Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
2026-08-08T01:23:59Z•d90a394e6ab44e6c1c58c4ccd26e5e0b7b4740fa81e7f15b578d432b2d585913
CVE-2026-63077CVE-2026-64561CVE-2026-64638AI-agent-securityAitMCiscoEntra-IDGitHub-ActionsKVMLinuxPLCRATSD-WANWordPressactive-exploitationbackdoorcloud-securityindustrial-control-systemsinfostealerkernelmalwarenpmphishingrouterssupply-chainvirtualizationvishingvulnerability
What happened
The document is a cybersecurity news feed covering active exploitation, critical vulnerabilities, malware campaigns, supply-chain attacks, phishing, cloud and AI agent security flaws, exposed industrial systems, and ransomware activity. Notable high-impact items include actively exploited TeamCity RCE (CVE-2026-63077), WordPress pre-auth XSS enabling potential PHP code execution (CVE-2026-64638), KVM guest-to-host escape (CVE-2026-64561), Linux SCTP local privilege escalation and container escape, malicious npm packages delivering cross-platform RATs and infostealers, Microsoft 365 adversary--
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d90a394e6ab44e6c1c58c4ccd26e5e0b7b4740fa81e7f15b578d432b2d585913
- Enrichment time
- 2026-08-08T01:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.