Malware
Ongoing coverage on Malware.
Latest coverage
A malware dev has committed a magnificent self-own after an AI-coded malicious package leaked its own GitHub private…
Researchers at Ox Security have discovered a malicious npm package called mouse5212-super-formatter, which was designed to steal information from Claude users. The AI-coded malware reportedly leaked its own GitHub private token, allowing researchers to trace the stolen files and analyze its operations before the threat actor's account was deleted.
Evening Safety Dance
Nvidia is urging users to update their GPU drivers immediately due to a security vulnerability that could lead to malware infections. Failing to update may expose users to 'surprise malware DLC'.
Danger Zone
A free horror game was removed from Steam due to malware concerns. Separately, PUBG: Battlegrounds issued a notice regarding weekly bans for the period of May 11th to May 17th, indicating ongoing efforts to combat cheating.
Your Nvidia GPU Needs A Driver Update Right Now, Unless You Enjoy Surprise Malware DLC
Nvidia has issued a critical security alert for its graphics card drivers on Windows and Linux, urging users to update to version 596.49 immediately. Hackers have exploited a vulnerability to gain unauthorized access to PCs, potentially stealing data or injecting malware. The company also introduced Auto Shader Compilation for RTX 50-series cards, designed to compile shaders in the background during idle times.
Your Nvidia GPU Needs A Driver Update Right Now, Unless You Enjoy Surprise Malware DLC
Nvidia has issued a critical security alert for its graphics card drivers on Windows and Linux, urging users to update to version 596.49 immediately. Hackers have exploited a vulnerability to gain unauthorized access to PCs, potentially stealing data or injecting malware. The company also introduced Auto Shader Compilation for RTX 50-series cards, designed to compile shaders in the background during idle times.
Another Steam Game Gets Removed Over Malware
Valve has removed the free-to-play survival-horror game Beyond the Dark from Steam after YouTuber Eric Parker exposed it for containing malware designed to steal player data. The game was previously uploaded under the name Rodent Race in December 2024, suggesting an attempt to bypass security checks. The FBI is investigating similar incidents of malware on Steam and has asked players who downloaded infected games between May 2024 and January 2026 to report it.
Another Steam Game Gets Removed Over Malware
Valve has removed the Steam game Beyond the Dark after YouTuber Eric Parker exposed it for containing malware designed to steal player data. The game was previously uploaded under the name Rodent Race, suggesting an attempt to bypass security checks. The FBI is investigating similar incidents of malware on Steam.
Free Steam game Beyond the Dark turns out to be malware, but this isn't the first time we've seen it
The Steam game Beyond the Dark, previously released as Rodent Race, has been removed from the platform after being discovered to contain data-gobbling malware. Cybersecurity expert Eric Parker detailed how the game disguised its malicious intent, raising concerns about the ease with which bad actors can inject malware into games after they pass initial store review. This incident highlights the ongoing challenges in video game security and the potential for AI to be used in creating such malicious software.
There's a devious hacking scheme that involves a hijacked Microsoft Teams account, a fake IT helpdesk, and a covert…
A new hacking scheme involves hijacked Microsoft Teams accounts impersonating IT helpdesks to trick users into downloading malicious files. This social engineering tactic uses a covert PowerShell command to unpack a WinPython environment, leading to the ModeloRAT malware infecting PCs without detection. The malware aims to embed itself in corporate environments to harvest data and establish connections to other devices.
Popular emulator Cemu was recently compromised with malware in Linux downloads
The popular Nintendo Wii U emulator Cemu was compromised, with malware found in certain Linux builds distributed via GitHub. The malicious code targeted user credentials and security keys, with a special payload for users in Israel. The developers have since removed the affected versions and are working to secure their distribution channels.
Morning Safety Dance
The company Canvas reported that data stolen in a hack affecting thousands of schools has been returned. Separately, Google discovered the first AI-developed zero-day exploit that bypasses two-factor authentication, utilizing self-morphing malware and Gemini technology.
A 'JobStealer' Trojan virus has popped up that attacks PCs via fake job interviews
A new Trojan virus named 'JobStealer' is targeting PCs by posing as a fake job interview invitation. Attackers use spoofed video conferencing apps and social media accounts to trick users into downloading malicious software that steals data, including cryptocurrency wallets. Versions for macOS, iOS, Android, and Linux are also noted, though not yet widely distributed.
Evening Safety Dance
A new type of malware has been identified that actively removes competing malware from infected systems before establishing its own control. This aggressive behavior highlights an evolving landscape in cyber threats.
Morning Safety Dance
Newly deciphered sabotage malware may have targeted Iran's nuclear program and predates Stuxnet. A separate mention indicates a biobank data leak was caused by 'a few bad apples'.
Fake Windows Support website offers 'cumulative update' for version 24H2 but delivers password-stealing malware that can avoid anti-virus detection
A sophisticated phishing scam is distributing password-stealing malware disguised as a 'cumulative update' for Windows Update version 24H2. The fake update, offered through a fraudulent Microsoft support website, can evade antivirus detection due to its obfuscated JavaScript within an Electron shell. Cybersecurity firm Malwarebytes has updated its antivirus to detect this threat and advises users to be wary of unofficial download sources.
Sunday Safety Dance
A new exploit allows malware to be delivered through compromised downloads of legitimate software like CPU-Z and HWMonitor. This vulnerability highlights significant cybersecurity failures, as demonstrated by a recent incident in Syria.
These two huge PC performance app downloads have been infected by a virus
The download pages for PC performance monitoring applications CPU-Z and HWMonitor, operated by CPUID, were compromised with malware. Download links were replaced with infected files, though the correct links appear to have been restored. Users who downloaded the software recently are advised to check file names and run virus scans, as Windows Defender reportedly flagged the compromised versions.
CPUID's download page has been hacked, with its popular processor and PC info tools replaced with links to files…
CPUID's official download page for its popular CPU-Z and HWMonitor software has been compromised, with malicious files replacing legitimate downloads. The altered files, detected by antivirus software, are part of a sophisticated malware campaign that deeply trojanizes the executables and uses advanced evasion techniques. This incident follows a similar attack on FileZilla, suggesting a pattern by the same threat group.
Web-code library with millions of weekly downloads poisoned by malicious release: 'This is unironically a malware…
The popular JavaScript library Axios was targeted in a sophisticated supply chain attack, with malicious versions distributing a remote access trojan. Attackers, identified as a North Korea-nexus threat actor, pre-built payloads and poisoned release branches, with malware calling home within seconds of installation. While malicious versions were quickly removed, cybersecurity firms warn of potential compromise and recommend thorough security assessments.
Morning Safety Dance
A self-propagating malware has been discovered in a popular Python library, turning it into a backdoor that can compromise entire machines. The attack specifically targeted and wiped machines based in Iran, highlighting significant open-source software security vulnerabilities.