Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
2026-06-29T07:24:13Z•84e45220648c9f71aeca88e96bddc3a4d471f5c2f12d2e3a104373e587d75fd0
ad-injectionamazon-qchrome-extensionci/cdcisa-kevcobalt-strikecordycepsdirtyclonegaslightgithub-actionsgogpt-5.6lantronixlinux-kernelmacosmiasmanpmopenaipedit-cowprivilege-escalationptc-windchillrussian-intelligencesharkloadersignal-phishingsupply-chain
What happened
A broad set of high-impact incidents and vulnerabilities reported by The Hacker News: supply-chain attacks continue (hijacked npm and Go packages, Miasma infections abusing GitHub Actions, Cordyceps CI/CD workflow hijacks), multiple malware campaigns (SharkLoader delivering Cobalt Strike, Gaslight macOS infostealer with prompt-injection evasion, Mistic backdoor, Turla's STOCKSTAY), and widespread exploitation/active campaigns (Signal backup recovery key phishing by Russian intelligence, Cisco Catalyst SD‑WAN zero‑day exploitation, active Lantronix EDS5000 exploitation). Notable local privilege
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 84e45220648c9f71aeca88e96bddc3a4d471f5c2f12d2e3a104373e587d75fd0
- Enrichment time
- 2026-06-29T07:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.