4 min read
Lazarus Group Poisons Axios: Inside the npm Supply Chain Attack
Regarding yesterday's Axios npm supply chain poisoning incident, ThreatBook has conducted in-depth sample analysis and attack tracing. Drawing on...
4 min read
Regarding yesterday's Axios npm supply chain poisoning incident, ThreatBook has conducted in-depth sample analysis and attack tracing. Drawing on...
3 min read
Axios — one of the most foundational dependencies in the JavaScript ecosystem, with over 3.6 billion annual downloads — was compromised on npm on...
3 min read
On March 24, 2026, ThreatBook Research Team detected a large-scale supply chain attack targeting LiteLLM — a core component widely used across the AI...
3 min read
ThreatBook Research and Response Team has identified and tracked an organized threat group conducting a large-scale malware distribution campaign...
3 min read
This is the full technical companion to our campaign overview published in Part 1. It documents the Windows and macOS malware chains in detail, and...
2 min read
Last week, ThreatBook's endpoint detection product, OneSEC EDR, identified and fully captured an active attack targeting OpenClaw users. The attack...
3 min read
The Threat Landscape An Open Economy, an Outsized Target Singapore's unique geographic position and economic standing have made it a frontline...
2 min read
The Threat Landscape A City Built on Commerce — and Cross-Border Risk Hong Kong's cyberattack landscape reflects the city's unique position. Unlike...
11 min read
Executive Summary For months, the cybersecurity community tracked what appeared to be a sophisticated cybercrime organization dubbed "SilverFox"....