What One Predator Case Can Reveal About an Online Platform’s Safety Gaps
2026-06-01T20:51:43Z•5a64b4e0a264b320a56a03fd7f2ae1652524f46d1f2b8c056ba26fa538cde5e5
PureLogsRAR-attachmentsXSSaccount-takeoveranthropicbrowser-credential-theftcodex-uicredential-theftcrypto-theftfileless-malwareinfostealernpm-malwarephishingpretalxprocess-hollowingsupply-chaintoken-exfiltrationzero-click
What happened
Recent HackRead items highlight multiple active threats: a zero-click XSS in pretalx (patched in v2026.1.0) that allowed attackers to hijack conference organizer accounts, steal sessions, auto-accept talks and demote admins; fileless PureLogs malware distributed via fake purchase-order RAR attachments using process hollowing to exfiltrate browsers, crypto wallets and Discord data; a malicious Codex UI npm package (≈27k weekly downloads) exfiltrating OpenAI refresh tokens enabling developer account takeover; and fake Anthropic sites delivering a fileless infostealer targeting Claude Code users.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 5a64b4e0a264b320a56a03fd7f2ae1652524f46d1f2b8c056ba26fa538cde5e5
- Enrichment time
- 2026-06-01T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.