<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Developer-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/developer-security/</link><description>Recent content in Developer-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 09:51:28 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/developer-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Fake Open-Source Sites Deliver Malware via TDS</title><link>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-tds-malware-remus-stealer-sessiongate/</link><pubDate>Thu, 04 Jun 2026 09:51:28 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fake-open-source-sites-tds-malware-remus-stealer-sessiongate/</guid><description>Attackers clone open-source project sites, rank them on Google, and use a Traffic Distribution System to deliver stealers and session hijacking malware to</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">The Hacker News</a></p>
<hr>
<p>Attackers have created convincing fake websites impersonating popular open-source tools, optimising them to rank highly on Google search results. Visitors are silently routed through a Traffic Distribution System (TDS) that delivers malware including credential stealers and session hijacking frameworks. This is a supply chain-adjacent threat targeting developers and technical users who search for and download software directly from the web.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Enforce organisational policies requiring software to be sourced only from verified package managers (npm, PyPI, etc.) or official repositories, and block direct binary downloads from unvetted sites via web proxy or CASB controls. Consider adding developer workstations to your threat model and ensure EDR coverage extends to engineering endpoints.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/fake-sites-mimicking-open-source-tools.html">Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS</a></p>
]]></content:encoded></item></channel></rss>