Fake GitHub Stars and AI Videos Mask a Crypto Clipper

2026-06-18T20:52:11Z443c656c526a2eee9e32f2496326d424fb36e1b057794936d8f430536c23348a
ai‑abusebackdoorcredential‑theftcrypto‑clipperfortinetivantijetbrainslaw‑enforcementmalwarenation‑statepatchingphishingransomwaresupply‑chainvulnerabilitieswordpress

What happened

A broad set of cybersecurity stories highlighting active malware and supply‑chain abuse, targeted infrastructure exploitation, and rising AI‑enabled threats. Key incidents include a Rust crypto clipper promoted via fake GitHub stars and AI‑narrated videos, LATAM infrastructure compromises leveraging Fortinet and Ivanti flaws (Operation Escaneo), large WordPress plugin supply‑chain backdoors affecting ~1.2M sites, JetBrains Marketplace plugins stealing API keys, multiple new trojans/backdoors (SilabRAT, SprySOCKS, Rokarolla), phishing kits abusing GitHub Pages (GitBait) and fake AI guides to l2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
443c656c526a2eee9e32f2496326d424fb36e1b057794936d8f430536c23348a
Enrichment time
2026-06-18T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.