LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
2026-03-26T01:24:14Z•231a23240d76f0d9e07d6a7fc3966c490e46544b3fa85be0c13b14b020978f34
BYOVDcanisterwormcisacredential-harvestcritical-vulnerabilitydevice-code-phishingdocker-hubfbighost-campaignglasswormhwaudkillerinfostealerlitellmmalwarenpm-malwareoauth-device-code-phishingphishingrcescreenconnectsolana-dead-dropsstoatwafflesupply-chainteampcptrivyvs-code-malicious-tasks
What happened
A high-impact week of threats and disclosures: Russian law enforcement arrested the alleged LeakBase forum admin while multiple active supply‑chain and credential‑theft campaigns escalated. The Trivy compromise and follow-on activity (malicious Docker images, CanisterWorm self‑propagating npm infections) and TeamPCP backdoors in the litellm package and stolen CI/GitHub workflows illustrate broad developer-supply‑chain abuse. Multiple critical vulnerabilities are being patched and actively exploited (Citrix NetScaler, Quest KACE SMA, Oracle Identity/Web Services Manager), and large-scale social
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 231a23240d76f0d9e07d6a7fc3966c490e46544b3fa85be0c13b14b020978f34
- Enrichment time
- 2026-03-26T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.