CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (26 June 2026)

Published: Loading…

At a Glance

  • Miasma and Mini Shai-Hulud supply chain attacks compromised 20 LeoPlatform npm packages and GitHub Actions workflows to steal CI/CD secrets.
  • Turla's STOCKSTAY .NET backdoor has been deployed against Ukrainian government and military targets and entities with Italian foreign policy interests.
  • Mistic backdoor, active since April 2026 and linked to Woodgnat access broker, targets insurance, education, IT, and professional services organisations.
  • Fifteen malicious JetBrains Marketplace plugins stole AI API keys from approximately 70,000 developers over an eight-month supply chain campaign.
  • ASIO confirmed nation-state hackers compromised an Australian critical infrastructure provider, harvesting active user credentials to enable future sabotage.

Summary

A coordinated supply chain campaign deploying Miasma and Mini Shai-Hulud malware published malicious versions of 20 LeoPlatform npm packages within a three-second window on June 24. The payload steals GitHub Actions tokens, cloud credentials, and package registry secrets, exfiltrating data through the victim's own GitHub token. The same campaign also compromised GitHub Actions workflows and the Verana Blockchain Go module, with related activity extending to three additional npm packages published under a separate account.

Fifteen malicious plugins on the JetBrains Marketplace were identified as having stolen AI API keys from approximately 70,000 developers over an eight-month period. The JetBrains plugins exfiltrated OpenAI, DeepSeek, and SiliconFlow credentials to a server on Alibaba Cloud infrastructure in Beijing.

Russia-linked Turla has been deploying the STOCKSTAY .NET backdoor against Ukrainian government and military organisations and entities connected to Italian foreign policy. STOCKSTAY shares significant code overlaps with Turla's KAZUAR toolkit and has been in continuous development since at least December 2022. Separately, the Mistic backdoor, linked to Woodgnat initial access broker, has been active since April 2026 across insurance, education, IT, and professional services sectors, with connections to Qilin, Rhysida, and Black Basta ransomware operations.

ASIO confirmed that nation-state hackers compromised an Australian critical infrastructure provider, harvesting credentials from active users including IT administrators. The agency assessed the attackers were mapping the network to enable future sabotage operations. CL-STA-1062, a separate threat cluster linked to UAT-7237, targeted government entities and critical energy infrastructure across Southeast Asia using a previously undocumented .NET backdoor named TinyRCT.

Google Chrome released version 149 patching 18 vulnerabilities, including four rated Critical, with more than half classified as use-after-free defects. GitLab issued updates addressing 13 vulnerabilities including three high-severity code execution and information disclosure flaws. A 25-year-old vulnerability in the Curl data transfer tool was also patched in the latest release.

Highlights of the Day

Rust macOS Backdoor Hides Behind AI Prompt Injection

SentinelLABS analysed a Rust-based macOS implant named macOS.Gaslight that embeds a 3.5 KB prompt-injection payload containing 38 fabricated system messages designed to disrupt LLM-assisted malware triage, while Apple detects the sample as MACOS_BONZAI_COBUCH and the researchers attribute it with high confidence to a DPRK-aligned activity cluster. The malware communicates through a Telegram Bot API polling loop protected by AES-GCM encryption and certificate-pinned TLS, provides an interactive shell, persists using a LaunchAgent masquerading as com.apple.system.services.activity, and includes a configurable Python stealer that collects browser data, terminal histories, system information and login.keychain-db.

New Mistic Backdoor Linked to Ransomware Access Operations

Symantec reported a new backdoor named Backdoor.Mistic that has been used since April 2026 against organisations in the insurance, education, IT and professional services sectors, with one intrusion also deploying the ModeloRAT remote access trojan associated with the Woodgnat initial access broker. The malware is side-loaded through the legitimate MpExtMs.exe process using a malicious EndpointDlp.dll, executes payloads directly in memory, includes a self-deletion kill switch, and Symantec has separately observed ModeloRAT used in attacks that deployed Qilin ransomware.

Source: Symantec

Miasma Campaign Compromises Leo npm Packages and GitHub Workflows

Researchers identified a new Miasma and Mini Shai-Hulud supply chain campaign that published malicious versions of 20 LeoPlatform npm packages on 24 June 2026, using a binding.gyp install-time execution technique to launch obfuscated malware through the Bun runtime, while related compromises also affected GitHub Actions workflows and the Verana Blockchain Go project. The payload steals GitHub Actions, cloud and package registry credentials, exfiltrates encrypted data through the victim's own GitHub token, targets AI coding assistant and IDE configuration for persistence, and Socket linked the activity to the same malware family behind earlier Miasma and Hades campaigns.

Millenium RAT Evolves Into Native C++ Malware-as-a-Service

Group-IB reported that Millenium RAT version 4 has been rewritten from .NET to native C++, uses the Telegram Bot API for command and control, is sold as a Malware-as-a-Service offering, and its telemetry identified 62,289 compromised Windows devices across more than 160 countries, including 39,730 infections during the first quarter of 2026. The RAT stores an encrypted configuration in embedded resources, supports browser and system data theft, keylogging, screenshots, audio recording and arbitrary command execution, establishes persistence through the Windows Run registry key, and can remotely encrypt files, download payloads, terminate processes and disrupt systems by triggering shutdown, restart, hibernation, logoff or a Blue Screen of Death.

Source: Group-IB

Turla Expands STOCKSTAY Espionage Backdoor

Google Threat Intelligence Group analysed STOCKSTAY, a .NET backdoor continuously developed by the Russia-linked Turla group since at least December 2022, and reported it has been used against government and military organisations in Ukraine as well as entities with an interest in Italian foreign policy, sharing significant code and functional overlaps with Turla's KAZUAR malware. STOCKSTAY communicates through secure WebSocket connections via a separate tunnelling component, stores an encrypted configuration disguised as stock market application data, generates a unique 4096-bit RSA key pair for encrypted command-and-control traffic, and supports file transfer, registry manipulation, command execution, screen capture and system reconnaissance.

Java-Based QuimaRAT Spreads Across Windows, macOS and Linux

LevelBlue analysed QuimaRAT, a Java-based malware-as-a-service RAT sold on underground forums and targeting Windows, Linux and macOS via a Java SE 8 JAR containing embedded JNA native libraries for multiple architectures and a modular Maven-based structure. The malware loads an encrypted config.dat file from within the archive and decrypts it using a repeating-key XOR routine, implements single-instance execution via OS-level file locking, performs environment and virtualisation checks before execution, and supports encrypted command-and-control communications using handshake and heartbeat protocol messages.

Source: LevelBlue

Island researchers analysed a Chrome extension “Adblock for YouTube” with over 11 million installs and identified an architecture that fetches configuration data from a remote server, including scriptlet instructions that can trigger JavaScript injection into browser pages without requiring extension updates or store review. The extension requests host permissions while attempting to restrict execution to YouTube domains using a URL substring check, and it periodically retrieves server-controlled rules that can select scriptlets capable of executing in the page’s main JavaScript context. A proof-of-concept demonstrated that remotely supplied scriptlet rules could execute across authenticated web applications when URLs contain the matched string, enabling cross-site data access within active browser sessions.

Source: Island

Malicious JetBrains plugins steal AI API keys from developers

JetBrains Marketplace supply chain attack involved 15 third-party plugins published under seven vendor accounts, impersonating AI development tools and stealing API keys entered by users. Keys including OpenAI-style sk- tokens were exfiltrated over unencrypted HTTP to 39[.]107[.]60[.]51 hosted on Alibaba Cloud in Beijing, affecting about 70,000 developers. JetBrains removed all plugins, banned seven publisher accounts and triggered a remote kill-switch, while the command-and-control server remained operational after takedown.

Unit 42 reports TinyRCT backdoor targeting Southeast Asian infrastructure

Unit 42 reported CL-STA-1062 activity targeting government entities and critical energy infrastructure across Southeast Asia, operating since at least 2022 and linked to UAT-7237. The group deployed a previously undocumented .NET backdoor named TinyRCT with capabilities including command execution, file exfiltration, screen capture and self-destruct functionality. Attackers used ASPX web shells for initial access and lateral movement, deploying SoftEther VPN, VNT and other open-source tools for tunnelling and exfiltration. Infection leveraged a .NET AppDomainManager injection chain using chrome_setup.zip, dropping PerfWatson2.exe and establishing C2 communication at 45[.]32[.]113[.]172 with AES-128 CBC encrypted beaconing.

Daily Coverage

Developments
Miasma Npm CampaignTurla Stockstay BackdoorMistic/Woodgnat RatJetbrains Plugin Theft
Vulnerabilities
CVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2025-67038N/A N/A (Critical)
Threat Groups
Turla[Also known as: Snake, Venomous Bear, Secret Blizzard] Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging inhouse tools and malware, such as Uroburos.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.SilenceSilence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.