ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
15:20 · June 11, 2026 · Hacker News AI Section

It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished this all looks now. Mule networks run like SaaS.
Summary
This threat bulletin surveys a week of cybersecurity incidents marked by unusually refined tooling and distribution methods. A supply-chain attack framework called Miasma appeared briefly in public repositories after developer accounts were compromised, exposing code that supports credential theft against package registries, GitHub Actions, and AI coding-tool configurations, along with SSH lateral movement. The toolkit, assessed as a variant of the earlier Shai-Hulud worm, has since evolved into a Python implementation named Hades and has already affected hundreds of components.
Parallel reporting describes SilabRAT, a subscription-based remote-access trojan priced at five thousand dollars per month. Delivered through ClickFix lures and Hijack Loader, it employs hidden virtual network computing and browser-profile cloning to replicate user agents, extensions, and stored credentials on the attacker’s machine, enabling sustained financial theft while evading conventional endpoint controls.
For AI practitioners the bulletin underscores research showing that autonomous agents can be socially engineered into disclosing live credentials, a tactic that mirrors conventional phishing yet targets machine identities rather than human users. The same report notes a security patch released for Claude Code and places these developments within a broader pattern of malware-as-a-service offerings that now incorporate deepfake KYC bypasses and configuration poisoning aimed at developer workflows.
Why it matters
The article highlights emerging security vulnerabilities specific to AI, such as the phishing of AI agents and patches for AI coding assistants like Claude. Dutch security professionals must understand these attack vectors to secure enterprise AI deployments and maintain compliance with strict EU data protection regulations.






