Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (23 April 2026)
Published: Loading…
At a Glance
- Self-propagating npm supply chain attacks used CanisterWorm malware to steal developer tokens, exfiltrate secrets, and republish compromised packages across ecosystems.
- Over 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to an actively exploited spoofing flaw used in ongoing zero-day attacks.
- Malicious npm and PyPI packages deployed hidden LLM proxy backdoors, enabling reverse shells, SOCKS5 tunnelling, and routing AI API traffic through attacker-controlled infrastructure.
- A ransomware affiliate reused Cobalt Strike infrastructure and SystemBC malware across LockBit, Black Basta, and Qilin campaigns using shared watermark identifiers.
- North Korean-linked operations used fake IT worker infrastructure with VPNs and freelance platforms to infiltrate organisations and facilitate sanctions evasion workflows.
- Mirai botnet variants actively exploited CVE-2025-29635 in D-Link routers to spread infections and expand distributed denial-of-service infrastructure.
Summary
Supply chain attacks escalated with multiple npm and PyPI compromises distributing credential-stealing malware and self-propagating worms targeting developer environments. Compromised packages deployed CanisterWorm-style payloads that exfiltrate secrets, steal authentication tokens, and republish infected versions across ecosystems. Additional campaigns installed hidden LLM proxy backdoors enabling reverse shells, SOCKS5 tunnelling, and covert routing of AI API traffic through attacker-controlled infrastructure.
Critical vulnerabilities remained widely exposed across enterprise systems, including more than 1,300 internet-facing Microsoft SharePoint servers affected by an actively exploited spoofing flaw. Microsoft released emergency updates addressing CVE-2026-40372 in ASP.NET Core, a high-severity privilege escalation vulnerability. Other disclosures included a sandbox escape flaw in Terrarium enabling root-level code execution and a firewall bypass vulnerability affecting MOVEit WAF deployments.
Ransomware activity showed continued infrastructure reuse, with a single affiliate linked to LockBit, Black Basta, and Qilin operations through shared Cobalt Strike configurations and SystemBC malware. The actor leveraged consistent tooling, including CountLoader payloads, across multiple campaigns spanning several years. Separately, a Kyber ransomware variant targeting Windows and VMware ESXi systems introduced post-quantum encryption techniques in active attacks.
Nation-state operations included North Korean campaigns using fake IT worker personas to infiltrate organisations via freelance platforms and VPN-backed infrastructure. Additional DPRK-linked activity targeted macOS systems using AppleScript and ClickFix techniques against financial and cryptocurrency entities. Chinese-linked espionage activity continued with updated LOTUSLITE malware targeting banking and policy organisations in Asia.
Botnet and malware campaigns expanded through exploitation of network devices and destructive attacks on critical infrastructure. Mirai variants exploited CVE-2025-29635 in D-Link routers to recruit devices into botnets, while parallel campaigns targeted routers and DVR systems. A newly identified Lotus Wiper malware conducted destructive attacks against Venezuela’s energy sector, systematically deleting files and overwriting system data.
Initial access trends shifted as phishing re-emerged as the leading intrusion vector, accounting for over one-third of observed compromises in early 2026. Attackers increasingly combined phishing with AI-assisted tooling, credential harvesting, and abuse of legitimate software such as remote access tools. Data breaches in the financial sector remained predominantly financially motivated, with credential theft and fraud operations driving large-scale monetisation.
Highlights of the Day
Compromised npm Packages Spread Worm-Like CanisterWorm Malware
Socket researchers identified compromised npm packages including @automagik/genie and pgserve carrying install-time malware that steals credentials, harvests environment secrets, and exfiltrates data via HTTPS webhooks and Internet Computer canister endpoints. The payload targets developer systems by extracting SSH keys, cloud credentials, browser data, and crypto wallet files, then encrypts and transmits the data using AES-256-CBC and RSA-OAEP schemes. The malware includes self-propagation logic that steals npm tokens to republish infected packages and deploys Python .pth-based payloads to spread across PyPI ecosystems.
Malicious npm and PyPI Packages Deploy Hidden LLM Proxy Backdoor
Aikido researchers discovered malicious npm and PyPI packages kube-health-tools and kube-node-health that deploy a Go-based backdoor installing an OpenAI-compatible LLM proxy on compromised Linux servers. The malware downloads a second-stage binary from GitHub, establishes WebSocket command-and-control via sync.geeker.indevs[.]in, and exposes reverse tunnels to local services including SSH and HashiCorp Vault. The implant provides SOCKS5 proxying, reverse shell access, SFTP file control, and routes AI API traffic through attacker-controlled endpoints while deleting installation traces and disguising itself as a system process.
Malicious Xinference PyPI Versions Steal Cloud and API Credentials
Malicious Xinference versions 2.6.0 to 2.6.2 were uploaded to PyPI with obfuscated code executing a base64-encoded payload on import to steal credentials and system data. The infostealer collects AWS and Google Cloud configurations, Kubernetes tokens, SSH keys, API secrets, database credentials, cryptocurrency wallets, and environment variables, then exfiltrates them to a remote server. The compromised package, downloaded over 600,000 times, was linked to a breached automation account, while TeamPCP references in the code were publicly denied by the group.
Ransomware Affiliate Linked Across LockBit, Black Basta, and Qilin
Silent Push identified a Cobalt Strike command-and-control server at 91.107.247[.]163 linked to a February 2026 ransomware intrusion involving The Gentlemen RaaS, using previously detected infrastructure. Analysis of Cobalt Strike watermark identifiers 1473793097 and 1357776117 enabled attribution of the activity to a single affiliate associated with LockBit, Black Basta, and Qilin campaigns. The actor deploys CountLoader and SystemBC malware alongside Cobalt Strike payloads, leveraging consistent tooling and infrastructure across multiple ransomware operations over a three-year period.
Attackers Exploit Legitimate Tools to Deliver Malware and Evade Detection
Cofense analysis shows threat actors increasingly abuse legitimate software such as Microsoft Office, exploiting vulnerabilities including CVE-2017-11882 and CVE-2017-0199 to achieve remote code execution and deliver malicious payloads. Remote access tools including NetSupport Manager and ConnectWise accounted for roughly 75% of observed cases, enabling capabilities such as keystroke logging, file access, screen capture, and lateral movement. Data from 2021 to 2024 indicates attackers favour low-cost or trial-based legitimate tools like FleetDeck and Atera, using them to bypass endpoint detection and response systems and maintain persistent access.
Fraud Networks Industrialise Mule Accounts on European Fintech Platforms
Group-IB found nearly one in seven business account registrations on French fintech platforms are fraudulent, with verified mule accounts sold on dark web marketplaces for $300 to $700. Fraudsters harvest victim personal data via phishing, use SIM modem farms and anti-detect tools during sign-up, then socially engineer victims to complete KYC verification on legitimate devices. After verification, accounts are accessed using low-cost Android devices linked to the same network infrastructure, enabling rapid laundering of funds through SEPA transfers across multiple European countries.
DPRK Fake IT Worker Network Exposed Through VPN Infrastructure Analysis
Team Cymru traced infrastructure linked to DPRK fake IT worker operations to domain luckyguys[.]site resolving to 163.245.219[.]19, analysing 30 days of network activity and identifying a second IP at 216.158.225[.]144. Traffic analysis showed heavy reliance on Astrill and Mullvad VPNs alongside residential IPs connecting to services including Gmail, ChatGPT, and Workana, a freelance hiring platform. Activity dropped sharply after public attribution on 8 April, with patterns indicating distributed laptop farms and coordinated use of remote employment channels for sanctions evasion.
Anthropic Investigates Unauthorised Access to Mythos AI Model
Anthropic confirmed unauthorised access to its Mythos vulnerability-hunting model via a third-party vendor environment, where users reportedly guessed the model’s endpoint using information exposed in the Mercor data breach. The access did not involve Anthropic’s production systems, and activity appears limited to a small group interacting with the preview model through a private Discord channel. Early testing by partners including Mozilla found the model identified hundreds of vulnerabilities, such as 271 in Firefox, but required human guidance and did not exceed human researchers’ capabilities.
Daily Coverage