Trust Wallet Chrome Extension Breach Caused  Million Crypto Loss via Malicious Code

Trust Wallet has urged users to update their Chrome extension to prevent further losses after a security incident affected about $7 million worth of digital assets. The breach involved malicious code in version 2.68, which allowed hackers to extract wallet mnemonics and drain funds, possibly by insiders or nation-state actors. #TrustWallet…

Read More
2025 Report: Destructive Malware in Open Source Packages

Over the past year Socket observed a rise in destructive open-source packages that directly sabotage developer environments by deleting source code, breaking builds, and wiping repositories or CI artifacts. These packages—published to npm, PyPI, NuGet, and Go module indexes—used remote kill switches, time-delays, typosquatting/dependency confusion, and remote payload loaders to trigger targeted codebase destruction. #Socket #npm

Read More
LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts, TRM Labs Finds

The 2022 LastPass data breach’s encrypted vault backups have been exploited over years, with Russian cybercriminals cracking weak master passwords to steal cryptocurrency assets until late 2025. Threat analysis reveals links to Russian exchanges and sophisticated laundering techniques, emphasizing ongoing risks in digital asset security. #LastPass #TRMLabs #RussianCybercriminals #CryptocurrencyTheft…

Read More
SEC Files Charges Over  Million Crypto Scam Using Fake AI-Themed Investment Tips

The SEC has charged multiple companies and individuals involved in a sophisticated cryptocurrency scam that defrauded over $14 million from retail investors. The scam involved fake platforms, social media ads, WhatsApp investment groups, and fictitious AI-generated tips, with proceeds transferred abroad. #CryptoFraud #InvestmentScam…

Read More
SEC sues crypto firms for defrauding investors out of  million

Several cryptocurrency companies were sued by the SEC for running a sophisticated investment scam that defrauded investors of over $14 million using fake social media promotions and AI-generated content. The scam involved manipulated screenshots, false licenses, and fake security token offerings, with stolen funds transferred internationally to Southeast Asia. #SEC #CryptocurrencyFraud…

Read More
Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

Cybersecurity researchers have uncovered a malicious npm package named “lotusbail” that masquerades as a WhatsApp API but secretly intercepts messages and links attackers to victims’ WhatsApp accounts. The package has been widely downloaded, enabling attackers to steal credentials, harvest contacts, and maintain persistent access—posing a significant threat to users. #WhatsAppSecurity #npmMalware…

Read More
EtherRAT dissected: How a React2Shell implant delivers 5 payloads through blockchain C2 | Sysdig

Sysdig TRT documented EtherRAT, a fileless, Ethereum smart-contract–backed implant delivered via React2Shell (CVE-2025-55182) that provides persistent access, comprehensive credential and crypto-wallet theft, worm-like propagation, web server hijacking, and SSH backdoor installation. The blockchain-based C2 grants attackers resilient command-and-control while creating an immutable forensic trail that exposed C2 URLs, wallet addresses, and a brief Grabify-based victim enumeration step. #EtherRAT #React2Shell

Read More
North Korea’s Digital Surge: B Stolen in Crypto as Amazon Blocks 1,800 Fake IT Workers

North Korea has increased its digital operations significantly, stealing over $2 billion in cryptocurrency in 2025 and deploying sophisticated fake IT worker schemes. These efforts are part of a broader strategy to fund the regime and avoid sanctions, with many cyberattacks linked to North Korean threat actors. #NorthKoreaCyberattacks #Chainalysis #BybitHeist #AmazonITWorkers…

Read More
Over .4 billion in crypto stolen throughout 2025, with North Korea again the top culprit

North Korean hackers stole over $2 billion in 2025, focusing on large-scale, targeted crypto thefts and sophisticated money laundering techniques. Their operations significantly contributed to the overall rise in crypto thefts, highlighting their strategic shift towards high-value attacks. #NorthKoreanHackers #CryptoTheft2025…

Read More
North Korea-Linked Hackers Steal .02 Billion in 2025, Leading Global Crypto Theft

Threat actors linked to North Korea caused a record-breaking $2.02 billion in cryptocurrency thefts in 2025, primarily through high-profile attacks like the Bybit hack. Their operations include sophisticated money laundering schemes and infiltration of IT workers globally to fund North Korea’s regime. #LazarusGroup #BybitHack…

Read More
NuGet malware targets Nethereum tools

ReversingLabs uncovered a NuGet supply-chain campaign (July–October 2025) involving 14 malicious packages that impersonated legitimate crypto libraries to steal wallet secrets, OAuth credentials, or redirect funds. The packages used homoglyphs, version bumping, inflated download counts and hidden functions (e.g., Shuffle, MapAddress) to exfiltrate data to hxxps://solananetworkinstance[.]info/api/gads or overwrite transaction destinations. #Netherеum.All #NuGet

Read More