84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack Targeting CI Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 12, 2026 A significant supply-chain compromise affecting 84 npm package artifacts across the TanStack namespace. The malicious versions, published to the npm registry at approximately 19:20 and 19:26 UTC, contain a suspected credential-stealing payload targeting CI systems, including GitHub …

Popular Go Library fsnotify Raises Supply Chain Alarms After Maintainer Access Changes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 A widely used Go library called fsnotify has found itself at the center of a supply chain security scare after a sudden change in maintainer access triggered alarm across the open source community.  The project provides cross-platform …

Google Warns of Hackers Using AI to Create Working Zero-Day Exploit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Threat Intelligence Group recently published an alarming report detailing the rapid industrialization of generative artificial intelligence in adversarial workflows. The most significant finding reveals that a cybercriminal syndicate successfully developed a working zero-day exploit entirely through artificial intelligence assistance. …

Hackers Use PlugX-Like DLL Sideloading Chain in Fake Claude Malware Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 Cybercriminals are getting creative with how they lure victims into downloading malware, and a new campaign involving a fake version of Anthropic’s Claude AI assistant is raising serious concerns. Attackers set up a convincing lookalike website to …

Hackers Use Fake DeepSeek TUI GitHub Repositories to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 Hackers are once again targeting developers and AI enthusiasts by impersonating popular open-source tools on GitHub. This time, the target is DeepSeek TUI, a legitimate terminal-based intelligent agent that allows users to interact with DeepSeek large language …

ShinyHunters Breaches Instructure Canvas LMS Through Free-For-Teacher Account Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The infamous hacking group ShinyHunters has struck again, this time targeting Instructure, the company behind Canvas Learning Management System (LMS). In early May 2026, Instructure confirmed unauthorized activity on its Canvas platform after detecting suspicious access on April 29, 2026. …

Crimenetwork Takedown Exposes 22,000 Users and Over 100 Illegal Sellers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 In a massive, internationally coordinated operation, the Frankfurt am Main Public Prosecutor’s Office – Central Office for Combating Internet Crime (ZIT) and the Federal Criminal Police Office (BKA) have successfully dismantled the relaunched “Crimenetwork” platform. Law enforcement …

Trending Hugging Face Repo With 200k Downloads Executes Malware on Windows Machines

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 A popular artificial intelligence repository on Hugging Face was recently found hiding dangerous malware that targeted Windows users. The repository, named “Open-OSS/privacy-filter,” had racked up over 200,000 downloads before the platform’s team stepped in and removed it. …

macOS Malware Leverages Google Ads and Legitimate Claude.ai Shared Chats to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 Threat actors are executing a sophisticated malvertising campaign targeting macOS users via poisoned Google Ads and deceptive artificial intelligence applications. Researchers recently uncovered an operation that redirects victims to fraudulent landing pages via sponsored search results. By …

Vidar Malware Targets Browser Credentials, Cookies, Crypto Wallets, and System Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

May 11, 2026 A long-active information stealer is making headlines again, and this time it is targeting more than just passwords. Vidar malware, a credential-harvesting tool in circulation since late 2018, has been observed running through a sophisticated multi-stage attack …