Graphalgo-linked malware hid in Terraform providers and Go packages, targeting developers and cloud infrastructure.
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server.
KREMLIN banking malware uses fake bank documents to steal passwords, cookies, and data from Chrome and Edge users in Brazil.
JSCeal can steal browser credentials, replay Google sessions using stolen cookies, and modify traffic for cryptocurrency services.