
Inside the fake crypto developer recruitment hack
Here’s a more-in-depth technical analysis of the packages involved in the "graphalgo" campaign.

Here’s a more-in-depth technical analysis of the packages involved in the "graphalgo" campaign.

A new branch of a fake job recruitment campaign, dubbed "graphalgo," is targeting developers with a RAT.

By combining early infrastructure detection with supply chain security controls you can give your defenders a leg up.

This RL Researcher’s Notebook highlights the packer’s evolution — and offers a YARA rule to detect all versions.

Highlighting an alarming trend, RL has discovered malicious packages targeting crypto wallets and OAuth tokens to steal funds.

RL researchers have identified 19 malicious extensions on the VS Code Marketplace — the majority containing a malicious file posing as a PNG.

Shai-hulud 2.0 malware has spread to 795 npm packages — and been downloaded more than 100M times.

Proving the road to takeover is paved with setuptools alternatives, the script for a popular Python package for building and installing PyPI packages leaves them vulnerable.

PowerShell Gallery’s Install-Module command presents one key link in the kill chain of a possible attack.

RL's analysis of an STD Group-operated RAT yielded file indicators to better detect the malware and two YARA rules.

RL researchers detected the first self-replicating worm that compromised npm packages with cloud token-stealing malware. Here's what you need to know.

RL discovered how the crypto contracts were abused — and how this incident is tied to a larger campaign to promote malicious packages on top repositories.

RL has discovered a loophole on VS Code Marketplace that allows threat actors to reuse legitimate, removed package names for malicious purposes.

The eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.

ETHcode, a VS Code extension for Ethereum smart contract development, was compromised following a GitHub pull request.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial