Search Articles

Search Results: CryptoSecurity

Massive npm Supply Chain Attack Hijacks 2.6 Billion Weekly Downloads via Phishing Compromise

Massive npm Supply Chain Attack Hijacks 2.6 Billion Weekly Downloads via Phishing Compromise

Attackers compromised a key npm maintainer's account through sophisticated phishing, injecting malicious code into 19 popular packages with over 2.6 billion weekly downloads. The malware hijacks cryptocurrency transactions by rewriting wallet addresses in real-time. This represents one of the largest software supply chain attacks in history, impacting developers globally.
Global 'ClickTok' Campaign Infects TikTok Shop Users with Spyware to Steal Cryptocurrency

Global 'ClickTok' Campaign Infects TikTok Shop Users with Spyware to Steal Cryptocurrency

Security firm CTM360 has uncovered a sophisticated malware operation targeting TikTok's e-commerce ecosystem. Dubbed 'ClickTok,' the hybrid attack combines fake shops and trojanized apps to deploy SparkKitty spyware, harvesting cryptocurrency credentials through screenshot theft. The campaign has already spawned over 10,000 impersonated domains and 5,000 malicious app instances.

OpenSSL 3.0 Vulnerability Exposes Critical Memory Corruption Risk

A newly disclosed vulnerability in OpenSSL 3.0, tracked as CVE-2022-3786, allows malicious email addresses to trigger a heap buffer overflow during X.509 certificate verification. While exploitation requires specific conditions, successful attacks could lead to remote code execution or crashes. This flaw underscores persistent risks in foundational cryptographic libraries.