<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #credential-theft</title><description>Articles tagged credential-theft on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>VS Code&apos;s webview sandbox leaks GitHub tokens that read and write every private repo</title><link>https://devtake.dev/article/vscode-zero-day-github-token-theft/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-zero-day-github-token-theft/</guid><description>A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.</description><pubDate>Wed, 03 Jun 2026 13:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>credential-theft</category><category>dev-tools</category><category>rce</category><category>supply-chain</category><category>oauth</category><author>luca-reinhardt</author></item><item><title>116,000 Minecraft PCs got infected by fake mods. The &apos;WeedHack&apos; stealer is free to anyone.</title><link>https://devtake.dev/article/minecraft-weedhack-malware/</link><guid isPermaLink="true">https://devtake.dev/article/minecraft-weedhack-malware/</guid><description>McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here&apos;s what it grabs and how to clean up.</description><pubDate>Wed, 03 Jun 2026 11:00:00 GMT</pubDate><category>gaming</category><category>gaming</category><category>minecraft</category><category>malware</category><category>security</category><category>credential-theft</category><category>infostealer</category><category>supply-chain</category><author>hiro-tanaka</author></item><item><title>ShinyHunters dumped 9.4GB of 7-Eleven franchisee data after a rejected ransom demand</title><link>https://devtake.dev/article/shinyhunters-7-eleven-breach-185k/</link><guid isPermaLink="true">https://devtake.dev/article/shinyhunters-7-eleven-breach-185k/</guid><description>ShinyHunters breached a 7-Eleven Salesforce instance holding franchisee documents, exposing 185,000 people. The 9.4GB archive hit a leak site after 7-Eleven declined to pay.</description><pubDate>Wed, 27 May 2026 18:35:00 GMT</pubDate><category>security</category><category>security</category><category>data-breach</category><category>shinyhunters</category><category>salesforce</category><category>extortion</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Scammers turned a Microsoft notification address into a spam relay. The emails pass SPF, DKIM, and DMARC.</title><link>https://devtake.dev/article/microsoft-internal-account-spam-abuse/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-internal-account-spam-abuse/</guid><description>Spammers found a Tenant Name injection in Entra ID that pushes fraud text into Microsoft&apos;s own OTP emails. The from-line reads msonlineservicesteam@microsoftonline.com.</description><pubDate>Mon, 25 May 2026 12:00:00 GMT</pubDate><category>security</category><category>security</category><category>microsoft</category><category>entra-id</category><category>phishing</category><category>dmarc</category><category>spamhaus</category><category>email-security</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>GitHub&apos;s internal repos were breached. The attacker came in through a poisoned VS Code extension.</title><link>https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</link><guid isPermaLink="true">https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</guid><description>GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee&apos;s device. The attacker claims to have exfiltrated 3,800 internal repositories.</description><pubDate>Fri, 22 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vscode</category><category>supply-chain</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A CISA contractor left GovCloud admin keys on public GitHub. The file was named &apos;Important AWS Tokens.txt&apos;.</title><link>https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</link><guid isPermaLink="true">https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</guid><description>GitGuardian found a public CISA repo with 844 MB of secrets, including AWS GovCloud admin keys. The repo sat open for six months.</description><pubDate>Thu, 21 May 2026 11:15:00 GMT</pubDate><category>security</category><category>security</category><category>cisa</category><category>github</category><category>supply-chain</category><category>credential-theft</category><category>aws</category><category>gitguardian</category><category>govcloud</category><author>luca-reinhardt</author></item><item><title>Twin contractors deleted 96 federal databases in 56 minutes. One asked an AI how to clear the logs.</title><link>https://devtake.dev/article/akhter-twins-opexus-database-deletion/</link><guid isPermaLink="true">https://devtake.dev/article/akhter-twins-opexus-database-deletion/</guid><description>A federal jury convicted Sohaib Akhter on May 7 of wiping 96 government databases at Opexus. His twin Muneeb queried an AI: &apos;how do I clear system logs from SQL servers.&apos;</description><pubDate>Fri, 15 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>insider-threat</category><category>opexus</category><category>eeoc</category><category>credential-theft</category><category>foia</category><category>policy</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>TanStack published its npm supply-chain postmortem. The attack chained three GitHub Actions flaws.</title><link>https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</link><guid isPermaLink="true">https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</guid><description>Attackers compromised 42 TanStack packages through a pull_request_target exploit, cache poisoning, and OIDC token theft. An external researcher caught it in 20 minutes.</description><pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>tanstack</category><category>github-actions</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>Chinese proxy networks sell Claude API access at 90% off. They harvest every prompt that passes through.</title><link>https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</link><guid isPermaLink="true">https://devtake.dev/article/chinese-grey-market-claude-api-stolen-credentials/</guid><description>A ChinaTalk investigation reveals how &apos;transfer stations&apos; resell Anthropic API access using stolen credentials, model substitution, and prompt harvesting.</description><pubDate>Sun, 10 May 2026 09:30:00 GMT</pubDate><category>ai</category><category>anthropic</category><category>claude</category><category>ai-security</category><category>credential-theft</category><category>china</category><category>supply-chain</category><category>ai-models</category><author>dieter-morelli</author></item><item><title>380,000 vibe-coded apps are sitting on the open web. 5,000 of them are leaking real data.</title><link>https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</link><guid isPermaLink="true">https://devtake.dev/article/vibe-coded-apps-expose-corporate-data/</guid><description>RedAccess found that AI coding tools like Lovable, Base44, and Replit default to public hosting, leaving medical records, bank internals, and corporate secrets indexed by Google.</description><pubDate>Sat, 09 May 2026 08:00:00 GMT</pubDate><category>security</category><category>security</category><category>ai-security</category><category>ai-agents</category><category>dev-tools</category><category>supply-chain</category><category>privacy</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>ShinyHunters hit Canvas LMS for the second time. 275 million student records, 9,000 schools.</title><link>https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</link><guid isPermaLink="true">https://devtake.dev/article/instructure-canvas-breach-shinyhunters-275m/</guid><description>ShinyHunters breached Canvas LMS again, claiming 275 million records from 9,000 schools. Names, emails, student IDs, and private messages exposed.</description><pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate><category>security</category><category>security</category><category>data-breach</category><category>instructure</category><category>canvas</category><category>shinyhunters</category><category>education</category><category>supply-chain</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Microsoft Edge keeps every saved password in cleartext memory. Microsoft calls it &apos;by design&apos;.</title><link>https://devtake.dev/article/microsoft-edge-cleartext-passwords-memory/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-edge-cleartext-passwords-memory/</guid><description>A researcher showed Edge decrypts the entire password vault at launch and leaves it in process memory. Chrome decrypts on demand. Microsoft says it&apos;s intentional.</description><pubDate>Tue, 05 May 2026 08:45:00 GMT</pubDate><category>security</category><category>security</category><category>microsoft</category><category>edge</category><category>browser-security</category><category>credential-theft</category><category>chromium</category><category>passwords</category><category>privacy</category><author>luca-reinhardt</author></item><item><title>Mini Shai-Hulud hit PyTorch Lightning. The 11.6M-download PyPI package shipped a credential stealer.</title><link>https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</link><guid isPermaLink="true">https://devtake.dev/article/pytorch-lightning-pypi-compromise-mini-shai-hulud/</guid><description>Two malicious lightning releases hit PyPI on April 30. The 42-minute window was enough to ship an RSA-encrypted infostealer to ML developers worldwide.</description><pubDate>Sat, 02 May 2026 09:00:00 GMT</pubDate><category>security</category><category>pytorch-lightning</category><category>pypi</category><category>supply-chain</category><category>mini-shai-hulud</category><category>credential-theft</category><category>python</category><category>ml</category><category>security</category><author>luca-reinhardt</author></item><item><title>70 million domains had a no-password root bypass. cPanel rushed an emergency patch.</title><link>https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</link><guid isPermaLink="true">https://devtake.dev/article/cpanel-whm-auth-bypass-cve-2026-41940/</guid><description>cPanel shipped fixes April 28 for a CVSS 9.8 auth bypass that walks attackers into shared-hosting panels with no password. WatchTowr says exploitation started before the patch.</description><pubDate>Fri, 01 May 2026 11:25:00 GMT</pubDate><category>security</category><category>security</category><category>cpanel</category><category>web-hosting</category><category>cve-2026-41940</category><category>auth-bypass</category><category>watchtowr</category><category>credential-theft</category><category>supply-chain</category><author>luca-reinhardt</author></item><item><title>Another npm worm: CanisterWorm hits 16 Namastex packages and reaches PyPI on the same hop</title><link>https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/canisterworm-namastex-npm-pypi-supply-chain/</guid><description>Socket flagged a self-propagating worm in @automagik/genie, pgserve, and 14 sibling Namastex Labs packages. It steals 40 credential categories and republishes itself.</description><pubDate>Tue, 28 Apr 2026 16:30:00 GMT</pubDate><category>security</category><category>npm</category><category>supply-chain</category><category>canisterworm</category><category>security</category><category>namastex</category><category>teampcp</category><category>pypi</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies</title><link>https://devtake.dev/article/gpt-proxy-npm-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/gpt-proxy-npm-supply-chain/</guid><description>Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.</description><pubDate>Sat, 25 Apr 2026 07:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>ai-security</category><category>malware</category><category>llm</category><category>china</category><category>credential-theft</category><author>luca-reinhardt</author></item><item><title>Bitwarden CLI got backdoored for 90 minutes. The worm calls itself &apos;Shai-Hulud: The Third Coming.&apos;</title><link>https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</link><guid isPermaLink="true">https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</guid><description>A malicious @bitwarden/cli@2026.4.0 hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.</description><pubDate>Thu, 23 Apr 2026 19:00:00 GMT</pubDate><category>security</category><category>bitwarden</category><category>shai-hulud</category><category>npm</category><category>supply-chain</category><category>worm</category><category>credential-theft</category><category>checkmarx</category><category>cicd</category><author>luca-reinhardt</author></item></channel></rss>