Kaspersky Labs has found malware named SparkCat in software development kits used for making Android and iOS apps. The malware, apparently developed by a Chinese speaker, scans images on devices for sensitive data, particularly cryptocurrency wallet recovery phrases. Downloaded about 242,000 times, it largely affects European and Asian users. It is disguised in both genuine and fake apps. Kaspersky suggests a supply chain attack or developer embedding.
ReversingLabs Identifies Novel ML Malware Hosted on Leading Hugging Face AI Model Platform
ReversingLabs has revealed a new malware attack technique called “nullifAI,” which targets machine learning models, such as AI platform Hugging Face. The technique employs the