Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks

2026-06-25T08:51:41Zdaf11398476eb979ca9c6e7fcd4624e8d19794a31ea994bca37b1749c0e05a18
AmadeyCI/CDChrome password theftCordycepsCryptoBanditsGhostShellGitHub ActionsKlueLastPassPostCSSSocGholishStealCTorUSB clipperWindows RATcredential dumpscredential theftdrone defenselaw enforcement takedownmalicious npm packagesmalwarenpmpipeline hijackingsupply chaintoken theft

What happened

Multiple high-impact cyber incidents and threats reported: Operation Endgame disrupted infrastructure used by StealC, Amadey and SocGholish, seizing millions of stolen credentials and servers tied to global cybercrime campaigns. GhostShell is running targeted campaigns against Ukrainian drone‑defense teams using fake drone documents to steal credentials and sensitive data. JFrog warned of malicious npm packages impersonating PostCSS that deploy a Windows RAT and stage theft of Chrome‑stored passwords. LastPass confirmed customer data exposure stemming from the Klue supply‑chain OAuth token ex‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
daf11398476eb979ca9c6e7fcd4624e8d19794a31ea994bca37b1749c0e05a18
Enrichment time
2026-06-25T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.