LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace

2026-03-26T01:24:14Z231a23240d76f0d9e07d6a7fc3966c490e46544b3fa85be0c13b14b020978f34
BYOVDcanisterwormcisacredential-harvestcritical-vulnerabilitydevice-code-phishingdocker-hubfbighost-campaignglasswormhwaudkillerinfostealerlitellmmalwarenpm-malwareoauth-device-code-phishingphishingrcescreenconnectsolana-dead-dropsstoatwafflesupply-chainteampcptrivyvs-code-malicious-tasks

What happened

A high-impact week of threats and disclosures: Russian law enforcement arrested the alleged LeakBase forum admin while multiple active supply‑chain and credential‑theft campaigns escalated. The Trivy compromise and follow-on activity (malicious Docker images, CanisterWorm self‑propagating npm infections) and TeamPCP backdoors in the litellm package and stolen CI/GitHub workflows illustrate broad developer-supply‑chain abuse. Multiple critical vulnerabilities are being patched and actively exploited (Citrix NetScaler, Quest KACE SMA, Oracle Identity/Web Services Manager), and large-scale social

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
231a23240d76f0d9e07d6a7fc3966c490e46544b3fa85be0c13b14b020978f34
Enrichment time
2026-03-26T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.