CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 April 2026)

Published: Loading…

At a Glance

  • TeamPCP used a Trivy-stolen API key to breach a European Commission AWS environment, exposing data from at least 30 EU entities.
  • Malicious axios versions 1.14.1 and 0.30.4 shipped plain-crypto-js@4.2.1 after UNC1069 socially engineered maintainer access to the npm publishing environment.
  • Attackers weaponised Anthropic’s Claude Code source leak within 24 hours, pushing Vidar v18.7 and GhostSocks through fake GitHub Releases.
  • A React2Shell credential-harvesting campaign compromised more than 750 systems using automated scanning and the Nexus Listener collection framework.
  • Fake Coca-Cola and Ferrari recruitment pages harvested Google Workspace and Facebook credentials, with the Coca-Cola kit dynamically relaying MFA challenges.

Summary

TeamPCP used an API key stolen in the Trivy supply-chain compromise to access a European Commission AWS environment on 19 March. The intrusion affected 42 Commission clients and at least 29 other Union entities, with leaked data including names, usernames, email addresses, and 51,992 outbound email files.

Malicious axios releases 1.14.1 and 0.30.4 were published to npm after UNC1069 used a fake company persona, Slack workspace, and spoofed Teams call against a maintainer. The packages injected plain-crypto-js@4.2.1 and installed a cross-platform remote access trojan, remaining available for roughly three hours before removal. Reports also indicate other high-impact Node.js maintainers were targeted in the same coordinated social-engineering campaign.

Attackers turned Anthropic’s Claude Code source leak into malware lures within 24 hours by publishing fake GitHub repositories and trojanised Releases. The campaign delivered Vidar stealer v18.7 and GhostSocks through 38 branded archives, using a Rust dropper with anti-analysis checks and PowerShell routines that disable Microsoft Defender protections. A separate React2Shell campaign used automated scanning and the Nexus Listener framework to compromise more than 750 systems for credential harvesting.

Two recruitment-themed phishing operations impersonated Coca-Cola and Ferrari to capture account credentials through fake hiring workflows. The Coca-Cola lure used a counterfeit booking page and a simulated Chrome sign-in window that relayed credentials to an attacker backend and dynamically served MFA prompts. The Ferrari lure presented a fake careers portal that redirected victims to a spoofed Facebook login page.

A TrueConf zero-day was exploited in attacks on Asian government targets for reconnaissance, privilege escalation, and follow-on payload execution. Cisco IMC also received fixes for ten flaws, including CVE-2026-20093, which allows unauthenticated remote attackers to bypass authentication and gain Admin access. Critical ShareFile vulnerabilities can also be chained to bypass authentication and upload arbitrary files to servers.

Drift Protocol confirmed attackers drained about $285 million after abusing durable nonces to seize Security Council administrative powers and empty five vaults. A new SparkCat variant on the Apple App Store and Google Play Store was also found stealing cryptocurrency wallet recovery phrase images from seemingly benign mobile apps.

Highlights of the Day

North Korean Social Engineering Breached Axios Maintainer

Axios maintainer Jason Saayman said North Korean cluster UNC1069 used a fake company persona, a branded Slack workspace, and a spoofed Microsoft Teams call to trick him into installing a remote access trojan. The compromise gave the attackers access to his npm publishing environment, allowing them to release malicious axios versions 1.14.1 and 0.30.4 with the injected dependency plain-crypto-js@4.2.1. The tainted packages were available on npm for about three hours on 31 March 2026 before removal, and the malicious payload was reported to install a cross-platform RAT affecting macOS, Windows, and Linux.

LinkedIn Script Probes 6,000 Browser Extensions

BleepingComputer found LinkedIn loading obfuscated JavaScript that checks Chromium browsers for 6,236 installed extensions by probing extension resource URLs, while also collecting device and browser telemetry including CPU cores, memory, timezone, battery status, and audio data. LinkedIn said the detection is used to identify extensions that scrape member data or violate its terms, but the BrowserGate report alleges the scan list includes competitor sales tools, job-search add-ons, and other extensions that can expose identifiable user and company information. BleepingComputer verified the extension-scanning behaviour but said it could not independently confirm claims that LinkedIn uses the results for enforcement or shares the data with third parties.

EU Cloud Breach Exposed Data Across 30 Institutions

CERT-EU said TeamPCP breached a European Commission AWS environment on 19 March using an API key stolen in the Trivy supply-chain compromise, then ran TruffleHog, created a new access key, and conducted reconnaissance. The attackers exfiltrated about 91.7 GB of compressed data from the europa.eu hosting platform, affecting 42 European Commission clients and at least 29 other Union entities. CERT-EU said the leaked dataset published by ShinyHunters includes names, usernames, email addresses, and at least 51,992 outbound email files, while finding no evidence of website tampering or lateral movement into other Commission AWS accounts.

Fake Claude Code Repos Push Vidar Malware on GitHub

Trend Micro says threat actors began abusing Anthropic’s accidental Claude Code source leak within 24 hours, creating fake GitHub repositories and trojanised Releases that delivered Vidar stealer v18.7 and GhostSocks proxy malware. The campaign used disposable GitHub accounts, 38 branded 7z archives across more than 25 software lures, and a Rust-compiled dropper with anti-analysis checks, XOR-encrypted strings, and PowerShell routines that disable multiple Microsoft Defender protections. Anthropic’s npm package version 2.1.88 exposed roughly 512,000 lines of internal TypeScript through a 59.8 MB source map file, while Trend Micro identified at least two Claude Code-themed repositories and six related GitHub distribution URLs tied to the broader operation.

Fake Coca-Cola and Ferrari Job Lures Steal Login Credentials

Malwarebytes identified two phishing campaigns impersonating Coca-Cola and Ferrari, using fake recruitment workflows to steal Google Workspace and Facebook credentials from job seekers. The Coca-Cola lure used a counterfeit Calendly-style booking page and a simulated Chrome sign-in window that relayed credentials to an attacker backend, polled every three seconds, and dynamically served MFA prompts for SMS, authenticator apps, email codes, or Google phone approvals. The Ferrari campaign presented a fake careers portal with a pop-up job invitation that redirected victims to a spoofed Facebook login page, while the Coca-Cola kit also rejected @gmail.com addresses to focus on higher-value corporate accounts.

Daily Coverage

Developments
Eu Cloud BreachAxios CompromiseClaude Code LureDrift Theft
Vulnerabilities
CVE-2026-35616Forticlientems 7.4.5 (Critical)CVE-2026-20093Cisco Enterprise Nfv Infrastructure Software 4.1.1 (Critical)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.