CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (11 April 2026)

Published: Loading…

At a Glance

  • GitHub Dependabot and Renovate automatically propagated a malicious axios 1.14.1 package update into 895 repositories, with 95 merged pull requests reaching production systems.
  • Marimo pre-authentication RCE vulnerability CVE-2026-39987 was exploited within 10 hours via the /terminal/ws endpoint, enabling AWS credential theft from .env files.
  • Trojanised CPUID HWMonitor installer executes fileless .NET malware using PowerShell, MSBuild, and regsvr32, reconstructing payloads from obfuscated IPv6 scriptlets.
  • Infoblox identified an Android banking trojan linked to Cambodia K99 Triumph City, using government-impersonating domains and targeting users across 21 countries.
  • Google integrated a Rust-based DNS parser into Pixel 10 modem firmware using hickory-proto to mitigate memory-safety vulnerabilities in baseband processing.

Summary

Software supply chain compromise dominated activity, with automated dependency tools propagating malicious packages into hundreds of repositories at production scale. GitHub Dependabot and Renovate systems merged compromised axios updates into live environments without human review in multiple cases. Parallel reporting shows supply chain abuse extending across CI/CD workflows and repository automation mechanisms.

Critical application vulnerabilities were actively exploited within hours of disclosure across multiple platforms. Marimo CVE-2026-39987 enabled unauthenticated remote code execution via a WebSocket terminal endpoint exposed before authentication. Attackers used early exploitation to enumerate systems and extract AWS credentials from environment files.

Infrastructure-level malware campaigns expanded across Android ecosystems and third-party software installers. A trojanised CPUID HWMonitor installer delivered fileless .NET payloads through PowerShell and Windows-native execution chains. The malware reconstructed payloads in memory using obfuscated scriptlets and leveraged trusted system binaries for execution.

Mobile banking trojans and RAT-based ecosystems continued targeting consumer devices and enterprise users through distributed campaigns. Mirax Android malware used Meta advertisements and GitHub-hosted droppers to reach over 200,000 accounts in Spanish-speaking regions. The malware incorporated SOCKS5 residential proxy capabilities and dynamic HTML overlays for credential theft and traffic routing.

Regionalised malware-as-a-service infrastructure and espionage-linked mobile trojans showed continued operational scale across multiple continents. An Android banking trojan linked to Cambodia’s K99 Triumph City used government impersonation domains and forced-labour-linked scam operations targeting 21 countries. Infrastructure analysis identified segmented command-and-control systems supporting credential theft, biometric capture, and remote device control.

Baseband and firmware-level security developments focused on reducing memory-safety risks in modem environments. Google integrated a Rust-based DNS parser into Pixel 10 modem firmware using hickory-proto and GN build tooling. The implementation targeted memory-unsafe parsing components previously exploited in cellular modem remote code execution attacks.

Highlights of the Day

Marimo RCE Exploited Within Hours of Disclosure

A critical pre-authentication remote code execution flaw in marimo versions 0.20.4 and earlier allows attackers to gain a full interactive shell via the unauthenticated /terminal/ws WebSocket endpoint. Sysdig observed exploitation 9 hours and 41 minutes after disclosure, with attackers executing commands, enumerating files, and extracting AWS credentials from .env files in under three minutes. The vulnerability, tracked as GHSA-2679-6mx9-h9xc with a CVSS score of 9.3, was patched in version 0.23.0 after disclosure on 8 April 2026.

Dependency Bots Spread Malicious Packages Across Hundreds of Repositories

A malicious axios package version 1.14.1 published on 31 March 2026 triggered automated dependency updates within five minutes, with Dependabot committing upgrades to public repositories. GitGuardian observed at least 895 repositories adopting the compromised package, including 154 pull requests opened by Dependabot and Renovate automation tools. Analysis showed 95 automated pull requests were merged into main branches, including 50 without human interaction, allowing malicious code to reach production systems in under an hour.

Trojanised HWMonitor Installer Delivers Fileless .NET Malware

A trojanised CPUID HWMonitor installer executes a multi-stage attack chain using PowerShell, MSBuild, and regsvr32 to run malicious scriptlets without writing files to disk. The Clippy.sct scriptlet reconstructs a hidden .NET payload in memory from obfuscated IPv6 address arrays and executes it via BinaryFormatter deserialisation and dynamic invocation. The decoded payload instantiates a malicious class that loads additional components from a secondary file and executes shellcode using Windows APIs including VirtualAlloc and CreateThread. The attack uses living-off-the-land techniques and trusted Windows binaries to enable fileless execution and evade static detection.

Source: LevelBlue

Android banking trojan tied to Cambodia scam compound exposed

Infoblox Threat Intelligence identified an Android banking trojan linked to Cambodia’s K99 Triumph City compound after DNS query spikes in customer networks. The malware-as-a-service platform supports real-time surveillance, credential theft and biometric data exfiltration, operating through hundreds of government-impersonating domains across multiple regions. Infrastructure analysis found segmented command-and-control panels, overlapping Vigorish Viper activity, and campaigns targeting at least 21 countries linked to forced-labour scam centres.

Google embeds Rust DNS parser in Pixel modem firmware

Google has integrated a memory-safe Rust DNS parser into Pixel 10 cellular baseband modem firmware, targeting memory-safety vulnerabilities in DNS processing components. Google used the hickory-proto crate with no_std modifications, integrating it into modem firmware via GN-based Pigweed build tooling and C FFI interfaces. Previous research by Project Zero demonstrated remote code execution on Pixel modems over the internet, highlighting the complexity of the modem attack surface.

Mirax Android RAT Turns Phones Into Residential Proxy Nodes

Mirax Android RAT MaaS has been observed targeting Android users in Europe, particularly Spain, distributed via Meta advertisements reaching over 200,000 accounts. Mirax provides remote access, keylogging, dynamic HTML overlays, and SOCKS5 residential proxy functionality using Yamux multiplexing over WebSocket command and control channels. Campaigns use mobile-targeted dropper websites, device checks, and GitHub Releases for delivery, deploying multi-stage Android APKs with encrypted payloads and installation flows.

Daily Coverage

Developments
Dependency Bot AbuseMarimo Rce ExploitHwmonitor TrojanK99 Banking Trojan
Vulnerabilities
CVE-2026-39987Marimo < 0.23.0 (Critical)