campaign shows how npm and PyPI installs can become a delivery route for code that runs before a developer ever opens the library.
Researchers warn that the tournament is already surrounded by thousands of malicious domains, turning a global sports moment into a high-value impersonation target.
As attention builds around the 2026 FIFA World Cup, spoofed sites, phishing lures, and fake storefronts are turning fan excitement into a ready-made fraud channel.
A two-hour showcase packed with more than 20 game announcements is a reminder that live entertainment events are also trust events, where speed can outpace verification.
A malicious project on Python’s main package index shows why trust in open-source software now starts with name verification, not just reputation.
A PyPI typosquat built to resemble the parsimonious parser library shows how easily trusted package names can be turned into bait for developers.
With the tournament window approaching, attackers are pairing typosquatted domains, cloned login pages, and deceptive streaming apps to turn fan excitement into credential theft and financial fraud.
A reported campaign tied to GHOST STADIUM used fraudulent web domains to mimic FIFA’s login experience and seek credentials and payment-related data, showing how brand trust becomes attack surface.