"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks

"Evolution of Web3 in Cloud Supply Chain Attacks" published by PaloaltoNetworks. #NPM, #AlluringPisces, #EtherHiding, #PolinRider, #NullReceiver https://unit42.paloaltonetworks.com/web3-cloud-supply-chain-attacks
This npm malware has no install script - it hides in a library method that runs when your app calls it. https://intel.threadlinqs.com/threat/TL-2026-2969 #ThreatIntel #EtherHiding #indexedbtree #btree
CIS CTI traced Remus infostealer distribution from Mar-Sep 2026, linking its MaaS ops to browser-session theft, EtherHiding C2 rotation, and multiple delivery chains tied to the Lumma lineage. #Remus #LummaStealer #EtherHiding
AI-powered attacks keep turning ordinary features into risks: model inspection RCE, secrets exposure, and blockchain-hidden malware instructions. OFAC also sanctioned 10 targets tied to ATM jackpotting. #TrenDeAragua #EtherHiding #OFAC
Wordfence uncovered stealthy WordPress must-use plugin malware. Learn how this WordPress must-use plugin malware abuses EtherHiding to steal secrets.
EtherHiding hides its C2 inside a Polygon smart contract - malware that phones the blockchain, not a domain. https://intel.threadlinqs.com/threat/TL-2026-2600 #ThreatIntel #EtherHiding #ClickFix #Polygon
"PolinRider Spreads Through Compromised GitHub Accounts and Packagist" published by Socket. #GitHub, #EtherHiding, #VSCode, #PolinRider, #NullReceiver https://socket.dev/blog/polinrider-github-packagist
"DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks" published by Chainalysis. #UNC5342, #EtherHiding https://www.chainalysis.com/blog/etherhiding-blockchain-dead-drops
One of our first lists is the cryptocurrency RPC Nodes lists. You want to block these right now to neutralized #Etherhiding attacks!
Zscaler ThreatLabz found SloppyRAT, a new malware family likely tied to ransomware ops. It uses a ClickFix infection chain, anti-analysis tricks, EtherHiding C2 resolution, and remote command execution. #SloppyRAT #ClickFix #EtherHiding
Recent Node.js malware attacks target global firms. Attackers deploy Node.js malware using trusted runtimes and smart contracts to evade detection.
📢 EtherHiding + WebRTC : campagne malveillante via blockchain BSC testnet sur 5 400 sites
Cet article présente l'analyse technique d'une campagne malveillante en cours exploitant la technique EtherHiding — l'utilisation de…
🟡 vérification factuelle moyenne
#BSCTestnet #EtherHiding #Cyberveille
REVSTEALER infostealer uses 4 modules to steal wallets, disable Defender, and mine XMRig via blockchain C2. https://intel.threadlinqs.com/threat/TL-2026-2353 #ThreatIntel #xmrig #Monero #EtherHiding
Over 5,400 compromised WordPress and PrestaShop sites are delivering ClickFix payloads via smart contracts on BNB Smart Chain through EtherHiding, with a new WebRTC stager complicating takedowns. #ClickFix #EtherHiding #BNBSmartChain
John Carlo Marquez's latest blog details a growing trend of more than 5,400 compromised websites leveraging the EtherHiding technique and a new campaign that abuses WebRTC to create a covert C2 channel. #EtherHiding #Malware
Attackers are abusing Node.js with ClickFix and EtherHiding to deploy malware stealthily. #Nodejs #ClickFix #EtherHiding #Malware #CyberSecurity #Infosec https://thedailytechfeed.com/node-js-runtime-hijacked-for-c2-malware-and-blockchain-tricks/