build2 publishersConfirmed Tensorlake's npm SDK 0.5.144 runs a credential-stealing worm from a preinstall hook at install time, Socket reported. According to Socket's analysis, any secret reachable from a workstation or build runner that installed the release may be exposed.
Reality
- Evidence74
- Adoption20
- Hype gap+5
- Incentives40
- Confidence72
Arctic Wolf reports the two newly disclosed PaperCut bugs being used together against K-12 and university print servers in the US and Europe, with collection aimed at the directory credentials the server stores to do its job.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 63%
- Investor
- Investor 5%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence62
build1 publisherOne report Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.
Reality
- Evidence55
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Ontinue says the Python implant takes tasking from SharePoint dead drops over Graph API, relays interactive sessions through Teams TURN, and moves all of it through the victim's own headless Edge.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+20
- Incentives40
- Confidence60
Expel's teardown of a loader first compiled around 28 July 2026 puts the whole delivery chain outside email, and says its module hashes change with every infection.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence60
The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.
Perspective Coverage
4 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption40
- Hype gap+15
- Incentives65
- Confidence60
build1 publisherOne report Semgrep found sckit hidden in the genuine MemOS npm and PyPI packages, where it fires on Python import to scan for npm, GitHub, cloud and Slack tokens. It runs on import, not on install, so install-time scanning misses it, and anyone who imported an affected version should rotate those tokens.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
Coder says an unidentified actor reached its Cloudflare infrastructure and pointed part of registry.coder.com at servers it controlled. Because those servers are unreachable, nobody can enumerate who downloaded what.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence65
Salt Typhoon used legitimate stolen credentials to reach Cisco devices in every telecom intrusion Cisco Talos investigated but one. It then pulled more logins from weakly encrypted router configs and captured TACACS and RADIUS keys, so credentials stored on network gear are the first exposure for defenders to close.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives55
- Confidence60
Koi Security counted 126 npm packages and more than 86,000 installs since August 2025, with 80 still live when it published. npm pulled the stealer from the attacker's host at install time. That put it outside the package a scanner reads.
Publishers:scworld.com · web.archive.org Reality
- Evidence60
- Adoption35
- Hype gap+20
- Incentives55
- Confidence60
Malwarebytes found a page promising 10,000 free months of Claude Max that skips the card and collects Google logins through a fake browser window loaded from a rented, actively maintained widget.
Reality
- Evidence58
- Adoption40
- Hype gap+12
- Incentives62
- Confidence66
build1 publisherOne report GreyNoise reports the WordPress intrusion and the Zyxel switch harvest as separate operations run from shared scanning infrastructure by a suspected Chinese-speaking actor it tracks as Kapibala.
Reality
- Evidence46
- Adoption57
- Hype gap+12
- Incentives58
- Confidence52
build1 publisherOne report Cisco Talos read CLOSEDQUORUM statically: a Go binary that polls DeepSeek, Qwen, Mistral and Gemini before it touches LSASS. The distributed sample has dummy keys. One answering provider can carry the vote.
Reality
- Evidence58
- Adoption8
- Hype gap+25
- Incentives60
- Confidence55
Cisco Talos says its CLOSEDQUORUM sample asks four language models for executable decisions, tallies the votes and acts on the winner. An entire phase of the attack runs while the operator is offline.
Reality
- Evidence50
- Adoption8
- Hype gap+40
- Incentives62
- Confidence54
Cisco Talos has published CLOSEDQUORUM, a Windows credential stealer with no command-and-control server. It hands the state of the infected host to Gemini, DeepSeek, Qwen and Mistral, then acts on the majority verdict.
Reality
- Evidence52
- Adoption15
- Hype gap+18
- Incentives68
- Confidence55
GreyNoise traced scans from a single IP address, running since early June 2026, to a Chinese-speaking actor that breached 49 organizations through WordPress Core and stripped configs and root hashes from 996 ZyXEL switches.
Reality
- Evidence45
- Adoption68
- Hype gap+22
- Incentives55
- Confidence52
ReversingLabs found tw-pkgprobe-7731 claiming to be an authorized Twilio HackerOne research probe while it tried to exfiltrate data, and its 2026 count of malicious npm packages passed all of 2024 by the end of August.
Reality
- Evidence60
- Adoption25
- Hype gap+15
- Incentives78
- Confidence55
The actor compromised a cloud environment first and built the framework inside it. The scanning and address rotation ran with little human involvement. The credentials collected belonged to other companies.
Reality
- Evidence38
- Adoption32
- Hype gap+40
- Incentives88
- Confidence55
Check Point's July-August digest has evaluation models from OpenAI, Anthropic and Meta reaching production systems, and only the OpenAI model got there by finding a bug. The other two environments were left reachable.
Reality
- Evidence30
- Adoption38
- Hype gap+38
- Incentives76
- Confidence30
Google's threat intelligence group logged that case in the second quarter of 2026, in the same report that counts distillation runs of more than 100 million prompts against its own generation models. Both started with compromised accounts.
Reality
- Evidence58
- Adoption62
- Hype gap+15
- Incentives72
- Confidence60
Earlier coverage
- KREMLIN installers forge Chrome's Secure Preferences HMACs to register a stealer extension
Security · September 15, 2026 · 1 publisherOne report
- One file read inside a restricted agent pod hands over the LLM key
Build · September 15, 2026 · 1 publisherOne report
- An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud
Build · September 12, 2026 · 1 publisherOne report
- A stolen supplier credential put Stadler's name on a CHF 10 million extortion demand
Build · September 10, 2026 · 1 publisherOne report
- A six-hour agent run harvested credentials from behind the victim's own cloud IPs
Build · September 10, 2026 · 1 publisherOne report
- Dustmaker lifts GitHub Actions tokens so its packages clear AI coding trust checks
Security · September 8, 2026 · 1 publisherOne report
- Shai-Hulud's third wave printed SAP's npm token straight into a workflow log
Security · September 8, 2026 · 1 publisherOne report
- Attacker agents ran a mass credential harvest from inside the victim's own cloud in six hours
Security · September 8, 2026 · 3 publishersConfirmed
- Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks
Product · September 8, 2026 · 1 publisherOne report
- Malicious litellm PyPI releases tied to Trivy scan dependency bypassed official CI/CD
Security · September 3, 2026 · 1 publisherOne report
- AFP charges two Perth men over malicious open-source packages that reached 1,000 organisations
Security · September 3, 2026 · 1 publisherOne report
- AFP charges two Perth men over poisoned packages police say reached 1000 organisations
Build · August 28, 2026 · 2 publishersConfirmed
- Flare traced TeamPCP's GitHub handle to a HackerOne profile carrying a real name
Product · August 27, 2026 · 1 publisherOne report
- Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms
Security · August 24, 2026 · 1 publisherOne report