390,000 WordPress accounts stolen from hackers in supply chain attack
ID: 82788544-652e-50f8-9f65-1ba8aa31abca
STIX ID: report--82788544-652e-50f8-9f65-1ba8aa31abca
Feed Name: Bleeping Computer
Threat Score
Datadog Security Labs uncovered a year-long campaign by actor MUT-1244 that trojanized GitHub proof-of-concept repositories and used phishing to deploy malware which exfiltrated over 390,000 WordPress credentials plus SSH keys, AWS credentials and other secrets from hundreds of machines (including security researchers and threat actors); the attacks leveraged backdoored build files, malicious packages and droppers, and uploaded data to file-sharing services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
