Malicious Chrome extensions tied to ownership transfers push malware and steal data, exposing thousands to credential theft ...
Malicious npm package '@openclaw-ai/openclawai' downloaded 178 times installs GhostLoader RAT, stealing credentials and crypto wallets.
A new ClickFix attack variant uses fake CAPTCHA pages instructing victims to paste and execute malicious commands in Windows Terminal.
A newly discovered InstallFix campaign relies on malicious commands on cloned installation webpages to trick victims into installing malware.