<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #malware</title><description>Articles tagged malware on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Red Hat&apos;s npm namespace and Arch&apos;s AUR were both backdoored within two weeks of each other</title><link>https://devtake.dev/article/npm-registry-supply-chain-wave/</link><guid isPermaLink="true">https://devtake.dev/article/npm-registry-supply-chain-wave/</guid><description>A worm hijacked Red Hat&apos;s npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.</description><pubDate>Sat, 13 Jun 2026 12:45:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>open-source</category><category>malware</category><author>luca-reinhardt</author></item><item><title>116,000 Minecraft PCs got infected by fake mods. The &apos;WeedHack&apos; stealer is free to anyone.</title><link>https://devtake.dev/article/minecraft-weedhack-malware/</link><guid isPermaLink="true">https://devtake.dev/article/minecraft-weedhack-malware/</guid><description>McAfee says a free malware-as-a-service stealer called WeedHack has hit 116,000+ Minecraft systems via fake mods and cheats. Here&apos;s what it grabs and how to clean up.</description><pubDate>Wed, 03 Jun 2026 11:00:00 GMT</pubDate><category>gaming</category><category>gaming</category><category>minecraft</category><category>malware</category><category>security</category><category>credential-theft</category><category>infostealer</category><category>supply-chain</category><author>hiro-tanaka</author></item><item><title>DAEMON Tools shipped a signed backdoor for almost a month. Kaspersky says one school in Russia got the second stage.</title><link>https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</link><guid isPermaLink="true">https://devtake.dev/article/daemon-tools-supply-chain-backdoor/</guid><description>Kaspersky pinned a supply-chain attack on the DAEMON Tools installer dating to April 8. Thousands hit globally, dozens upgraded to a QUIC RAT implant via signed binaries.</description><pubDate>Wed, 06 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>daemon-tools</category><category>malware</category><category>kaspersky</category><category>quic-rat</category><category>code-signing</category><category>windows</category><author>luca-reinhardt</author></item><item><title>Malicious npm and PyPI packages turn dev servers into Chinese LLM proxies</title><link>https://devtake.dev/article/gpt-proxy-npm-supply-chain/</link><guid isPermaLink="true">https://devtake.dev/article/gpt-proxy-npm-supply-chain/</guid><description>Aikido found a stage-2 Go binary inside two health-check-themed packages that runs an OpenAI-compatible router routing Claude, GPT, and Gemini traffic through Chinese aggregators.</description><pubDate>Sat, 25 Apr 2026 07:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category><category>pypi</category><category>ai-security</category><category>malware</category><category>llm</category><category>china</category><category>credential-theft</category><author>luca-reinhardt</author></item></channel></rss>