Researchers documented several malware campaigns that used fake software and trojanized packages to deliver credential theft and remote-access payloads. On Windows, a fake Resident Evil 9 mod from GitHub triggered a curl | cmd chain that deployed hidden batch, JavaScript, portable Node.js, portable Python, and an in-memory Go payload with browser theft, wallet targeting, hVNC-style control, webcam-related code, and exfiltration via Wormhole/B2 and Gofile; a separate fake AI video player installer led through Python bytecode, shellcode, and protected .NET loaders to PureRAT, which persisted through the Run key and communicated over authenticated WebSockets with agent.sm-veo.com. Another Windows campaign, dubbed Operation TURB00, used a Go loader and decoy console program to launch Vidar in memory, steal browser and application data, and install persistence through agt.dll and the CadenceOptimizer service running under svchost as LocalSystem.
On macOS, analysts reversed a fully undetected Atomic macOS Stealer (AMOS) sample distributed as a signed DMG, bypassed its anti-VM checks, and recovered an AppleScript payload that stole browser data, wallet files, Telegram Desktop data, documents, and system information before exfiltrating to 95.164.53.3/contact. In the software supply chain, a malicious PyPI package, nhmpy 2.4.7, masqueraded as NumPy while using a .pth file and an obfuscated JavaScript payload executed through Bun to harvest developer, cloud, CI/CD, registry, SSH, wallet, messaging, VPN, and AI-assistant secrets; it then spread using stolen GitHub tokens and malicious GitHub Actions workflows. Separately, a public Windows local privilege escalation exploit named REDSUN showed how attackers could turn standard-user access into NT AUTHORITY\SYSTEM by abusing a TOCTOU flaw involving NTFS and the Cloud Files API, creating a potential post-compromise path for malware already running on a host.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
A multi-stage Windows malware sample was analyzed and clustered into a broader Operation TURB00 Vidar campaign. The Go-based loader decrypted an in-memory Vidar payload, and analysis revealed the primary C2 turbo88ku[.]top, Telegram and Steam dead-drop fallbacks, credential theft, and persistence via the CadenceOptimizer service.
A Windows 11 system was compromised after the user installed a fake Resident Evil 9 / REFramework mod from a GitHub repository. The infection chain used a malicious DLL to launch a remote curl | cmd sequence and staged an infostealer/RAT that persisted for about eleven days.
The typosquatted PyPI package nhmpy 2.4.7, which bundled legitimate NumPy alongside a .pth autostart file and obfuscated JavaScript malware, was removed from PyPI after being identified as a credential-stealing supply-chain worm. The package harvested a wide range of secrets and propagated using stolen GitHub tokens and malicious GitHub Actions workflows.
A staged malware chain delivered as DriveVideoSetup-x64-0.1.0.exe was observed using fake Google Drive or SMVEO-themed video lures. Analysis linked the final payload Uwjoqtb.dll to PureRAT and documented persistence, certificate creation under %LOCALAPPDATA%\SMVEO\, and authenticated WebSocket communications with agent.sm-veo.com.
A researcher using the alias Chaotic Eclipse released the Nightmare-Eclipse exploit suite in April 2026, including the REDSUN local privilege escalation exploit. REDSUN abuses a TOCTOU race involving NTFS and the Windows Cloud Files API to let a standard user gain NT AUTHORITY\SYSTEM privileges.
A macOS malware campaign abused sponsored search results, a fake GitHub repository, and Homebrew-themed installation steps to trick a user into running a malicious Bash command. The chain installed legitimate Homebrew, harvested the user's password, downloaded an obfuscated second-stage binary named "update" from cfocares[.]com, and used anti-analysis and encoded runtime commands to deliver additional payloads.
A Fully Undetected Atomic macOS Stealer sample distributed as Installer_v2.7.8.dmg was reverse engineered, revealing anti-VM checks, an encrypted AppleScript payload, and exfiltration to 95.164.53.3/contact. The analysis recovered the decrypted osascript from memory and documented theft of browser data, wallet files, Telegram data, documents, and system information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
mrtiepolo.medium.com
Open sourcejuliangrtz.me
Open sourcemeltedinhex.com
Open sourceblog.lukeacha.com
Open sourcemedium.com
Open sourcegithub.com
Open sourcemedium.com
Open sourcedenwp.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.