Threat Intelligence News from LevelBlue SpiderLabs
ID: c833c2f7-fde4-5f7e-a5b9-7c89ee3489ce
STIX ID: report--c833c2f7-fde4-5f7e-a5b9-7c89ee3489ce
Feed Name: LevelBlue SpiderLabs Blog
LevelBlue SpiderLabs details two major November developments: the resurgence of the Shai-Hulud supply-chain worm that trojanized 700+ npm packages and compromised tens of thousands of repositories to steal GitHub tokens, npm credentials, and cloud API keys via malicious preinstall scripts; and the coordinated takedown of the Rhadamanthys infostealer infrastructure that had supported hundreds of thousands of infected systems and millions of stolen credentials. The report also provides updated trackers, 11,616+ new IOCs, and detection/hunting improvements to help organizations audit dependencies, rotate credentials, enforce MFA, and harden CI/CD pipelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
