BleepingComputer reports that 88 malicious npm packages impersonating Babel, GraphQL Codegen, and other established projects have facilitated data theft from JavaScript developers as part of three new waves of the PhantomRaven attack campaign from November 2025 to February 2026.
Android users in Brazil have been targeted with the new BeatBanker malware, which is distributed in the form of a fake Starlink app on bogus Google Play Store sites and features both banking trojan and cryptocurrency mining capabilities, reports BleepingComputer.
KadNap operates as a peer-to-peer network, utilizing a custom version of the Kademlia Distributed Hash Table (DHT) protocol to communicate with its command-and-control (C2) infrastructure.
Newly emergent Linux malware ClipXDaemon could facilitate the clandestine takeover of cryptocurrency clipboard data in X11 sessions, resulting in the real-time replacement of copied cryptowallet addresses with attacker-controlled addresses without the need for command-and-control infrastructure, reports The Cyber Express.
Novel A0Backdoor spread in Teams phishing operation Intrusions involving the new A0Backdoor malware have been targeted at financial and healthcare entities as part of a new phishing campaign exploiting Microsoft Teams, according to BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.