ReversingLabs

@reversinglabs.com

ReversingLabs is the trusted name in file and software security. RL - Trust Delivered.

📢 New ReversingLabs research: Copy, Paste, Compromise: The Tale of ClickFix The complete #ClickFix attack chain, the MaaS economy behind it, and an open-source #YARA rule validated against 4K+ samples — 123 of them lures that evaded every #Antivirus engine. 👇 www.reversinglabs.com/clickfix

ClickFix Threat Report: Copy, Paste, Compromise | ReversingLabs | ReversingLabs

Original RL research on ClickFix: the attack chain, the MaaS economy behind it, and the YARA detection strategy that catches what AV and EDR miss.

reversinglabs.com

48,000 CVEs in 2025. Only 58 posed a real, exploitable threat to enterprise supply chains. "Patch everything" is mathematically dead. The signal that matters: malware, tampering, exposed secrets. Go from noise to signal: www.reversinglabs.com/blog/noise-t... #AppSec #SoftwareSupplyChainSecurity

CVE noise drowns out software supply chain threats | RL Blog

48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

reversinglabs.com

🚨 Supply Chain Attack Alert! 🚨 31 @redhat-cloud-services hashtag#npm packages backdoored in 72 seconds! ReversingLabs has confirmed a large-scale, coordinated supply chain attack targeting the "@redhat-cloud-services" npm scope.

Megalodon compromised GitHub Actions YAML files across dozens of repos — base64-encoded credential stealer, C2 on RouterHosting LLC. RL retrohunted to a related campaign 2 weeks earlier. Same C2 pattern. Same adversary. IOCs + YARA rule published: hubs.ly/Q04hVW-v0

Researcher's Notebook: Hunting Megalodon Fossils | RL Blog

Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.

hubs.ly

RL documented 163 samples of the Dirty Frag Linux exploit (formerly Copy Fail), active malware — and developed YARA rules for identification. Patch the kernel. Run the queries. Deploy the rules. The detection gap is now. www.reversinglabs.com/blog/dirtyfr...

How Dirty Frag rose from the Linux exploit Copy Fail | RL Blog

RL researchers documented 163 samples tied to CVE-2026-31431, identified active malware adoption — and developed YARA rules to identify them.

reversinglabs.com

A new class of #AI-derived threats is raising red flags: #MCP post-deployment drift ("rug pull") attacks. They exploit trust of agents over time rather than at the initial point of compromise, which requires deeper visibility. Here's what you need to know. hubs.ly/Q04fhLR30

MCP client rug-pull attack worries mount for AppSec | ReversingLabs

This class of AI tool supply chain attack highlights how trust of agents can be exploited by threat actors.

hubs.ly

Malware is evolving—and targeting AI workflows. Our research on the PromptMink campaign shows how attackers are abusing AI coding agents like Claude to deliver crypto-stealing malware. This isn’t just prompt injection. It’s supply chain risk in a new form. Read: www.reversinglabs.com/blog/claude-...

Claude adds PromptMink malicious dependency to crypto agent | ReversingLabs

The malicious npm package has evolved into a dependency that allows attackers to access users’ crypto wallets and funds.

reversinglabs.com

🚨 New RL #ThreatResearch: The #Graphalgo fake developer recruiter interview campaign is back. RL researchers have uncovered a broader network of fake companies tied to this fake recruiter operation — plus new attacker techniques. Read what the RL team found: www.reversinglabs.com/blog/graphal...

Graphalgo fake recruiter-test campaign respawned | ReversingLabs

NK threat actors targeting crypto developers are back with an LLC and new techniques to hide malware. Here's RL's analysis.

reversinglabs.com

The axios supply chain attack should be front an center for #AppSec teams given it's wide reach. Here's RL's immediate-response checklist — and best practices for ongoing defense. Also learn how RL’s xBOM and Spectra Assure Community can help. 👇 www.reversinglabs.com/blog/axios-a...

Axios supply chain attack: How AppSec teams should respond | ReversingLabs

Here's an incident-response checklist and ongoing best practices. Plus: How RL’s xBOM and Spectra Assure Community can help.

reversinglabs.com

At #RSAC, JPMorgan Chase CISO Patrick Opet revisited third-party risk — and the supplier changes that followed. Is your organization learning the lesson on “trust debt”? Learn how to move beyond blind trust: www.reversinglabs.com/blog/opet-jp...

How JPMorgan Chase tackles third-party software ‘trust debt’ | ReversingLabs

JPMC CISO Patrick Opet discussed his open letter on third-party software risk — and the changes suppliers have made since.

reversinglabs.com

📢 Just dropped: New RL research! 👻 Ghost campaign returns via malicious #npm packages ⚠️ Phishes sudo passwords + hides behind fake install logs 🔍 www.reversinglabs.com/blog/npm-fak... 🛡️ Ask us about it — + Spectra Assure Community — at Booth #4328 #RSAC2026

Malicious npm packages use fake install logs to load RAT | ReversingLabs

The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

reversinglabs.com

🚨 RL researchers discovered a malicious package impersonating a legitimate Stripe package on #NuGet — marking a move away from blockchain-related targets while staying focused on financial development tools. Read here: www.reversinglabs.com/blog/malicio...

Malicious NuGet package targets Stripe | ReversingLabs

In this latest incident, threat actors target developers with a bogus package — a shift away from cryptocurrency development targets.

reversinglabs.com