LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

2026-07-14T19:24:13Z133d243f7d90cf56b6ad076d3bb8d974e63376c3c3c1b5fd35921d8681f27bea
CISA-KEVbrowser-extensioncrypto-walletsdata-exfiltrationevilginxgit-leakinfostealermacosmalwaremisconfigurationnpmnpm-compromiseoauthoauth-client-id-spoofingphaaSphishingprivacy-leakremote-access-trojanrustsanctionssecure-boot-bypasssupply-chainuefivulnerability-disclosurezero-day

What happened

Multiple high-impact security incidents and vulnerabilities were reported across software supply chains, cloud and enterprise services, browser extensions, and firmware. New malware and espionage activity includes LabubaRAT (Rust RAT) masquerading as NVIDIA software, CrashStealer macOS infostealer using a notarized dropper, and a compromised jscrambler npm release that runs a native Rust infostealer during install. Supply-chain and registry abuse observed: 148 malicious npm packages acting as student proxies (DDoS botnet), Injective Labs GitHub compromise pushing wallet-key-stealing npm code,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
133d243f7d90cf56b6ad076d3bb8d974e63376c3c3c1b5fd35921d8681f27bea
Enrichment time
2026-07-14T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.