'NoVoice' Android malware on Google Play infected 2.3 million devices

2026-04-01T19:23:28Z0e28e653b519eb3112c5eba775957911d24b6db243d3143c8a17100dae0d2de5
ai-leakandroid-malwareaxioschromeclaudefbi-warninggigabytegoogle-playmobile-securitynpm-compromiseransomware-detectionrcesource-code-theftsupply-chain-attacktrivywindows-updatezero-day

What happened

Multiple high-impact security stories: a new Android malware family dubbed "NoVoice" was found on Google Play hidden in 50+ apps with at least 2.3M installs; attackers hijacked the Axios npm account to distribute cross‑platform RATs; Cisco reported source‑code theft tied to stolen credentials from the Trivy supply‑chain compromise; Google patched a fourth Chrome zero‑day exploited in the wild this year; GIGABYTE Control Center has an arbitrary file‑write flaw; vulnerabilities allowing RCE in Vim and GNU Emacs were discovered (via prompts to Claude); Anthropic accidentally leaked Claude Code in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0e28e653b519eb3112c5eba775957911d24b6db243d3143c8a17100dae0d2de5
Enrichment time
2026-04-01T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.