LIVE · cybersecurity feed
Live wire

worm

supply chain attackhigh

Miasma Worm Exploits Developer Credentials in Supply Chain Attacks

A sophisticated supply chain attack, dubbed Miasma, has compromised numerous npm packages, including those under the @redhat-cloud-services namespace. Attackers exploited stolen developer credentials, which lingered in underground markets for weeks before being used to poison software packages. The worm also targeted AI coding assistants, expanding its attack surface to local developer environments.

CVE-2025-29927high

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts

A new credential theft framework dubbed PCPJack has been identified, capable of spreading across exposed cloud infrastructure. The tool not only harvests sensitive data from various cloud services but also actively removes artifacts associated with the threat actor group TeamPCP. PCPJack targets services like Docker, Kubernetes, and MongoDB, exfiltrating stolen information and seeking to infect additional systems.