blank landing page header
On Demand Webinar

When Worms (and Phish) Attack

Threat Research Round-Up Q3 2025

Recent research highlights how attackers are exploiting the interconnected nature of modern development environments to launch stealthy and highly effective supply chain intrusions.

Watch our latest Research Round-Up webinar as we dissect five campaigns investigated by ReversingLabs since June. They are:

  • The Shai Hulud worm, which propagates through DevOps pipelines by abusing build automation and artifact distribution.
  • Malicious Ethereum smart contracts embedding obfuscated logic designed to trigger hidden behaviors post-deployment.
  • A weaponized pull request that introduced a backdoor into a Visual Studio Code extension.
  • The ESLint compromise, where attackers compromised eslint-config-prettier - an npm package with more than 3.5 billion downloads and 12,000 dependencies, using it to inject persistent malware into developer systems.
  • Malware families masquerading as legitimate VS Code extensions to evade detection and hijack developer workflows.
  • ReversingLabs researchers Karlo Zanki and Lucija Valentić will analyze attacker tradecraft—including social engineering against open-source maintainers, tampering with package registries, and abuse of developer trust in familiar tools.

    Learn how these campaigns unfolded, what signals defenders should monitor in CI/CD pipelines and IDE ecosystems, and actionable measures to harden their own supply chain security posture.

    Watch Now!

    Spectra Assure Free Trial

    Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

    Get Free TrialMore about Spectra Assure Free Trial
    Blog
    Events
    About Us
    Webinars
    In the News
    Careers
    Demo Videos
    Cybersecurity Glossary
    Contact Us
    reversinglabsReversingLabs: Home
    Privacy PolicyCookiesImpressum
    All rights reserved ReversingLabs © 2026
    XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
    Back to Top
    ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
    Skip to main content
    Contact UsSupportLoginBlogCommunity
    reversinglabs
    ReversingLabs: Home
    Solutions
    Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
    Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
    Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
    Products & Technology
    Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
    Spectra CoreIntegrations
    Industry
    Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
    Partners
    Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
    Alliances
    Resources
    BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
    Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
    Company
    About UsLeadershipCareersSeries B Investment
    EventsRL at RSAC
    Press ReleasesIn the News
    Pricing
    Software Supply Chain SecurityMalware Analysis and Threat Hunting
    Request a demo
    Menu
    Watch Now