Sophisticated Daxin Malware Reemerges in Taiwan with Additional Backdoor Capability

Daxin and its new Stupig backdoor persisted undetected for 13 years, exploiting outdated Java software to infiltrate Taiwan's high-tech manufacturing sector.

Daxin and its new Stupig backdoor persisted undetected for 13 years, exploiting outdated Java software to infiltrate Taiwan's high-tech manufacturing sector.

Millions of developers received malware through compromised npm packages; rotate credentials and audit systems immediately if your projects depend on AsyncAPI, Keyv, Axios, or @ctrl/tinycolor.

After healthcare data breaches, most major organizations offer one to two years of free credit monitoring and identity theft protection, though federal law doesn't require it.

Treasury sanctions VPN operator and cybercriminal suppliers for enabling 25+ ransomware groups targeting U.S. hospitals, governments, and financial firms.

Large enterprises and U.S. healthcare organizations face accelerating ransomware targeting, with enterprise attacks up 74% and healthcare enduring 2.3 attacks daily in H1 2026.

The attack exploits developer trust in open-source repositories.

Attackers can hijack Windows Defender using symbolic links, requiring only admin access and built-in Windows commands, leaving minimal forensic traces.

Learn what Dark Basin proved, what remains alleged, and how targeted climate groups can reduce phishing risk.

Use Sophos' victim survey to prioritize account security, MFA coverage, and faster ransomware containment.

Spot fake project pages, risky external downloads, and publisher gaps before trojanized software reaches your machine.