CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (5 June 2026)

Published: Loading…

At a Glance

  • A binding.gyp-based npm supply chain worm compromised dozens of packages, abusing node-gyp execution during install to steal credentials and propagate across ecosystems.
  • The U.S. Department of Justice coordinated a Disruption Week operation that dismantled Southeast Asia cryptocurrency fraud infrastructure and froze millions in illicit assets.
  • CISA added CVE-2026-45247 affecting Mirasvit Cache Warmer to its Known Exploited Vulnerabilities catalog after confirmed active exploitation in the wild.
  • A malicious executable bundled with Hola Browser was identified as a cryptominer installing services and modifying system settings in a supply chain compromise affecting users.
  • Five Eyes agencies warned that Chinese intelligence operatives are using LinkedIn and other job platforms to recruit insiders with access to sensitive information.
  • A VS Code webview flaw allowed GitHub token theft via github.dev links through synthetic keyboard event injection targeting OAuth credentials.

Summary

Supply chain attacks across the npm ecosystem escalated after a binding.gyp worm infected multiple packages by triggering code execution during installation. The malware leveraged node-gyp behaviour to bypass conventional package script restrictions and propagate across repositories. Attackers used the mechanism to exfiltrate credentials and expand compromise across development environments.

The U.S. Department of Justice coordinated a multi-agency Disruption Week operation targeting Southeast Asia cryptocurrency fraud networks. Authorities dismantled infrastructure supporting large-scale social engineering scams and froze millions in digital assets linked to laundering operations. The action included arrests and takedowns of accounts associated with transnational fraud syndicates operating regional scam compounds.

Multiple vulnerabilities and malware incidents were reported across enterprise and consumer systems, including a Mirasvit Cache Warmer flaw added to CISA’s Known Exploited Vulnerabilities catalog. The issue was confirmed as actively exploited in the wild through deserialisation of untrusted data. Separately, a VS Code webview flaw enabled GitHub token theft via github.dev links through injected keyboard event sequences.

Supply chain compromise activity also affected consumer software, including a Hola Browser incident involving an undeclared cryptomining executable. The binary modified system configurations and installed persistence mechanisms while operating as a background service. Investigators attributed the issue to a limited supply chain compromise affecting a subset of users.

State-linked and cybercrime activity included recruitment operations attributed to Chinese intelligence services using job platforms to target individuals with access to sensitive information. Parallel reporting highlighted ongoing phishing, credential theft, and ransomware-adjacent campaigns leveraging social engineering across professional networks. These operations focused on intelligence collection and long-term access development within government and defence-adjacent sectors.

Data breach activity included exposure of 2.6 million DentaQuest accounts following a ShinyHunters-linked intrusion and dataset leak. The compromised data included identity, contact, and insurance records, with partial overlap from previously exposed datasets. Additional reports confirmed continued exploitation of enterprise systems and customer-facing platforms across multiple sectors.

Highlights of the Day

Miasma Worm Compromises 57 npm Packages

Researchers identified a new Miasma supply-chain campaign that compromised 57 npm packages across more than 286 malicious versions, including @vapi-ai/server-sdk and ai-sdk-ollama, during a two-hour publishing spree on 3 June. The malware abuses a 157-byte binding.gyp file to trigger code execution through node-gyp during npm installation, bypassing checks focused on preinstall and postinstall scripts. Analysis showed the payload steals GitHub, cloud and CI/CD credentials, downloads the Bun runtime, uploads encrypted data to GitHub repositories controlled by the liuende501 account, and attempts automated propagation across npm, RubyGems and GitHub repositories.

Disruption Week Targets Scam Networks and Crypto Laundering

The U.S. Department of Justice, alongside law enforcement agencies and technology companies including Apple, Google, Meta, Microsoft and Coinbase, coordinated a four-day operation that disrupted more than 1.4 million social media and email accounts linked to cyber-enabled cryptocurrency investment fraud networks in Southeast Asia. Participants also voluntarily froze over $3.8 million in cryptocurrency connected to money laundering, decommissioned servers and hosting infrastructure used by scam operators, and supported investigations that led to seven arrests in Thailand. The operation focused on criminal syndicates running large-scale “pig butchering” fraud schemes from compounds in Cambodia, Laos and Burma, where trafficked workers are often forced to conduct scams targeting victims worldwide.

CISA Flags Actively Exploited Mirasvit Cache Vulnerability

CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation of a deserialisation of untrusted data flaw in the Mirasvit Full Page Cache Warmer product. The agency identified the vulnerability as a significant security risk and noted that deserialisation flaws remain a common attack vector used by malicious cyber actors. Under Binding Operational Directive 22-01, U.S. Federal Civilian Executive Branch agencies must remediate KEV-listed vulnerabilities by the specified deadline, while CISA urged all organisations to prioritise mitigation of actively exploited flaws.

Hola Browser Incident Exposes Hidden Crypto-Mining Binary

Sophos X-Ops identified an undeclared executable, me.exe, bundled with some installations of Hola Browser version 1.251.91.0, where the file appeared to function as a crypto-miner and was not listed among the product’s certified components. Analysis found the unsigned binary contained obfuscated code, added Windows Defender exclusions, included XMRig-related strings, and could install itself as the hola_monitor_svc service configured to run automatically when the system was idle. Hola said the file resulted from a supply-chain compromise affecting approximately 0.1% of users, and an investigation by Sygnia concluded that no user data was accessed, exfiltrated or compromised.

Source: Sophos

Five Eyes Warn of Chinese Recruitment Campaign

Five Eyes intelligence agencies warned that China’s military intelligence services are using LinkedIn, Indeed, Upwork and other online job platforms to recruit people with access to classified or privileged information through recruiters posing as consultants, think tanks and human resources firms. The joint bulletin said applicants are screened for access to sensitive government, military and economic information, then asked to produce reports before being directed to encrypted messaging platforms and offered payments ranging from hundreds to thousands of dollars. The agencies said targets include security clearance holders, military personnel, academics, journalists and think tank employees, with collected information used to build intelligence on government policy, military capabilities and strategic activities.

VS Code Webview Flaw Enables GitHub Token Theft via Link

A vulnerability in Microsoft Visual Studio Code webview handling enables synthetic keyboard event injection that can lead to GitHub token theft via github.dev links. Ammar Askar published a proof-of-concept exploit showing OAuth tokens granting repository access can be exfiltrated after user interaction with a maliciously crafted notebook. Microsoft applied fixes to VS Code after disclosure, restricting notebook webview keydown event propagation and adding confirmation steps for opening unsafe content in github.dev environments.

DentaQuest breach exposes data of 2.6 million accounts

A breach at DentaQuest exposed data from 2.6 million accounts after ShinyHunters claimed theft of 234 GB and later leaked the dataset. DentaQuest confirmed a cybersecurity incident on 2 June, reporting limited network access, containment actions, external investigators, and continued service operations. Have I Been Pwned identified leaked records affecting 2.6 million accounts, including emails, names, phone numbers, government IDs, insurance data, and 66% previously seen entries.

Daily Coverage

Developments
Npm Worm OutbreakDisruption Week OperationCisa Kev UpdateHola Cryptominer
Vulnerabilities
CVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2026-3300CVE-2026-20182Cisco Catalyst Sd-Wan Manager 20.1.12 (Critical)CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …CVE-2026-45247CVE-2026-48519CVE-2024-21182CVE-2026-28318CVE-2026-28299CVE-2026-7312Sitefinity 14.0.7700 (Critical)