LiteLLM Breach May Have Exposed 2,500+ Organizations
CloudSEK maps 2,500+ organizations in a LiteLLM exposure dataset. Check versions 1.82.7…
BdThemes Plugins Installed Backdoors Through a Poisoned API
Seven BdThemes WordPress plugins loaded a poisoned remote feed that created rogue…
Solidity Pro VS Code Extensions Steal Wallets and API Keys
Malicious Solidity Pro extensions stole wallet data, API keys, SSH keys, and…
NUL1DROPPER npm Malware Runs When a Package Is Imported
NUL1DROPPER runs when poisoned npm packages are imported, not through install scripts.…
QuickFox VPN Malware Installed the FDMTP Backdoor
QuickFox Windows installers delivered the FDMTP backdoor. Check affected versions, local indicators,…
Keyv npm Worm Poisoned 444 Packages: Check Before Rotating Tokens
The Keyv npm worm poisoned hundreds of packages and can react when…
Arch Freezes AUR Pushes After Malware Wave: Check Your System
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure,…
Adform Script Swapped Crypto Wallet Addresses on Websites
A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron recipient…
SvcHostUpdate.exe in Startup: The MythicalsGames Backdoor
SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the…
Joyfill npm Packages Compromised: Six Malicious Versions
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and…
Jscrambler npm Package Compromised: Check Five Malicious Versions
Five malicious Jscrambler npm releases ran a cross-platform infostealer. Check versions, lockfiles,…
OptinMonster CDN Backdoor Checks
WordPress sites using OptinMonster, TrustPulse, or PushEngage should check for rogue admin…
