Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

2026-06-29T07:24:13Z84e45220648c9f71aeca88e96bddc3a4d471f5c2f12d2e3a104373e587d75fd0
ad-injectionamazon-qchrome-extensionci/cdcisa-kevcobalt-strikecordycepsdirtyclonegaslightgithub-actionsgogpt-5.6lantronixlinux-kernelmacosmiasmanpmopenaipedit-cowprivilege-escalationptc-windchillrussian-intelligencesharkloadersignal-phishingsupply-chain

What happened

A broad set of high-impact incidents and vulnerabilities reported by The Hacker News: supply-chain attacks continue (hijacked npm and Go packages, Miasma infections abusing GitHub Actions, Cordyceps CI/CD workflow hijacks), multiple malware campaigns (SharkLoader delivering Cobalt Strike, Gaslight macOS infostealer with prompt-injection evasion, Mistic backdoor, Turla's STOCKSTAY), and widespread exploitation/active campaigns (Signal backup recovery key phishing by Russian intelligence, Cisco Catalyst SD‑WAN zero‑day exploitation, active Lantronix EDS5000 exploitation). Notable local privilege

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
84e45220648c9f71aeca88e96bddc3a4d471f5c2f12d2e3a104373e587d75fd0
Enrichment time
2026-06-29T07:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.