Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (24 April 2026)
Published: Loading…
At a Glance
- Bitwarden CLI npm package version 2026.4.0 was compromised by the Shai-Hulud worm, stealing SSH keys, cloud credentials, and GitHub tokens from developer environments.
- A US federal agency was breached via Cisco Firepower vulnerabilities CVE-2025-30333 and CVE-2025-20362, with FIRESTARTER malware enabling persistent re-entry.
- Apple patched CVE-2026-28950, a logging flaw in iOS Notification Services that retained deleted messages, used by FBI to recover Signal content.
- China-aligned APT GopherWhisper targeted Mongolian government entities using Go-based backdoors and abused Slack, Discord, and Outlook for command-and-control.
- Supply chain attacks hit npm, PyPI, and Docker Hub within 48 hours, targeting CI/CD credentials, API keys, and cloud tokens across developer pipelines.
- CISA ordered federal agencies to patch the BlueHammer Microsoft Defender flaw following confirmed zero-day exploitation in the wild.
Summary
A coordinated wave of supply chain attacks struck npm, PyPI, and Docker Hub between April 21 and 23, targeting developer credentials and CI/CD pipeline secrets. The Bitwarden CLI package version 2026.4.0 was compromised by the Shai-Hulud self-propagating worm, harvesting SSH keys, cloud credentials, and GitHub tokens before encrypting and exfiltrating data to attacker-created public repositories. The Checkmarx KICS Docker images and VS Code extensions were separately compromised, with an obfuscated payload collecting AWS, Azure, and Google Cloud tokens alongside npm configuration files.
CISA confirmed that a US federal agency was breached through Cisco Firepower vulnerabilities CVE-2025-30333 and CVE-2025-20362, with the FIRESTARTER backdoor providing persistent access without re-exploitation of the original flaws. The intrusion is linked to UAT-4356, previously attributed to the ArcaneDoor espionage campaign targeting network perimeter devices. CISA and the UK NCSC issued updated advisories requiring agencies to inventory Cisco devices and verify potential compromise.
A newly identified China-aligned APT, GopherWhisper, targeted Mongolian government entities using Go-based backdoors including LaxGopher, RatGopher, and BoxOfFriends. The group abused Slack, Discord, Microsoft Outlook, and file.io for command-and-control communications, with infrastructure activity aligning to UTC+8 working hours. A separate joint advisory from ten countries warned that China-nexus actors are broadly leveraging compromised routers and IoT devices as proxy networks for further intrusions.
CISA added the BlueHammer Microsoft Defender privilege escalation flaw to its Known Exploited Vulnerabilities catalogue, ordering federal remediation following confirmed zero-day exploitation. Apple separately released iOS and iPadOS updates patching CVE-2026-28950, a Notification Services logging flaw that retained deleted messages, including Signal content retrieved by the FBI using forensic tools. The UK NCSC officially endorsed passkeys as the default authentication standard, formally advising consumers to move away from passwords.
Trigona ransomware affiliates deployed a custom command-line exfiltration tool supporting five parallel connections per file and targeting high-value documents ahead of encryption. UNC6692 conducted a Microsoft Teams-based social engineering campaign, impersonating IT helpdesk staff to deploy the SNOWBELT loader and a custom malware suite including Python-based port scanning and LSASS credential extraction. Separately, UNC6692 used an initial email flooding operation to create urgency before redirecting victims to attacker-controlled AWS S3-hosted payloads.
Ransomware severity reached an average of $508,000 per claim in 2025, a 16% year-over-year increase, with remote access services serving as the entry point in 87% of cases. Crypto drainer infrastructure is increasingly converging with traditional cybercrime tooling, with StepDrainer targeting over 20 blockchain networks and EtherRAT deploying trojanised Node.js implants. Fake CAPTCHA pages are being used in international revenue share fraud campaigns, coercing users into sending premium SMS messages to 17 countries through chained redirect infrastructure.
Highlights of the Day
Shai-Hulud worm compromises Bitwarden CLI via npm supply chain
The @bitwarden/cli npm package version 2026.4.0 was compromised in a supply chain attack involving a Shai-Hulud self-propagating worm delivered through CI/CD or preinstall execution paths. The malware uses a bw_setup.js bootstrapper to execute a heavily obfuscated payload (bw1.js) that harvests SSH keys, cloud credentials, npm tokens, and GitHub runner data from infected systems. Exfiltrated data is encrypted using AES-256-GCM and stored in attacker-created public GitHub repositories with Shai-Hulud themed naming conventions, while propagation occurs through npm and GitHub Actions workflows. Some reports indicate use of a telemetry endpoint (audit.checkmarx.cx) and CI/CD pipeline compromise via GitHub Actions or publish workflow manipulation.
Cisco firewall breach exposes US agency via FIRESTARTER backdoor
A US federal agency was breached through Cisco ASA vulnerabilities CVE-2025-30333 and CVE-2025-20362, with FIRESTARTER malware installed on Firepower devices enabling persistent access. Line Viper malware created unauthorised VPN sessions bypassing authentication policies, while FIRESTARTER maintained access and allowed re-entry without re-exploiting vulnerabilities in March 2026. CISA and the UK NCSC issued updated advisories linking the activity to ArcaneDoor actors, requiring agencies to inventory Cisco devices and verify possible compromise.
GopherWhisper APT Targets Mongolian Government Using Go Backdoors
ESET Research discovered GopherWhisper China-aligned APT targeting a Mongolian governmental entity using Go-based malware including LaxGopher, RatGopher and BoxOfFriends, alongside injectors JabGopher and loader FriendDelivery. The group abuses Discord, Slack, Microsoft 365 Outlook and file.io for C2 and exfiltration, extracting messages through stolen API tokens to issue commands and return outputs. Analysis of Slack and Discord traffic revealed operational activity including file enumeration commands and internal testing, with infrastructure use aligning to UTC+8 working hours.
Trigona Ransomware Deploys Custom Data Exfiltration Tool
In March 2026, Trigona ransomware affiliates deployed uploader_client.exe, a custom command-line exfiltration tool communicating with a hardcoded attacker-controlled server for data theft. Tool capabilities include five parallel connections per file, TCP rotation after 2,048 MB, and exclusion filtering to prioritise high-value documents such as invoices and PDFs. Prior to exfiltration, attackers deployed kernel-level security-disabling tools including HRSword, Mimikatz, AnyDesk, and vulnerable driver abuse to bypass endpoint protections and harvest credentials.
Fake CAPTCHA Pages Drive Global SMS Revenue Fraud Campaign
Infoblox Threat Intelligence identified fake CAPTCHA pages used in international revenue share fraud campaigns that coerce users into sending premium SMS messages across multiple countries. Traffic distribution systems redirect victims through chained domains to CAPTCHA interfaces that trigger SMS messages to 17 countries including Azerbaijan, Myanmar, Egypt generating revenue shares. Operators employ back button hijacking and multi-stage verification flows with preconfigured phone lists and affiliate tracking parameters to maximise message volume and delay detection.
UNC6692 Uses Social Engineering to Deploy Custom Malware Suite
UNC6692 conducted a December 2025 intrusion campaign using IT helpdesk impersonation over Microsoft Teams and an initial email flooding operation targeting victims. Victims were directed to download a renamed AutoHotKey binary from an AWS S3 bucket, triggering SNOWBELT installation and headless Microsoft Edge execution. Post-compromise activity included scheduled tasks for SNOWBELT persistence, Python-based port scanning, PsExec use, RDP access, and LSASS credential extraction exfiltrated via LimeWire.
Crypto Drainers and Hybrid Malware Converge Across Web3 Ecosystems
Threat intelligence reports increasing convergence between traditional cybercrime tooling and cryptocurrency theft, with malware infrastructure repurposed for wallet phishing and drainer operations. StepDrainer targets over 20 blockchain networks using multichain drainer techniques, while EtherRAT delivers a Windows TFTP trojanised Node.js implant with blockchain RPC integration. Campaigns leverage Web3Modal wallet interfaces, Seaport and Permit2 approvals, and on-chain configuration stores to automate credential theft and cross-chain asset exfiltration across hybrid ecosystems.
Daily Coverage