Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
First reported
Last updated
Happening score
H score 13
1 unique sources, 1 articles

Summary

Hide ▲

A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft. The operation uses bogus GitHub stars, inflated download counts, and AI-narrated YouTube tutorials to make the downloads look legitimate. A WordPress phishing page serves as the distribution hub, and the malware runs at startup to persist on infected systems. On macOS, a bundled unlocker script helps users bypass Apple quarantine and Gatekeeper, increasing the chance the unsigned app will run.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

About this happening: The OkoBot malware framework is actively running on Windows and using SeedHunter to steal hardware wallet recovery phrases, putting wallet owners and endpoint data at...

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

GitHub fake-repository infostealer campaign

Campaign
H score41 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage

Technical Analysis
H score23 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

About this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...

Timeline

  1. 18.06.2026 18:00 2 articles · 27d ago

    Rust clipboard hijacker campaign hides behind fake crypto tools and planted reputation signals

    Initial Disclosure

    An unnamed actor is using bogus GitHub stars, inflated SourceForge downloads, AI-narrated YouTube tutorials, planted VirusTotal votes, and a WordPress phishing hub to push booby-trapped crypto tools aimed at crypto traders and gamblers; the resulting Rust clipboard hijacker runs on Windows and macOS, persists at startup, watches the clipboard for wallet addresses, swaps them for attacker-controlled addresses, and on macOS adds an unlocker script to help users bypass Apple's quarantine and Gatekeeper.

    Show sources