Cybercriminals are leveraging Google ads to install an infostealer malware (“Atomic”) on macOS and Linux devices via a fake Homebrew website. The malware, sold as a $1,000 per month subscription, steals credentials, browser data and cryptocurrency wallets. The hackers have designed a fake ad that redirects users to a malicious site, brewe.sh instead of the genuine Homebrew site, brew.sh. The Homebrew team has expressed frustration at Google’s lack of action against such scams.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.