Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (1 April 2026)
Published: Loading…
At a Glance
- Axios npm package versions 1.14.1 and 0.30.4 were backdoored with plain-crypto-js 4.2.1, deploying WAVESHAPER.V2 RAT across Windows, macOS, and Linux systems.
- Cisco source code from over 300 repositories was stolen using credentials obtained from the Trivy supply chain compromise, impacting customer and internal projects.
- Phantom Stealer campaigns targeted European logistics, manufacturing, and tech firms, exfiltrating browser credentials, cookies, session data, and payment information via .NET droppers.
- Lloyds mobile banking glitch exposed up to 447,936 customers’ transaction data, including sort codes, account numbers, and National Insurance numbers for several hours.
- Claude AI-assisted research identified remote code execution flaws in Vim and GNU Emacs, triggered on file open and executable via modelines or Git integration.
- LevelBlue demonstrated passive BLE device tracking bypassing MAC address randomisation by correlating RF power levels across randomized address cycles in observed environments.
Summary
The Axios npm package was compromised in a supply chain attack, with versions 1.14.1 and 0.30.4 deploying the WAVESHAPER.V2 remote access trojan across multiple operating systems. The malicious releases included a backdoored dependency plain-crypto-js 4.2.1, installing a multi-stage trojan capable of data exfiltration and arbitrary command execution.
Cisco suffered a source code breach after attackers used credentials stolen from the Trivy supply chain compromise. Over 300 repositories, including internal and customer projects, were accessed, along with multiple AWS keys enabling lateral activity across development environments.
Phantom Stealer campaigns targeted European logistics, manufacturing, and technology sectors via spoofed procurement-themed emails carrying .NET droppers. The malware exfiltrated credentials, session data, payment cards, and cookies across browsers, messaging platforms, and email clients.
A software update on Lloyds Banking Group’s mobile application exposed up to 447,936 users’ current account transactions. Sensitive information including sort codes, account numbers, National Insurance numbers, and payment references were temporarily visible for several hours.
Claude AI-assisted testing revealed remote code execution vulnerabilities in Vim and GNU Emacs. In Vim, malicious modelines executed commands upon file open, patched in version 9.2.0272, while Emacs Git integration allowed arbitrary script execution without patching.
LevelBlue demonstrated that passive tracking of Bluetooth and BLE devices can bypass MAC address randomisation. Correlation of RF power levels across randomized addresses allowed persistent device fingerprinting without active connections.
Highlights of the Day
Malicious Dependency Compromises Axios npm Releases
A supply chain attack on Axios has injected the malicious package plain-crypto-js@4.2.1 into npm releases axios@1.14.1 and axios@0.30.4, deploying a multi-stage remote access trojan capable of exfiltrating data, executing arbitrary commands, and persisting on infected systems. The affected releases were published outside Axios’s normal GitHub workflow, suggesting unauthorised access to publishing credentials and a break in standard release controls. Additional impacted packages include @shadanai/openclaw and @qqbrowser/openclaw-qbot, which distribute the trojanised dependency through vendored paths, extending the compromise across multiple npm modules.
Phantom Stealer Campaign Delivers Credential Theft via Phishing Emails
Between November 2025 and January 2026, Phantom Stealer campaigns targeted European logistics, manufacturing, and technology firms using spoofed procurement-themed phishing emails carrying archive attachments with obfuscated JavaScript droppers or malicious executables. The .NET-based infostealer harvested browser credentials, cookies, payment cards, Wi-Fi keys, and session data from Chrome, Firefox, Discord, Telegram, and Outlook, exfiltrating it via Telegram, Discord, SMTP, or FTP. Group-IB’s Business Email Protection and Malware Detonation Platform blocked all waves, detecting SPF/DKIM failures, impersonated senders, reused templates, and staged payload execution across multiple campaign waves.
Lloyds Mobile Banking Glitch Exposes 450,000 Users’ Transaction Data
A software update on 12 March 2026 caused Lloyds Banking Group’s mobile banking platform to temporarily display other users’ current account transactions, affecting up to 447,936 customers who logged in during the incident. Of these, 114,182 users accessed detailed transaction data, including sort codes, account numbers, National Insurance numbers, and payment references, with some entries linked to non-Lloyds account holders. The bank resolved the issue within five hours, confirmed no unauthorised transfers occurred, and issued roughly £139,000 in goodwill payments to 3,625 affected customers.
RF Power Levels Can Bypass MAC Address Randomisation for Tracking
LevelBlue researchers demonstrated that passive tracking of Bluetooth Low Energy devices is possible despite MAC address randomisation by correlating Received Signal Strength Indicator (RSSI) values across address cycles. By observing when a device disappears and a new randomized MAC appears with similar power levels in close time proximity, the technique links old and new addresses without active connections. The proof-of-concept successfully tracked a smartphone among BLE traffic, highlighting persistent device fingerprinting risks in 802.11, Bluetooth, and BLE environments.
Cisco Source Code Stolen via Trivy Supply Chain Breach
Threat actors used stolen credentials from the Trivy vulnerability scanner compromise to access Cisco’s internal development environment, exfiltrating source code from over 300 GitHub repositories, including AI-powered products and unreleased software. The breach also involved theft of multiple AWS keys, enabling unauthorised activity across several Cisco accounts, and impacted developer and lab workstations, with some customer repositories—including banking and US government code—accessed. Security researchers linked the attack to the TeamPCP group, which has conducted a series of supply chain attacks on GitHub, PyPI, NPM, and Docker platforms using their TeamPCP Cloud Stealer malware.
Claude AI Discovers RCE Vulnerabilities in Vim and Emacs
Researcher Hung Nguyen used Claude AI to identify remote code execution (RCE) flaws in Vim and GNU Emacs, triggered simply by opening a file. The Vim vulnerability affects all versions up to 9.2.0271, allowing attackers to execute arbitrary commands via malicious modelines, and has been patched in version 9.2.0272. The GNU Emacs flaw exploits Git integration, where opening a file in an attacker-controlled repository can execute arbitrary scripts through core.fsmonitor, but maintainers attribute the issue to Git and have not issued a patch.
Daily Coverage