Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 48 threats
This weekly recap covers multiple active threats including a Chrome 0-day, router hijacking campaigns, and a notable supply chain attack against the Coder platform that resulted in credential theft. Attackers also demonstrated a novel phishing technique using text-rendered QR codes to bypass email image-blocking protections, and abused a network management protocol for malicious purposes.
Unidentified threat actors exploited a recently disclosed critical vulnerability in JetBrains TeamCity to breach JetBrains' own environment, compromising its Cadence CI/CD service. JetBrains has urged all Cadence users to immediately revoke and rotate credentials and secrets used in their Cadence executions, indicating potential exposure of customer AWS credentials and other secrets.
Attackers gained unauthorized access to Coder's Cloudflare-hosted registry infrastructure and inserted rogue registry servers distributing trojanized Terraform modules. These malicious modules contained credential-stealing code, potentially exposing secrets and cloud credentials for any environment that pulled infrastructure definitions from the compromised registry.
Researchers discovered 13 malicious Composer theme packages on Packagist designed to inject JavaScript into Vietnamese movie and comic streaming sites. The injected code performs mobile ad-fraud and gambling-redirect operations and deploys spyware targeting unpatched iOS devices visiting the compromised sites.
A critical flaw in @hulumi/policies before version 1.3.2 allows attackers to craft AWS IAM condition operators (ForAnyValue:StringLike) that evade security guardrails designed to detect overly permissive GitHub Actions OIDC trust policies. This enables attackers to establish stealthy, wildcard-based trust relationships between arbitrary GitHub repositories/workflows and AWS IAM roles, potentially leading to unauthorized cross-account access.
Researchers identified 19 malicious Chrome and Edge extensions published over the past six months that steal cryptocurrency wallet secrets and drain funds. The extensions share common code and tradecraft, suggesting a coordinated campaign distributed through official browser extension stores. This poses a broad supply-chain risk to any user or organization installing these extensions.
Multiple malicious extensions distributed through the Chrome Web Store and Microsoft Edge Add-ons store delivered a modular malware framework capable of stealing cryptocurrency, browsing history, and other sensitive data. The campaign also deployed ClickFix-style social engineering lures to trick users into executing further malicious commands, expanding the attack's reach beyond simple browser compromise.
Australian Federal Police arrested two suspects believed to be members of TeamPCP, a cybercrime group linked to what is described as the longest-running spree of software supply chain attacks via malicious open-source packages. The group allegedly compromised thousands of global businesses by distributing trojanized open-source software components. While this report covers the law enforcement action, the underlying threat—malicious open-source packages—remains a systemic risk to any organization consuming public package repositories.
Nokogiri versions before 1.13.2 for CRuby ship vulnerable vendored copies of libxml2 2.9.12 and libxslt 1.1.34, exposing applications to denial-of-service, memory disclosure, and potential remote code execution when processing untrusted XML/XSL input. This is a widely-used Ruby gem for XML/HTML parsing, meaning the vulnerability propagates transitively into any application, service, or pipeline that depends on it.
GitPython versions before 3.1.59 mishandle multi-line git-config values during write operations, allowing crafted config entries with embedded newlines to be corrupted into live directives such as core.hooksPath. This enables an attacker who can influence a repository's config file to achieve arbitrary code execution the next time any unrelated GitPython write operation touches that config, with a critical CVSS score of 9.8.
A critical prototype pollution vulnerability exists in exceljs-hardened versions prior to 5.0.0, where the deepMerge helper fails to sanitize dangerous keys (__proto__, constructor, prototype) when merging cell note objects. Attackers can craft malicious spreadsheet or JSON input to pollute Object.prototype, potentially leading to remote code execution, denial of service, or security bypass in downstream application logic.
Attackers compromised a legitimate Android device-update application distributed with car head units, using it to deliver malware that enrolls devices into a proxy botnet and conducts ad fraud. This supply-chain compromise leverages a trusted update mechanism to gain persistent access to a large, distributed fleet of embedded automotive devices.
Researchers identified 14 trojanized npm packages disguised as calendar and streak-tracking utilities that covertly deploy an AI-powered Linux backdoor called RedC2 4.0. The malware extracts and executes a bundled binary as a detached background process, giving attackers persistent, AI-assisted command-and-control capability on infected hosts.
A compromised maintainer account was used to publish malicious versions of three popular Rust crates (arrayref, internment, append-only-vec), collectively downloaded over 245 million times. The malicious releases introduced a typosquatted dependency whose build script downloaded and executed a remote payload at compile time, enabling arbitrary code execution on any system that built the affected packages.
Attackers compromised the maintainer account of the widely-used Rust crate 'arrayref' and published a malicious version that executes infostealer malware at compile time on developer systems. Any developer or CI/CD pipeline pulling the poisoned version would trigger malware execution during the build process, risking credential and secret theft.
Researchers at Wiz disclosed a GitHub Actions workflow injection vulnerability in Snowflake's public snowflake-connector-net repository, where a maliciously crafted GitHub issue could trigger command injection in a workflow that contained internal Jira credentials. Successful exploitation could allow an attacker to exfiltrate secrets and potentially compromise the CI/CD pipeline of a widely used Snowflake connector library.
Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.
A tampered build of Ninja Tables Pro 5.2.11 was distributed through a decommissioned update server, embedding a malicious PHP updater component that grants attackers persistent backdoor access. The compromised plugin creates a passwordless admin account, drops web shells in mu-plugins and uploads directories, and registers scheduled tasks that survive plugin removal, making remediation difficult. Organizations running affected WordPress instances face full site takeover risk, including any hosted applications, APIs, or backend services running on the same host.
A tampered build of Fluent Forms Pro 6.2.7 distributed via a decommissioned update server injects a malicious PHP file that installs a backdoor REST API endpoint, a passwordless administrator account, and persistent scheduled tasks. This constitutes a supply-chain compromise capable of full site takeover, with persistence mechanisms designed to survive plugin removal.
A threat actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin developer, and tampered with a remote JSON feed served to site administrators. This modified feed was used to silently create rogue administrator accounts on affected WordPress installations, granting attackers persistent backend access.