#trojanized
Hey guys time to uncover a trojanized XWorm Rat builder 💞
January 27, 2025 at 2:35 PM
Researchers have identified trojanized X-VPN installers distributing STX RAT malware. The legitimate X-VPN service remains secure; the threat is isolated to malicious downloads hosted by attackers outside official channels.
June 12, 2026 at 8:15 PM
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
A financially motivated Russian threat actor tracked as UAT-11795 is using trojanized software to steal credentials and cryptocurrency by deploying a new backdoor called Starland RAT. [...]
www.bleepingcomputer.com
July 16, 2026 at 10:33 AM
The Sandworm russian military cyber-espionage group is targeting Windows users in #Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates.

www.bleepingcomputer.com/news/securit...
Russian military hackers deploy malicious Windows activators in Ukraine
The Sandworm Russian military cyber-espionage group is targeting Windows users in Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates.
www.bleepingcomputer.com
February 15, 2025 at 2:20 AM
BASED BASED BASED BASED BASED FREE HIM HE DIDN'T DO ANYTHING WRONG
May 4, 2025 at 2:30 AM
New Research: Trojanized Open VSX extensions are shipping GlassWASM, a new WebAssembly malware variant.

It hides malware logic in TinyGo-compiled WASM and pulls C2 instructions from Solana transaction memos.

socket.dev/blog/glasswa...
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ...
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.
socket.dev
June 16, 2026 at 1:10 AM
🚨 Major active supply chain attack just hit npm.

Popular package @​ctrl/tinycolor was trojanized — and it didn’t stop there. Over 40 packages were silently modified to steal secrets from dev machines & CI pipelines.

Our team at Socket caught it. Full report coming soon. Stay safe out there.
September 16, 2025 at 3:10 AM
alt text: "Kramer, operating under the alias 'NullBulge,' created and distributed a malicious program disguised as an AI art generation tool. The uploaded this trojanized" (screencap ends there)
full, uncritical support of Disney hacker "NullBulge"
May 4, 2025 at 12:58 AM
no way to prevent this says only package manager where this regularly happens
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign.
www.bleepingcomputer.com
November 24, 2025 at 7:21 PM
SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials.
SonicWall warns of trojanized NetExtender stealing VPN logins
SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials.
www.bleepingcomputer.com
June 24, 2025 at 8:36 PM
A fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user's computer into a residential proxy node.
Malicious 7-Zip site distributes installer laced with proxy tool
A fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user's computer into a residential proxy node.
www.bleepingcomputer.com
February 10, 2026 at 7:13 PM
The ongoing attack has stolen sensitive login credentials from both malicious and benevolent security personnel by infecting them with Trojanized versions of open source software from GitHub and NPM.
Yearlong supply-chain attack targeting security pros steals 390K credentials
Multifaceted, high-precision campaign targets malicious and benevolent hackers alike.
arstechnica.com
December 16, 2024 at 6:10 PM
A trojanized ad-tech script quietly swapped visitors' crypto wallet addresses in real time. https://intel.threadlinqs.com/threat/TL-2026-2656 #ThreatIntel #DoublePulsar #Adform #SupplyChainAttack
September 26, 2026 at 12:54 PM
North Korean hackers, aka Diamond Sleet, spread a trojanized version of CyberLink's legit app.
Beware - They're using supply chain tricks to smuggle in malicious code.
Learn more about this attack : thehackernews.com/2023/11/nort...
North Korean Hackers Distribute Trojanized CyberLink Software in Supply Chain Attack
North Korean hackers, aka Diamond Sleet, spread a trojanized version of CyberLink's legit app.
thehackernews.com
November 23, 2023 at 6:16 AM
bah now I'm seeing "this is why you turn off auto-updates" and my god 'power users' and professional nerds are worse than gamers with the "I never get viruses because I'm smart" smugness
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
CPUID breach served STX RAT via trojanized CPU-Z downloads on April 9–10, impacting 150+ victims and multiple industries.
thehackernews.com
April 14, 2026 at 11:32 PM
lol "trojanized"
April 14, 2026 at 11:34 PM
#Sandworm Russian military cyber-espionage group is targeting Windows users in Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates. #RussiaUkrainewar #CyberAttacks www.bleepingcomputer.com/news/securit...
Russian military hackers deploy malicious Windows activators in Ukraine
The Sandworm Russian military cyber-espionage group is targeting Windows users in Ukraine with trojanized Microsoft Key Management Service (KMS) activators and fake Windows updates.
www.bleepingcomputer.com
February 12, 2025 at 3:18 AM
🚨 Active npm supply chain attack: keyv​@​6.0.0 and 13 other packages have been compromised. keyv alone gets 154M weekly downloads.

The worm steals cloud and CI credentials, then uses stolen npm tokens to publish trojanized versions of more packages.
August 4, 2026 at 12:20 PM
Not a game:

200+ Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers

thehackernews.com/2025/06/67-t...

@hackernews.bsky.social

#infosec #github #gamers #trojan
200+ Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
A new cybersecurity campaign has exposed 67 trojanized GitHub repositories, targeting gamers and developers with malicious Python tools.
thehackernews.com
June 22, 2025 at 4:20 PM
Threat actors have been distributing trojanized versions of the KeePass password manager for at least eight months to install Cobalt Strike beacons, steal credentials, and ultimately, deploy ransomware on the breached network.
Fake KeePass password manager leads to ESXi ransomware attack
Threat actors have been distributing trojanized versions of the KeePass password manager for at least eight months to install Cobalt Strike beacons, steal credentials, and ultimately, deploy ransomware on the breached network.
www.bleepingcomputer.com
May 19, 2025 at 9:17 PM
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now.

As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file
April 10, 2026 at 6:03 AM
🚨 Update: The "Shai-Hulud" supply chain attack has expanded to nearly 500 trojanized npm packages, including several from CrowdStrike, all using the same malware first seen in Tinycolor.

Full details and package list: socket.dev/blog/ongoing... #NodeJS #JavaScript
Ongoing Supply Chain Attack Targets CrowdStrike npm Packages...
Socket detected multiple compromised CrowdStrike npm packages, continuing the "Shai-Halud" supply chain attack that previously hit Tinycolor and dozen...
socket.dev
September 16, 2025 at 6:15 PM