CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

SMS Blaster Phishing Takedown and Supply Chain Attacks Highlight Rising Abuse of Legitimate Tools

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A coordinated law enforcement operation in Canada dismantled an SMS blaster phishing ring that impersonated cellular towers to deliver fraudulent SMS messages to tens of thousands of devices, harvesting sensitive credentials. In parallel, multiple software supply chain attacks exploited npm and PyPI ecosystems: a malicious npm package impersonating TanStack exfiltrated developer environment variables during installation, and a compromised PyPI package (elementary-data) leveraged a GitHub Actions script-injection vulnerability to deploy a credential stealer. Additional campaigns weaponized legitimate remote-control tools such as the Komari agent for SYSTEM-level backdoors and introduced next-generation phishing kits (Saiga 2FA, Phoenix System) integrating advanced post-compromise capabilities and telemetry for targeted attacks.

Timeline

  1. 30.04.2026 16:55 1 articles · 3h ago

    Law enforcement dismantles SMS blaster phishing ring; supply chain attacks escalate with npm and PyPI compromises

    A coordinated arrest of three individuals in Canada targeted an SMS blaster device that impersonated cellular towers to deliver phishing messages to tens of thousands of devices. In parallel, two separate software supply chain compromises were disclosed: an npm package impersonating TanStack exfiltrating developer environment variables during installation, and a compromised PyPI package (elementary-data) leveraging a GitHub Actions script-injection vulnerability to deploy a credential stealer. Concurrently, threat actors deployed the Komari agent as a SYSTEM-level backdoor following VPN credential compromise, and introduced next-generation phishing kits integrating advanced post-compromise capabilities and telemetry for targeted campaigns.

    Show sources

Information Snippets