Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

2026-08-07T19:23:59Z9f5b1c930018f7fced1f1333ebe620df6ecd1660e604b2e688734284506e7d00
CVE-2026-63077CVE-2026-64561CVE-2026-64638AitMCisco IOS XEKVMLinuxMicrosoft 365PLC exposure และICS securityRATRCESCTPSD-WANTeamCityWordPressXSSactive exploitationcontainer escapecrypto-theftindustrial control systemsinfostealermacOSmalwarenpmphishingsupply-chainvirtualizationvishing

What happened

The feed highlights multiple high-impact cybersecurity threats, including widespread malicious npm packages delivering cross-platform RATs and infostealers, macOS crypto and credential stealers, enterprise vishing and Microsoft 365 adversary-in-the-middle phishing, critical WordPress, Linux SCTP, KVM, Cisco, and TeamCity vulnerabilities, exposed industrial control systems, cloud and coding-agent security flaws, router backdoors, and emerging attacks against NAT, CPUs, AI assistants, and cryptographic wallets. Several issues involve remote code execution, privilege escalation, container or VM逃逸

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9f5b1c930018f7fced1f1333ebe620df6ecd1660e604b2e688734284506e7d00
Enrichment time
2026-08-07T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer · Baitaphish