
Sep 22, 2026 · 7 min
ShinyHunters hijacks Clop site amid extortion dispute
ShinyHunters hijacks Clop, fake LastPass kills security tools, trusted npm release carries malware
The episode shows how criminal-group infighting can turn victim data, ransom payments, and trusted software channels into fresh threats.
- 1ShinyHunters defaced Clop’s leak site and threatened to expose ransom-paying victims, payment amounts, and Bitcoin addresses.
- 2Fake LastPass installers reportedly disable security tools, raising the risk of credential theft and weakened defenses.
- 3A trusted npm release carried GHAPPIER malware, showing how software distribution can undermine established security controls.
Don't miss
ShinyHunters’ threat to publish Klopp’s ransom-paying victims, payment amounts, and Bitcoin addresses turns a group dispute into a broader exposure threat.
The brief
Sarah Lane leads a briefing on a widening cybercrime story: ShinyHunters has taken over and defaced Klopp’s dark web leak site during an exploit-related dispute.
The takeover carries an added threat: ShinyHunters says it may reveal companies that paid Klopp, how much they paid, and the associated Bitcoin addresses.
The episode also flags fake LastPass installers that disable security tools, turning a familiar password-management name into a lure for weakening defenses.
A trusted npm release reportedly carried GHAPPIER malware, underscoring how attackers can exploit software ecosystems rather than only targeting end users directly.
Together, the headlines point to a broader risk: criminal disputes, impersonation, and trusted distribution channels can all become mechanisms for secondary compromise.