WhisperX tag archive

#credential-theft

This page collects WhisperX intelligence signals tagged #credential-theft. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (9)

The Lab · 2026-03-31 08:27:10 · GitHub Issues

1. GitHub Action Compromise: Malicious Trivy v0.69.4 Release & Tag Hijack Exposes Supply Chain

A critical supply chain attack has compromised the official GitHub Actions for Trivy, a widely used open-source security scanner. On March 19, 2026, a threat actor used stolen credentials to publish a malicious version of Trivy (v0.69.4) and executed a sweeping hijack of the project's version history. The attacker forc...

The Lab · 2026-04-24 03:54:08 · GitHub Issues

2. Kyverno SSRF Flaw Exposes Multi-Tenant Kubernetes Environments to Cross-Tenant Credential Theft

A critical Server-Side Request Forgery (SSRF) vulnerability in Kyverno's APICall feature allows users with Policy creation permissions to pivot from low-privilege namespace access into high-value internal targets, effectively dismantling tenant isolation in shared Kubernetes clusters. Tracked as GHSA-fmqp-4wfc-w3v7 and...

The Lab · 2026-05-08 11:24:46 · SecurityWeek RSS

3. PCPJack Worm Emerges: Removes Rival TeamPCP Malware, Targets AWS, Docker, Kubernetes Environments

Security researchers have identified a new credential-stealing worm framework, designated PCPJack, which demonstrates an unusual dual-function capability: removing rival malware infections while simultaneously harvesting sensitive authentication data from cloud infrastructure. The malicious framework specifically targ...

The Vault · 2026-05-08 19:54:50 · The Hacker News Echo RSS

4. Brazilian Banking Trojan TCLBANKER Targets 59 Financial Platforms via WhatsApp and Outlook Worms

Security researchers at Elastic Security Labs have flagged a newly documented Brazilian banking trojan, tracked as TCLBANKER (REF3076), capable of targeting 59 banking, fintech, and cryptocurrency platforms. The malware represents what analysts describe as a major evolution of the Maverick trojan, incorporating sophist...

The Vault · 2026-05-09 04:31:44 · r/netsec

5. "AccountDumpling": Google-Sent Phishing Campaign Compromises 30,000+ Facebook Accounts, Researchers Warn

Security researchers have uncovered a large-scale phishing operation that exploited Google infrastructure to compromise more than 30,000 Facebook accounts, according to findings published by Guard.io's threat intelligence team. The campaign, dubbed "AccountDumpling," leveraged compromised Facebook business accounts to ...

The Vault · 2026-05-12 12:48:18 · BleepingComputer Echo RSS

6. Shai-Hulud Campaign Compromises Hundreds of npm and PyPI Packages with Credential-Stealing Malware

A sophisticated supply-chain attack campaign dubbed "Shai-Hulud" has compromised hundreds of packages across the npm and PyPI package registries, distributing credential-stealing malware directly into developer environments. The campaign represents a calculated targeting of the software development ecosystem, exploitin...

The Lab · 2026-05-12 19:18:29 · VentureBeat

7. npm Supply Chain Worm Harvests Developer Credentials, Persists After Package Removal

A sophisticated supply chain attack campaign has compromised 172 npm and PyPI packages since May 11, embedding a credential-harvesting worm that survives package removal on affected development workstations. Security researchers warn that any environment that installed or imported these packages should be treated as co...

The Lab · 2026-05-12 21:48:19 · Decrypt

8. Fake OpenAI Privacy Filter Clone Dominated Hugging Face Trend—Extracting Credentials in Plain Sight

A counterfeit repository impersonating OpenAI's Privacy Filter model overwhelmed Hugging Face's trending charts, accumulating 244,000 downloads in under 18 hours before platform moderators removed it. Security researchers who examined the malicious clone discovered it was designed to harvest user credentials, exploitin...

The Lab · 2026-05-14 01:18:24 · Mastodon:mastodon.social:#cybersecurity

9. TeamPCP Exploits CI/CD Pipelines: Checkmarx KICS and elementary-data Compromises Expose Credential Theft Campaign

Financially motivated threat actor TeamPCP is actively exploiting trusted software supply chain channels to harvest credentials at scale, with recent compromises of Checkmarx KICS and elementary-data projects demonstrating the campaign's reach and operational sophistication. The attack chain leverages CI/CD infrastruc...