CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (20 May 2026)

Published: Loading…

At a Glance

  • Compromised npm maintainer atool pushed malicious @antv and echarts-for-react releases stealing GitHub Actions secrets and CI/CD credentials.
  • Trojanised Microsoft durabletask PyPI releases delivered infostealer worm targeting AWS, Azure, GCP, and Kubernetes credentials through import-time execution, propagating across cloud environments via EC2 SSM and kubectl exec mechanisms.
  • ChromaDB FastAPI CVE-2026-45829 enables pre-auth remote code execution via embedding model loading before authentication checks during collection creation in API endpoints.
  • Microsoft disrupted Fox Tempest malware-signing service abusing Artifact Signing and Azure tenants to issue fraudulent certificates used in ransomware distribution campaigns.
  • Universal Robots PolyScope CVE-2026-8153 command injection allows unauthenticated network access to execute system commands on industrial robot controllers via Dashboard Server.

Summary

Compromised npm maintainer injected malicious packages across AntV ecosystem and echarts-for-react, harvesting GitHub Actions secrets and CI/CD credentials via exfiltration channels. Trojanised Microsoft durabletask PyPI releases delivered infostealer worm targeting AWS, Azure, GCP, and Kubernetes credentials through import-time execution, propagating across cloud environments via EC2 SSM and kubectl exec mechanisms.

ChromaDB FastAPI CVE-2026-45829 enables pre-auth remote code execution via embedding model loading before authentication checks during collection creation in API endpoints. Universal Robots PolyScope CVE-2026-8153 command injection allows unauthenticated network access to execute commands on industrial robot controllers via Dashboard Server interface. Drupal core vulnerability scheduled for urgent patch enables rapid exploitation risk across supported branches requiring immediate core update deployment with exploit development expected within hours or days window.

Microsoft disrupted Fox Tempest malware-signing-as-a-service operation abusing Artifact Signing and Azure tenants to issue fraudulent certificates supporting ransomware distribution campaigns. Public GitHub repository linked to CISA exposure contained AWS keys, Azure tokens, Kubernetes manifests, and CI/CD credentials across infrastructure tooling and backups. Microsoft revoked over one thousand certificates and disrupted code-signing abuse infrastructure linked to malware distribution across Azure-based services and fraudulent account creation.

Banana RAT banking trojan campaign targeted Brazilian financial institutions using WhatsApp phishing chains and PowerShell loaders delivering remote access, keylogging, and PIX fraud capabilities. Android ad fraud operation Trapdoor used 455 malicious applications and 183 C2 domains to generate 659 million daily bid requests across infrastructure. Public Instagram posts enabled AI-generated phishing campaigns producing personalised emails without requiring stolen databases or prior credential compromise across targeted users.

Highlights of the Day

Microsoft disrupts Fox Tempest malware-signing service operation

Microsoft Threat Intelligence tracked Fox Tempest operating a malware-signing-as-a-service operation abusing Microsoft Artifact Signing to issue short-lived fraudulent code-signing certificates via Azure tenants and signspace[.]cloud. Microsoft revoked over one thousand certificates linked to operation, and its Digital Crimes Unit disrupted infrastructure including shift to pre-configured virtual machines on Cloudzy infrastructure. Microsoft linked the service to ransomware activity including Vanilla Tempest deployments of Oyster backdoor and Rhysida ransomware, with infections spanning multiple sectors and regions globally.

Microsoft DurableTask PyPI Packages Deliver Infostealer Worm

Three malicious PyPI releases of durabletask versions 1.4.1 to 1.4.3 contained a Python dropper executing on import and retrieving rope.pyz from check.git-service.com C2 infrastructure. The payload operates as an infostealer worm targeting AWS, Azure, GCP and Kubernetes environments, harvesting credentials and propagating across EC2 via SSM and kubectl exec. Exfiltration uses GitHub FIRESCALE dead-drop and fallback domain t.m-kosche.com, with packages quarantined after analysis of credential theft and supply chain compromise.

Mass npm Supply Chain Attack Hits AntV Ecosystem

A compromised npm account 'atool' pushed malicious versions across Alibaba AntV ecosystem packages including timeago.js, echarts-for-react, and multiple @antv modules. The payload reads GitHub Actions runner memory to extract CI/CD secrets, harvests credentials, and exfiltrates data via GitHub API and t.m-kosche.com C2 channel endpoint. Over 2,500 public repositories were created using stolen tokens, while persistence mechanisms targeted VS Code and Claude configurations, expanding CI/CD compromise scope significantly further.

Command Injection Hits Universal Robots PolyScope Dashboard Server

Universal Robots PolyScope 5 OS command injection CVE-2026-8153 affects Dashboard Server interface, enabling unauthenticated network-access RCE on robot controllers running versions prior to 5.25.1. Carries CVSS 9.8 score and was disclosed through CISA and CERT/CC coordination, requiring Dashboard Server activation and reachable port exposure for exploitation. Universal Robots released PolyScope 5.25.1 to remediate the issue affecting industrial cobots, where input handling flaws allow command execution impacting confidentiality, integrity, and availability.

Banana RAT Targets Brazilian Banks via PowerShell Trojan

Trend Micro identified Banana RAT banking trojan linked to SHADOW-WATER-063 targeting Brazilian financial institutions through WhatsApp and phishing delivery chains. Initial access uses Consultar_NF-e.bat dropping obfuscated PowerShell that loads msedge.txt in memory with AES-wrapped payloads and establishes encrypted command and control communication. Post-execution capabilities include screen streaming, keylogging, remote input control, PIX QR interception, and banking overlay fraud via 24.199.90.58 infrastructure and windowsk-cdn.com C2 domains.

ChromaDB Pre-Auth Flaw Enables Remote Code Execution via Model Loading

HiddenLayer reported CVE-2026-45829 in ChromaDB FastAPI server where collection creation loads embedding configuration before authentication, enabling pre-auth remote code execution via model loading. Unauthenticated API requests can specify HuggingFace model references with trust_remote_code enabled, causing server to download and execute attacker-controlled code prior to access checks. Vulnerability affects ChromaDB versions 1.0.0 through 1.5.8 and stems from unsafe ordering where model instantiation occurs before authentication in V1 and V2 endpoints.

Daily Coverage

Developments
Antv Supply ChainPypi WormChromadb RceFox Tempest Disrupted
Vulnerabilities
CVE-2026-45585Windows 11 Version 24H2 - (Medium)CVE-2026-3102Exiftool 13.0 (Medium)CVE-2021-22204CVE-2026-46333Linux Bfedb589252C01Fa505Ac9F6F2A3D5D68D707Ef4 (High)CVE-2026-8153CVE-2026-45829CVE-2026-29205
Threat Groups
ReaperAPT37 is a North Korean statesponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 20162018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.