Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:the_hacker_news, telegram, wave_d3
tags: report:microsoft_mstic, telegram, wave_d3
tags: telegram, wave_d3
tags: telegram, wave_d3
tags: telegram, wave_d3
tags: telegram, wave_d3
tags: telegram, wave_d3
tags: telegram, wave_d3
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Malicious npm packages abuse dependency confusion to profile developer environments A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering question
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals cre
Deduped connector weight from graph context.