LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
2026-07-14T19:24:13Z•133d243f7d90cf56b6ad076d3bb8d974e63376c3c3c1b5fd35921d8681f27bea
CISA-KEVbrowser-extensioncrypto-walletsdata-exfiltrationevilginxgit-leakinfostealermacosmalwaremisconfigurationnpmnpm-compromiseoauthoauth-client-id-spoofingphaaSphishingprivacy-leakremote-access-trojanrustsanctionssecure-boot-bypasssupply-chainuefivulnerability-disclosurezero-day
What happened
Multiple high-impact security incidents and vulnerabilities were reported across software supply chains, cloud and enterprise services, browser extensions, and firmware. New malware and espionage activity includes LabubaRAT (Rust RAT) masquerading as NVIDIA software, CrashStealer macOS infostealer using a notarized dropper, and a compromised jscrambler npm release that runs a native Rust infostealer during install. Supply-chain and registry abuse observed: 148 malicious npm packages acting as student proxies (DDoS botnet), Injective Labs GitHub compromise pushing wallet-key-stealing npm code,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 133d243f7d90cf56b6ad076d3bb8d974e63376c3c3c1b5fd35921d8681f27bea
- Enrichment time
- 2026-07-14T19:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.