Malicious npm package mimicking CryptoJS targets cryptocurrency wallets Cybersecurity researchers at Sonatype have identified a harmful npm package named "crypto-encrypt-ts" designed to impersonate the legitimate but unmaintained CryptoJS library to exfiltrate cryptocurrency and sensitive user data, according to HackRead.
Security researchers at Wordfence have identified a new, sophisticated malware strain masquerading as a legitimate WordPress security plugin, according to a report by Cybersecurity News.
The U.S. and other NATO members countries' critical infrastructure, government, and defense organizations have been targeted by Russian cyberespionage operation Nebulous Mantis, also known as Storm-0978, UNC2596, Cuba, and Tropical Scorpius, multi-stage intrusions deploying the RomCom malware since mid-2022, reports Security Affairs.
Telecommunications, energy, finance, media, biotechnology, and tourism organizations across Russia have been subjected to attacks involving a new DarkWatchman malware version as part of a Hive0117 phishing campaign that is believed to not have any association with the ongoing Russia-Ukraine war, according to The Record, a news site by cybersecurity firm Recorded Future.
Attacks involving a Windows-based surveillance malware have been launched against multiple senior members of the World Uyghur Congress as part of a new spear-phishing campaign discovered in early March, The Hacker News reports.
Novel Gremlin Stealer malware emerges Data theft could be conducted by threat actors through the novel Gremlin Stealer malware, which has been promoted through the CoderSharp Telegram channel since mid-March, reports Infosecurity Magazine.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.