Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack

Cybersecurity researchers have uncovered a large-scale spam campaign called IndonesianFoods, flooding the npm registry with over 67,000 fake packages designed to overwhelm the ecosystem. The campaign employs a worm-like propagation mechanism, exploiting manual script execution to sustain continuous spam uploads, potentially monetizing via the TEA protocol. #IndonesianFoods #npmspam #TEAprotocol…

Read More
Slot Gacor: The Rise of Online Casino Spam

Online casino SEO spam has surged since 2021, with attackers increasingly compromising WordPress sites to inject cloaked casino pages and backlinks, often targeting regions with strict gambling laws like Indonesia. The observed infection used layered redundancies—database-stored payloads, .dat files, theme/plugin modifications, and reinfection code—to persist and evade detection. #SlotGacor #browsec.xyz

Read More
China-linked Actors Maintain Focus on Organizations Influencing U.S. Policy

Chinese-linked APT actors used known exploitation scans and a multi-stage intrusion in April 2025 to establish persistent, stealthy access to a U.S. organization, employing DLL sideloading (vetysafe.exe -> sbamres.dll), legitimate binaries (msbuild.exe, Imjpuexc), scheduled tasks, a custom loader, and DCSync-like activity. #APT41 #Kelp #SpacePirates #Dcsync #DeedRAT

Read More
PolarEdge Expands via IoT Proxy Network

XLab discovered RPX_Client, a previously undocumented PolarEdge relay component that onboards compromised IoT/edge devices into a proxy pool and enables remote command execution, linked to download infrastructure at 111.119.223.196 and corroborated by homology with known PolarEdge samples. The investigation identified 140 RPX_Server VPS nodes (port 55555) and over 25,000 infected devices across 40 countries, revealing an ORB network used for long-term stealth and traffic obfuscation. #PolarEdge #RPX_Client

Read More