PyPI Package Hack Sent Malware to Millions
A top PyPI package with over 1 million monthly downloads was compromised via exploit, not stolen credentials, spreading malware to developers since April 2026. Details on the breach and fallout.
A top PyPI package with over 1 million monthly downloads was compromised via exploit, not stolen credentials, spreading malware to developers since April 2026. Details on the breach and fallout.
73 counterfeit VS Code extensions on Open VSX deliver GlassWorm v2 malware, targeting developers with stolen session tokens and credentials. Report published April 28, 2026.
UNC6692 deploys Snow malware via email bombing and social engineering. Attackers gain persistent access using Snowbelt, Snowglaze, and Snowbasin variants. Full analysis.
Fast16 malware hijacks legitimate Chrome extensions to steal credentials and bypass security. The attack abused trust mechanisms in the web ecosystem. A growing concern for developers and enterprises alike.
A threat actor uses Microsoft Teams to deploy the new Snow malware, bypassing traditional defenses with social engineering. The attack leverages trusted collaboration tools to install browser extensions, tunnelers, and backdoors. Details from BleepingComputer’s April 27, 2026 report.
Researchers uncover ‘fast16’ malware framework from 2006, predating Stuxnet by five years and reshaping the timeline of state-level cyber sabotage. Details from Dark Reading’s April 27, 2026 report.
In 2005, a Lua-based sabotage framework targeted engineering software—years before Stuxnet. SentinelOne’s discovery rewrites early cyberwarfare history. Details from April 27, 2026.