WhisperX tag archive

#credential theft

This page collects WhisperX intelligence signals tagged #credential theft. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (10)

The Lab · 2026-03-30 18:26:58 · The Register

1. PyPI Poisoning: Trivy Attackers Strike Again with Malicious Telnyx Package

The threat actors behind the recent Trivy supply-chain breach have escalated their campaign, now poisoning the Python Package Index (PyPI) with malicious versions of the Telnyx SDK. This latest attack aims to infect developers' systems with credential-stealing malware, marking a continued and aggressive exploitation of...

The Network · 2026-04-07 17:27:26 · Fancy Bear (APT28) / Russian GRU

2. Fancy Bear (APT28) Hijacks Thousands of Home Routers in Global Password Theft Campaign

Russian state-linked hackers have seized control of thousands of residential home routers worldwide, using them as a covert platform to steal passwords and authentication tokens. The operation, attributed to the group known as Fancy Bear or APT28, represents a significant escalation in cyber espionage tactics, moving b...

The Lab · 2026-04-10 13:22:38 · The Register

3. CPUID Website Hijacked: Legitimate HWMonitor Downloads Replaced with Malware

For six hours this week, the trusted CPUID website became a trap. Attackers hijacked a portion of its backend infrastructure, transforming legitimate download links for popular system monitoring tools like HWMonitor into a delivery mechanism for malware. Visitors seeking genuine software were instead exposed to a coin ...

The Network · 2026-04-13 18:52:56 · TechCrunch

4. FBI Takedown: W3LL Phishing Kit Targeted 17,000+ Global Victims, Stole Passwords & MFA Codes

The FBI has dismantled a sophisticated phishing operation that successfully compromised thousands of victims worldwide by stealing not just passwords, but also the multi-factor authentication (MFA) codes meant to protect them. This takedown highlights a critical escalation in credential theft, moving beyond simple pass...

The Lab · 2026-04-27 18:24:12 · Decrypt

5. Google Exposes Web Pages Hijacking AI Agents to Drain PayPal Accounts and Steal Credentials

Google's security team has uncovered a systematic campaign in which malicious web pages are weaponized to hijack AI agents, directing them to transfer funds, delete files, and transmit credentials to attacker-controlled infrastructure. The findings emerged from a scan of billions of web pages, revealing that threat act...

The Lab · 2026-04-30 10:54:11 · GitHub Issues

6. Critical Vulnerability in OpenClaw Skill Installer Exposes LLM API Keys to Stealth Theft

A critical security flaw in OpenClaw's third-party Skill marketplace allows malicious actors to execute arbitrary shell commands on a user's system during Skill installation — without any sandbox isolation, permission prompt, or code review. The vulnerability, classified as OWASP LLM Top 10: LLM03:2025 (Supply Chain Vu...

The Lab · 2026-04-30 17:24:11 · VentureBeat

7. AI Coding Assistants Face Credential-Theft Onslaught: Nine Months of Exploits Target Claude Code, Copilot, and Codex Authentication Layer

A coordinated string of security disclosures has exposed a systemic vulnerability across major AI coding assistants: attackers are consistently bypassing the models themselves and targeting the credentials these tools hold. Over nine months, six research teams documented exploits against Codex, Claude Code, Copilot, an...

The Lab · 2026-05-08 14:24:50 · The Hacker News Echo RSS

8. Quasar Linux RAT Emerges as Stealthy Threat Targeting Developer Credentials Across Software Supply Chain

A previously undocumented Linux implant dubbed Quasar Linux RAT (QLNX) has been discovered actively targeting developers' systems in what appears to be a calculated campaign against software supply chain infrastructure. The malware establishes a persistent, silent foothold on compromised machines before unleashing a su...

The Lab · 2026-05-10 14:01:51 · r/cybersecurity

9. CVE-2026-44843: LangChain Flaw Lets Single Chat Message Steal API Keys and Hijack AI Prompts

A single chat message is all it takes. CVE-2026-44843, a vulnerability in LangChain's framework, enables attackers to steal credentials and hijack AI application behavior through a malicious payload delivered via chat interface. The flaw resides in LangChain's tracer component, which deserializes untrusted data, granti...

The Lab · 2026-05-13 00:18:27 · CyberScoop RSS

10. Mini Shai-Hulud Malware Infiltrates Hundreds of Open-Source Packages, Including TanStack React Router

A sprawling supply-chain attack has embedded credential-stealing malware into hundreds of open-source software packages distributed through major registries, security researchers warned. The campaign, dubbed "mini Shai-Hulud," targets development tools with massive user bases, placing malicious code within reach of dev...