Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks
2026-06-25T08:51:41Z•daf11398476eb979ca9c6e7fcd4624e8d19794a31ea994bca37b1749c0e05a18
AmadeyCI/CDChrome password theftCordycepsCryptoBanditsGhostShellGitHub ActionsKlueLastPassPostCSSSocGholishStealCTorUSB clipperWindows RATcredential dumpscredential theftdrone defenselaw enforcement takedownmalicious npm packagesmalwarenpmpipeline hijackingsupply chaintoken theft
What happened
Multiple high-impact cyber incidents and threats reported: Operation Endgame disrupted infrastructure used by StealC, Amadey and SocGholish, seizing millions of stolen credentials and servers tied to global cybercrime campaigns. GhostShell is running targeted campaigns against Ukrainian drone‑defense teams using fake drone documents to steal credentials and sensitive data. JFrog warned of malicious npm packages impersonating PostCSS that deploy a Windows RAT and stage theft of Chrome‑stored passwords. LastPass confirmed customer data exposure stemming from the Klue supply‑chain OAuth token ex‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- daf11398476eb979ca9c6e7fcd4624e8d19794a31ea994bca37b1749c0e05a18
- Enrichment time
- 2026-06-25T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.