Dossier
credential stealer
Coverage of credential stealer in the Nexus archive.
- 400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer
Attackers hijacked over 400 packages in the Arch User Repository (AUR) to install a Rust-based credential stealer that harvests developer secrets. The malware can load an eBPF rootkit to hide itself when executed with root privileges. The AUR is a community-maintained package collection separate from Arch Linux's official repository.
- Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Threat actors are exploiting a patched security flaw in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware. Arctic Wolf reported that the campaign used trusted endpoint management infrastructure to deliver malware across managed endpoints, disguising the payload as a Fortinet endpoint update.