Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
2026-08-07T19:23:59Z•9f5b1c930018f7fced1f1333ebe620df6ecd1660e604b2e688734284506e7d00
CVE-2026-63077CVE-2026-64561CVE-2026-64638AitMCisco IOS XEKVMLinuxMicrosoft 365PLC exposure และICS securityRATRCESCTPSD-WANTeamCityWordPressXSSactive exploitationcontainer escapecrypto-theftindustrial control systemsinfostealermacOSmalwarenpmphishingsupply-chainvirtualizationvishing
What happened
The feed highlights multiple high-impact cybersecurity threats, including widespread malicious npm packages delivering cross-platform RATs and infostealers, macOS crypto and credential stealers, enterprise vishing and Microsoft 365 adversary-in-the-middle phishing, critical WordPress, Linux SCTP, KVM, Cisco, and TeamCity vulnerabilities, exposed industrial control systems, cloud and coding-agent security flaws, router backdoors, and emerging attacks against NAT, CPUs, AI assistants, and cryptographic wallets. Several issues involve remote code execution, privilege escalation, container or VM逃逸
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9f5b1c930018f7fced1f1333ebe620df6ecd1660e604b2e688734284506e7d00
- Enrichment time
- 2026-08-07T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.