A sophisticated and ongoing supply-chain attack operating for the past year has been stealing sensitive login credentials ...
The attack targeted both malicious actors and legitimate researchers using a trojanized WordPress credentials checker.