September 5, 2026
- GOOP is live and iterating — malware masquerading as Babel on npm, delivered through fake job interviews (a Nike-branded front-end "project"), using Ethereum smart contracts for C2 resolution and updating its on-chain C2 mid-analysis; a parallel strand targets US trucking firms with VBS files posing as haul schedules (@vxunderground, trucking thread). Socket has described the campaign as DEV#POPPER-adjacent. · Supply Chain & Build Pipelines
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May