T1204.002Malicious File
T1204.002 — Malicious File is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 315 detection use cases covering it and 308 threat-intel articles citing it.
Execution
315Use cases
308Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1204 · User Execution
Use cases covering this technique (315)
Email attachment opened from external sender [WEEKLY] Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes [WEEKLY] Developer package install spawning script-host with non-registry C2 within 5 minutes [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes [WEEKLY] Package Manager Install Spawning Outbound Egress to Non-Registry Infrastructure Within 5 Minutes [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime [WEEKLY] Package manager lifecycle hook spawns runtime with outbound egress to non-registry host within 5 minutes [WEEKLY] Package manager spawns network-fetching child to public code-hosting within minutes of install O365 SharePoint Malware Detection O365 Threat Intelligence Suspicious File Detected Batch File Write to System32 Cisco NVM - Susp Script From Archive Triggering Network Activity Drop IcedID License dat Single Letter Process On Endpoint Suspicious Process Executed From Container File Windows Advanced Installer MSIX with AI_STUBS Execution Windows AppX Deployment Full Trust Package Installation Windows AppX Deployment Package Installation Success Windows AppX Deployment Unsigned Package Installation Windows Binary Execution from an Archive Windows Default Cobalt Strike PowerShell Beacon Windows Developer-Signed MSIX Package Installation Windows EFI Volume Mount Attempt Via Mountvol Windows Explorer.exe Spawning PowerShell or Cmd Windows Explorer LNK Exploit Process Launch With Padding Windows MSIX Package Interaction Windows Mustang Panda USB Tool Execution Windows NorthStar C2 Agent Execution Windows PowerShell Script From WindowsApps Directory Windows Suspect Process With Authentication Traffic Windows Suspicious QEMU Execution Windows Universal Data Link File Creation Windows User Execution Malicious URL Shortcut File Uncommon Processes On Endpoint Article-specific behavioural hunt — Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication [LLM] AUR helper or makepkg spawning npm/node to install atomic-lockfile or js-digest Article-specific behavioural hunt — Tracing Digital Intent: New MacOS Tahoe 26 Artifact Discovered Article-specific behavioural hunt — Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit [LLM] Atomic Arch: deps ELF execution by SHA256/MD5 or src/hooks/deps path [LLM] Atomic Arch — pacman/makepkg post-install spawning npm install of atomic-lockfile [LLM] Atomic Arch — ELF payload 'deps' written or executed under build/cache directories after AUR install Article-specific behavioural hunt — ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Univ Article-specific behavioural hunt — A tale of two eras [LLM] Talos weekly prevalent malware hash execution (Coinminer/Injector/Dropper.Miner) [LLM] Talos prevalent malware filename pattern — VID001.exe and d4aa3e70..._N_Exe.exe Article-specific behavioural hunt — Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspi [LLM] Miasma/Hades known-bad SHA256 execution on developer endpoint Article-specific behavioural hunt — npm v12 delivers one of the biggest security improvements in years Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-48039: Meta Ads MCP: Unauthenticated HTTP MCP Tool Ex [LLM] CVE-2026-48039 PoC artifact execution (meta-ads-mcp-vuln001 image, FAKE_TOKEN_FOR_POC_DEMO env) Article-specific behavioural hunt — Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories Article-specific behavioural hunt — OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack [LLM] SPECTRALVIPER known-bad SHA1 observed on disk or in process Article-specific behavioural hunt — OceanLotus: From external espionage to domestic targeting [LLM] SPECTRALVIPER known SHA1 sample sighting (ESET 2024-2026 IOC bundle) Article-specific behavioural hunt — GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks Article-specific behavioural hunt — Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE B Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-48030: Pheditor: OS Command Injection in terminal han Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-8467: PhoenixStorybook: Unauthenticated remote code e Article-specific behavioural hunt — Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositori [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Article-specific behavioural hunt — Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Conti [LLM] Miasma stealer payload SHA256 match on disk or in execution Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Article-specific behavioural hunt — Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47252: Anyquery: AppleScript/JXA Code Injection via U Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45034: PHPSpreadsheet has a patch bypass for CVE-2026 Article-specific behavioural hunt — One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public Article-specific behavioural hunt — AI brands as bait: How threat actors are using the AI hype in social engineering [LLM] Execution or drop of fake AI-platform installer (DeepSeek/Manus/Seedance/GPT-5.5/Kimi) Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47731: NASA AMMOS Instrument Toolkit: Path traversal Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47670: Authenticated Remote Code Execution via loadRe Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47669: DbGate: Zip Slip in archive/unzip allows arbit Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47668: DbGate: Unauthenticated Remote Code Execution Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47708: MCP-for-Stata: Command injection via log_file_ [LLM] Mini Shai-Hulud payload SHA256 on disk (7c24b4d9...e627144e8b) Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-8whc-2wmv-ww35: WWBN AVideo: Unauthenticated Stored DOM C Article-specific behavioural hunt — Reporting from Vegas: Networking, AI, and good boys [LLM] Talos weekly prevalent malware SHA256 IOC sweep (Coinminer / Procpatcher / KMS activator) Article-specific behavioural hunt — Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp Article-specific behavioural hunt — Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in bind Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44182: Jupyter Enterprise Gateway: Kubernetes Manifes [LLM] Argamal Loader Artifacts — natives2_blob.bin / Modified ffmpeg.dll IOC Sweep Article-specific behavioural hunt — Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing cam Article-specific behavioural hunt — Why EDR and proxy won’t save you from supply chain malware Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated June 2) Article-specific behavioural hunt — Multiple redhat-cloud-services npm Packages compromised Article-specific behavioural hunt — Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Re [LLM] Nx Console v18.95.0 Compromised VSIX / main.js / payload SHA-256 Hash Match [LLM] FlutterShell macOS payload SHA256 IOC match Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47413: praisonai-platform: Any workspace member can a Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47429: When Vitest UI server is listening, arbitrary Article-specific behavioural hunt — Containers on fire: from container escapes to supply chain attacks Article-specific behavioural hunt — Miasma supply chain attack: malicious code found in @redhat-cloud-services npm p Article-specific behavioural hunt — Malicious npm packages abuse dependency confusion to profile developer environme Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47416: praisonai-platform: Any workspace member can p Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47410: praisonai-platform: JWT signing key defaults t Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47407: PraisonAI Platform has a cross-workspace IDOR Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47391: PraisonAI's unauthenticated A2A official examp Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47392: PraisonAI vulnerable to sandbox escape via `pr Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47393: PraisonAI `deploy --type api` emits a Flask se Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47140: NodeVM builtin denylist bypass via process and Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47210: vm2 sandbox escape via JSPI-backed Promise `.f Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47137: vm2 has a CVE-2023-37903 patch bypass: nesting Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47131: vm2 has a Sandbox Escape issue Article-specific behavioural hunt — What’s in the container? Analyzing vulnerabilities, risks and protection with Ka Article-specific behavioural hunt — Typosquatted npm packages used to steal cloud and CI/CD secrets Article-specific behavioural hunt — Less panic patching, more precision Article-specific behavioural hunt — Pirates in the crosshairs: how one cybercrime gang has been infecting book, movi [LLM] HLS Installer.874.exe DLL side-load from pirate-streaming ZIP lure Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46621: Yamcs Vulnerable to Authenticated Remote Code Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46562: Yamcs Vulnerable to Remote Code Execution via Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45618: LiquidJS is Vulnerable to Remote Code Executio Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44632: Yamcs Vulnerable to Server-Side Code Injection [LLM] BTMOB Android RAT APK SHA256 sighting in file or email telemetry Article-specific behavioural hunt — Laravel Lang Supply Chain Advisory [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Article-specific behavioural hunt — Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer Article-specific behavioural hunt — Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Reposito Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46670: YesWiki: Unauthenticated SQL Injection [LLM] Screening Serpens recruitment lure — Hiring Portal.zip + job requisition PDFs Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46703: Boxlite: Path Traversal Vulnerability Leads to Article-specific behavioural hunt — The art of being ungovernable [LLM] Talos weekly prevalent-malware hash hit (Coinminer worm / TunMirror / SECOH-QAD / KMS-Loader) [LLM] Known Shai-Hulud / Nx Console implant hash match (SHA256/SHA1) Article-specific behavioural hunt — Dev Machine Guard Now Supports Linux Article-specific behavioural hunt — The Wild West of VS Code extensions and how a poisoned extension breached GitHub [LLM] TamperedChef shell-company code-signing certificate execution (CL-UNK-1090) [LLM] TamperedChef trojanized-app activation via --cm / --enableupdate / --fullupdate flags Article-specific behavioural hunt — GitHub breached via a malicious VS Code extension: why developer devices are the Article-specific behavioural hunt — CISA KEV: CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability Article-specific behavioural hunt — The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package C Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46339: 9router: Unauthenticated Remote Code Execution Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46395: HAXcms: Private Key Disclosure via Broken HMAC Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45721: Algernon: handler.lua discovery walks parent d Article-specific behavioural hunt — Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages Article-specific behavioural hunt — actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Article-specific behavioural hunt — Active Supply Chain Attack: Malicious node-ipc Versions Published to npm Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-wx9m-wx4f-4cmg: Malicious dropper in mistralai 2.4.6 PyPI [LLM] Gremlin Stealer packed sample SHA256 execution (2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b) Article-specific behavioural hunt — Malicious node-ipc versions published to npm in suspected maintainer account com Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45369: utcp-cli Vulnerable to Command Injection via U Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45374: DeepSeek TUI: task_create Insecure Defaults En Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-45311: DeepSeek TUI: run_tests Tool Enables RCE via M [LLM] DeepSeek-TUI spawning 'cargo test' — CVE-2026-45311 auto-approved run_tests pathway Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-44990: Apostrophe has default XSS via `xmp` raw-text Article-specific behavioural hunt — The time of much patching is coming [LLM] Talos weekly top-prevalent malware hash watch (Coinminer / Injector / W32.Variant) Article-specific behavioural hunt — Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-46442: FlowiseAI: Authenticated Host RCE via POST /ap [LLM] FrostyNeighbor JS dropper self-relaunch with --update flag Article-specific behavioural hunt — Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Article-specific behavioural hunt — Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools Article-specific behavioural hunt — PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Article-specific behavioural hunt — Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Article-specific behavioural hunt — A rigged game: ScarCruft compromises gaming platform in a supply-chain attack [LLM] BirdCall trojanized APK/mono.dll SHA1 match on Windows endpoints Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Article-specific behavioural hunt — elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub A Article-specific behavioural hunt — Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, Article-specific behavioural hunt — CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentia Article-specific behavioural hunt — Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud [LLM] Mini Shai-Hulud PyPI payload known SHA256 (start.py / router_runtime.js) Article-specific behavioural hunt — lightning PyPI Compromise: A Bun-Based Credential Stealer in Python Article-specific behavioural hunt — Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer Article-specific behavioural hunt — Someone published four versions of a fake "tanstack" package in 27 minutes to st Article-specific behavioural hunt — Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Reme Article-specific behavioural hunt — "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Article-specific behavioural hunt — Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomini [LLM] Roblox cheat/exploit download on enterprise endpoint (Lumma Stealer entry vector) Article-specific behavioural hunt — Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Wo Article-specific behavioural hunt — GopherWhisper: A burrow full of malware Article-specific behavioural hunt — GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Article-specific behavioural hunt — @velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via l Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Article-specific behavioural hunt — Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw Article-specific behavioural hunt — GlassWorm goes native: New Zig dropper infects every IDE on your machine Article-specific behavioural hunt — Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT Article-specific behavioural hunt — axios compromised on npm: maintainer account hijacked, RAT deployed Article-specific behavioural hunt — litellm: Credential Stealer Hidden in PyPI Wheel [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP [LLM] gofile.io archive download by browser followed by extracted-EXE execution within 30 minutes Article-specific behavioural hunt — Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags Article-specific behavioural hunt — CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Article-specific behavioural hunt — Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup- Article-specific behavioural hunt — bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys Article-specific behavioural hunt — Malicious npm Releases Found in Popular React Native Packages - 130K+ Monthly Do Article-specific behavioural hunt — Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wa Article-specific behavioural hunt — ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Article-specific behavioural hunt — xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Article-specific behavioural hunt — TeamPCP deploys CanisterWorm on NPM following Trivy compromise Article-specific behavioural hunt — fast-draft Open VSX Extension Compromised by BlokTrooper Article-specific behavioural hunt — Securing the Agent Skills Registry: How Snyk and Tessl Are Setting the Standard Article-specific behavioural hunt — DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laund [LLM] DRILLAPP variant 1 persistence: LNK file written to user Startup folder by non-Explorer process [LLM] DRILLAPP variant 2 delivery: CPL file executed from user-writable folder spawning Edge Article-specific behavioural hunt — kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package Article-specific behavioural hunt — Sednit reloaded: Back in the trenches Article-specific behavioural hunt — The 89% Problem: How LLMs Are Resurrecting the "Dormant Majority" of Open Source Article-specific behavioural hunt — Persistent XSS/RCE using WebSockets in Storybook’s dev server Article-specific behavioural hunt — Harden Runner Now Supports Windows and macOS GitHub Actions Runners Article-specific behavioural hunt — PlugX Meeting Invitation via MSBuild and GDATA Article-specific behavioural hunt — SvelteSpill: A Cache Deception Bug in SvelteKit + Vercel Article-specific behavioural hunt — Securing the Agent Skill Ecosystem: How Snyk and Vercel Are Locking Down the New Article-specific behavioural hunt — From detection to prevention: How Zen stops IDOR vulnerabilities at runtime Article-specific behavioural hunt — npm backdoor lets hackers hijack gambling outcomes Article-specific behavioural hunt — Exploitability Isn’t the Answer. Breakability Is. [LLM] Pastebin-piping stager retrieved from rentry.co/openclaw-core (macOS/Linux ClawHub skill) [LLM] Download of openclawcore-1.0.3.zip from denboss99 GitHub release (Windows OpenClaw skill payload) [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Article-specific behavioural hunt — Snyk Finds Prompt Injection in 36%, 1467 Malicious Payloads in a ToxicSkills Stu [LLM] npx invocation of known phantom package names disclosed by Aikido [LLM] VS Code (Code.exe/node) drops payload to %TEMP%\Lightshot staging directory Article-specific behavioural hunt — Gone Phishin': npm Packages Serving Custom Credential Harvesting Pages Article-specific behavioural hunt — Malicious PyPI Packages spellcheckpy and spellcheckerpy Deliver Python RAT Article-specific behavioural hunt — CISA KEV: CVE-2025-54313 — Prettier eslint-config-prettier Embedded Malicious Co Article-specific behavioural hunt — Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component Article-specific behavioural hunt — Critical Remote Code Execution Vulnerabilities Discovered in React Server Compon Article-specific behavioural hunt — How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstag Article-specific behavioural hunt — Sha1-Hulud: The Second Coming - Zapier, ENS Domains, and Other Prominent NPM Pac Article-specific behavioural hunt — Supply Chain Security Alert: eslint-config-prettier Package Shows Signs of Compr Article-specific behavioural hunt — Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE- Article-specific behavioural hunt — Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Article-specific behavioural hunt — Snyk Log Sniffer: AI-Powered Audit Log Insights for Security Leaders Article-specific behavioural hunt — Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages Article-specific behavioural hunt — PlushDaemon compromises network devices for adversary-in-the-middle attacks Article-specific behavioural hunt — Automated Package-Publication Incident IndonesianFoods in the NPM Ecosystem Link [LLM] Execution / write of ESET APT Q2-Q3 2025 known-bad SHA256 payload [LLM] Archive utility writing LNK/DLL/EXE to Windows Startup folder (RomCom CVE-2025-8088) Article-specific behavioural hunt — Snyk Studio brings security scanning and automated fixes to Factory's Droids Article-specific behavioural hunt — Gotta fly: Lazarus targets the UAV sector [LLM] DreamJob trojanized PDF/installer execution from job-lure decoy folder Article-specific behavioural hunt — Phishing Campaign Leveraging the NPM Ecosystem Article-specific behavioural hunt — CISA KEV: CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Article-specific behavioural hunt — CISA KEV: CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Article-specific behavioural hunt — s1ngularity: Popular Nx Build System Package Compromised with Data-Stealing Malw Article-specific behavioural hunt — Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack Article-specific behavioural hunt — npm Supply Chain Attack via Open Source maintainer compromise Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Article-specific behavioural hunt — When 'Changed Files' Changed Everything: Our Black Hat 2025 Presentation on the Article-specific behavioural hunt — Cursor IDE Malware Extension Compromise in $500k Crypto Heist [LLM] Cursor IDE or VS Code spawning PowerShell/WScript from extensions folder (Solidity Language malware chain) [LLM] Solidity Language Cursor extension known malicious SHA-256 hash present on disk or executed Article-specific behavioural hunt — Security Testing for Single-Page Applications (SPAs) Article-specific behavioural hunt — CVE-2025-29927 Authorization Bypass in Next.js Middleware Article-specific behavioural hunt — Unburdening Developers From Vulnerability Fatigue with Snyk Delta Findings Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Article-specific behavioural hunt — Can Snyk Detect JWT Security Issues? Article-specific behavioural hunt — Solving Security Challenges with Snyk Code and Symbolic AI Article-specific behavioural hunt — CISA KEV: CVE-2022-23748 — Dante Discovery Process Control Vulnerability Article-specific behavioural hunt — Creating SBOMs with the Snyk CLI Article-specific behavioural hunt — CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Article-specific behavioural hunt — Ultralytics AI Pwn Request Supply Chain Attack Article-specific behavioural hunt — Lottie Player npm package compromised for crypto wallet theft Article-specific behavioural hunt — The mysterious supply chain concern of string-width-cjs npm package Article-specific behavioural hunt — Proactive AppSec continuous vulnerability management for developers and security Article-specific behavioural hunt — Promise queues and batching concurrent tasks in Deno Article-specific behavioural hunt — Identifying insecure C Code with Valgrind and fixing with Snyk Code Article-specific behavioural hunt — Want to avoid a data breach? Employ secrets detection Article-specific behavioural hunt — CISA KEV: CVE-2024-7262 — Kingsoft WPS Office Path Traversal Vulnerability Article-specific behavioural hunt — Vulnerabilities in NodeJS C/C++ add-on extensions Article-specific behavioural hunt — A denial of service Regex breaks FastAPI security Article-specific behavioural hunt — 10 Dimensions of Python Static Analysis Article-specific behavioural hunt — Polyfill supply chain attack embeds malware in JavaScript CDN assets Article-specific behavioural hunt — Finding and fixing exposed hardcoded secrets in your GitHub project with Snyk Article-specific behavioural hunt — Essential Node.js backend examples for developers in 2024 Article-specific behavioural hunt — 10 modern Node.js runtime features to start using in 2024 Article-specific behavioural hunt — Fastify plugins as building blocks for a backend Node.js API Article-specific behavioural hunt — Preventing broken access control in express Node.js applications Article-specific behavioural hunt — Symmetric vs. asymmetric encryption: Practical Python examples Article-specific behavioural hunt — Building an npm package compatible with ESM and CJS in 2024 Article-specific behavioural hunt — Nine Docker pro tips for Node.js developers Article-specific behavioural hunt — Exploiting HTTP/2 CONTINUATION frames for DoS attacks Article-specific behavioural hunt — GitHub “besieged” by malware repositories and repo confusion: Why you'll be ok Article-specific behavioural hunt — 5 Node.js security code snippets every backend developer should know Article-specific behavioural hunt — Preventing server-side request forgery in Node.js applications Article-specific behavioural hunt — Preventing SQL injection attacks in Node.js Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Article-specific behavioural hunt — Build and deploy a Node.js security scanning API to Platformatic Cloud Article-specific behavioural hunt — Command injection in Python: examples and prevention Article-specific behavioural hunt — Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE? Article-specific behavioural hunt — Code injection in Python: examples and prevention Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Honey Baked Messages Article-specific behavioural hunt — Exploring WebExtension security vulnerabilities in React Developer Tools and Vue Article-specific behavioural hunt — File encryption in Python: An in-depth exploration of symmetric and asymmetric t Article-specific behavioural hunt — Dependency injection in Python Article-specific behavioural hunt — The art of conditional rendering: Tips and tricks for React and Next.js develope Article-specific behavioural hunt — Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & Article-specific behavioural hunt — Installing and managing Java on macOS Article-specific behavioural hunt — High severity vulnerability found in libcurl and curl (CVE-2023-38545) Article-specific behavioural hunt — Modern VS Code extension development tutorial: Building a secure extension Article-specific behavioural hunt — Security implications of cross-origin resource sharing (CORS) in Node.js Article-specific behavioural hunt — A guide to input validation with Spring Boot Article-specific behavioural hunt — Node.js vs. Deno vs. Bun: Performance & JavaScript Runtime Comparison Article-specific behavioural hunt — Using JLink to create smaller Docker images for your Spring Boot Java applicatio Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Article-specific behavioural hunt — Mitigating DOM clobbering attacks in JavaScript Article-specific behavioural hunt — Implementing TLS in Kubernetes Article-specific behavioural hunt — Finding and fixing insecure direct object references in Python Article-specific behavioural hunt — Swift deserialization security primer Article-specific behavioural hunt — XS leaks: What they are and how to avoid them Article-specific behavioural hunt — Building a security-conscious CI/CD pipeline Article-specific behavioural hunt — The importance of verifying webhook signatures Article-specific behavioural hunt — Using insecure npm package manager defaults to steal your macOS keyboard shortcu Article-specific behavioural hunt — The SecurityManager is getting removed in Java: What that means for youArticles citing this technique (308)
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-14
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high A tale of two eras art-40
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-45
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit [GHSA / CRITICAL] GHSA-jpvj-wpmj-h7rv: Supply chain compromise via malicious @cap-js/openapi art-123
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-159
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-238
crit The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-248
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-254
crit [GHSA / CRITICAL] CVE-2026-46395: HAXcms: Private Key Disclosure via Broken HMAC Implementation art-261
crit [GHSA / CRITICAL] GHSA-wx9m-wx4f-4cmg: Malicious dropper in mistralai 2.4.6 PyPI package art-272
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-315
med Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira art-347
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-352
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-434
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-470
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository art-652
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-673
med Creating SBOMs with the Snyk CLI art-1013
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1032
high Defense in Depth art-1278
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1328
med File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques art-1329
high Dependency injection in Python art-1346
crit Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133) art-1349
med Implementing TLS in Kubernetes art-1409