AI Poisoning & AMOS Stealer How Trust Became the Biggest Mac Threat Huntress

Attackers poisoned search results to surface malicious ChatGPT and Grok conversations that instruct macOS users to copy-paste a Terminal one-liner which downloads and deploys an AMOS stealer. The campaign abuses platform and format trust to harvest credentials, escalate to root, persist via a LaunchDaemon, and exfiltrate wallet, browser, and keychain data. #AMOS #macOS

Read More
ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit โ€” and 20 More Stories

This weekโ€™s cyber stories highlight the rapid evolution of digital threats, from malware in movie downloads to sophisticated botnets exploiting system vulnerabilities. The Threatsday Bulletin provides a concise overview of major security incidents and emerging risks in the cyber landscape. #Mirai #LummaStealer…

Read More
Google ads for shared ChatGPT, Grok guides push macOS infostealer malware

A new cyberattack campaign exploits Google search ads to direct users to malicious AI chats that install the AMOS macOS infostealer malware. This campaign uses poisoned ChatGPT and Grok conversations to trick users into executing malicious commands, leading to potential data theft and device compromise. #AMOS #Grok #ChatGPT #macOS #Infostealer

Read More
PeerBlight Linux Backdoor Exploits React2Shell CVE-2025-55182

A critical unauthenticated deserialization vulnerability in React Server Components (CVE-2025-55182, “React2Shell”) has been exploited in the wild to deliver cryptominers, a BitTorrent-DHTโ€‘backed Linux backdoor (PeerBlight), a reverse-proxy tunnel (CowTunnel), a Go post-exploitation implant (ZinFoq), and a Kaiji botnet variant across multiple organizations. Immediate patching of affected react-server-dom packages and Next.js mitigations are recommended to prevent these automated exploitation campaigns. #React2Shell #PeerBlight #CowTunnel #ZinFoq

Read More
AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows

Trend Research describes the discovery and technical analysis of GhostPenguin, a previously undocumented multi-threaded Linux backdoor that provides a remote /bin/sh shell and extensive filesystem operations over an RC5-encrypted UDP channel (initial handshake over UDP port 53). The backdoor was found using an AI-driven VirusTotal zero-detection hunting pipeline that decompiled and…

Read More
Investigating Shai-Hulud: Inside the NPM Supply Chain Worm

Attackers exploited a GitHub Actions injection vulnerability in Nxโ€™s workflow to steal an NPM publishing token, push malicious Nx packages, and use those packages to harvest credentials, SSH keys, and crypto wallets from developer systems. The campaign evolved into a self-replicating NPM supply-chain worm called Shai-Hulud that registers compromised hosts as self-hosted GitHub Actions runners and uses GitHub Discussions as a stealthy C2 channel. #ShaiHulud #Nx

Read More
DigitStealer MacOS Infostealer

DigitStealer is a macOS information stealer delivered as an unsigned DynamicLake.dmg that runs almost entirely in memory and abuses JavaScript for Automation (JXA) and AppleScript to harvest high-value data. It enforces geographic and Apple Silicon M2+ hardware checks, fetches four in-memory payloads (AppleScript stealer, two obfuscated JXA modules, and a LaunchAgent backdoor using DNS TXT for C2), and tampers with Ledger Live to enable seed-phrase exfiltration. #DigitStealer #LedgerLive

Read More
Sha1-Hulud: The Second Coming of The New npm GitHub Worm

Sha1-Hulud has launched a sophisticated supply-chain attack targeting npm packages used by JavaScript developers, infecting nearly 1,000 packages and exposing tens of thousands of repositories. The latest campaign includes new features like cross-platform support, a self-destruct mechanism, and remote code execution via GitHub Actions, increasing the threat’s severity. #Sha1Hulud #npmSupplyChainAttack…

Read More