Nine malicious npm packages published by the dirtyblanket account on September 29, 2026, distribute a self-propagating Linux worm that installs a backdoor, steals SSH keys and npm tokens, and spreads via compromised machines to AUR packages and new npm versions. The worm uses a preinstall hook to download and execute a payload through the Internet Archive Wayback Machine, evading allowlists and version pinning.
MacSync, a Swift-based malware targeting macOS, has evolved to use public iCloud calendar events for payload delivery. The new variant includes an Objective-C backdoor disguised as Finder that can execute AppleScript, deploy malicious browser extensions, and establish persistence. The malware continues to spread through social engineering and fake applications.
MacSync, a Swift-based malware targeting macOS, has evolved to use public iCloud calendar events for payload delivery. The malware, distributed via ClickFix campaigns and fake applications, now includes a new Objective-C backdoor module disguised as Finder that enables remote code execution and persistence on infected systems.