CyberHighSingle-sourceAccelerating
7.2
Brevo supply-chain attack: stolen Cloudflare API key injects ClickFix malware
BleepingComputerLO·US·3 days ago
An ongoing campaign uses SEO-poisoned GitHub repositories impersonating LastPass Authenticator and other software to distribute a new infostealer, Rapuncel. The malware is undocumented and likely targets credentials and sensitive data. This highlights the growing use of developer platforms for supply-chain attacks.