Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (13 July 2026)
Published: Loading…
At a Glance
- Compromised jscrambler npm releases from version 8.14.0 dropped Rust-built infostealers targeting browser credentials, cryptocurrency wallets, and cloud secrets.
- GhostCommit prompt injection hides malicious instructions inside PNG images to bypass AI code reviewers CodeRabbit and Bugbot.
- Updated RedHook Android malware abuses Wireless ADB and Shizuku to gain shell-level privileges without rooting devices.
- Zimbra urged customers to patch a critical stored XSS flaw in the Classic Web Client enabling malicious email code execution.
- Metasploit released an exploit for CVE-2026-41264, an unauthenticated remote code execution flaw in FlowiseAI's CSV Agent tool.
- Australia's ACSC warned of a global campaign exploiting vulnerabilities in content management systems and plugins.
Summary
Multiple jscrambler npm releases beginning with version 8.14.0 were trojanized through compromised publishing credentials. The packages executed hidden Rust-built native binaries on Linux, Windows, and macOS during installation. The malware stole browser credentials, cryptocurrency wallet data, and cloud secrets before Jscrambler revoked the credentials and published a clean release.
Researchers demonstrated GhostCommit, a prompt injection technique that conceals instructions inside PNG images referenced by repository configuration files. The technique caused multimodal coding agents to read a repository's .env file and embed its secrets into generated code. CodeRabbit and Bugbot failed to detect the attack because both tools exclude image files from review by default.
Updated RedHook Android malware variants abuse Wireless ADB and the Shizuku framework to obtain shell-level privileges without rooting devices. The malware is distributed through fake government and financial websites hosting malicious APKs and has expanded from Vietnam into Indonesia.
Zimbra disclosed a critical stored cross-site scripting flaw in its Classic Web Client that allows crafted emails to execute malicious scripts in user sessions. Separately, Metasploit added an exploit for CVE-2026-41264, an unauthenticated remote code execution vulnerability in FlowiseAI's CSV Agent component.
Australia's ACSC issued an alert on a global campaign targeting vulnerable content management systems and plugins. Ghost accounts were observed abusing the GitHub API to map organizations, repositories, and members in a mass reconnaissance campaign. Separately, China- and India-aligned threat actors conducted sustained espionage against Pakistani law enforcement systems, including the Balochistan Police portal.
Highlights of the Day
Malicious jscrambler npm Releases Drop Cross-Platform Credential-Stealing Binaries
Several jscrambler npm releases, including 8.14.0, 8.16.0, 8.17.0, 8.18.0 and 8.20.0, were compromised to execute hidden Rust-built native binaries that target Linux, Windows and macOS, initially through a preinstall hook and later by injecting the same loader into the package's main modules. Analysis found the malware steals browser credentials, cryptocurrency wallet data, cloud secrets and AI development tool configurations, while Jscrambler confirmed the attacker used compromised npm publishing credentials, revoked them, deprecated the affected releases and published a clean version, 8.22.0.
Image-Based Prompt Injection Bypasses AI Code Reviewers
ASSET Research Group demonstrated GhostCommit, a prompt injection technique that hides instructions inside a PNG image referenced by an AGENTS.md file, causing multimodal coding agents to read a repository's .env file and embed its contents as integer arrays in generated source code. Testing showed Cursor, Antigravity and Codex CLI configurations leaked seeded secrets, while Claude Code consistently refused the attack, and the researchers found CodeRabbit excludes PNG files from review by default, allowing the malicious pull request to pass without findings.
RedHook Android Trojan Gains Shell-Level Access Through Wireless ADB
Group-IB found updated RedHook Android RAT variants abuse Wireless ADB and the Shizuku framework to obtain shell-level privileges (uid 2000), allowing them to execute protected system APIs, grant permissions, modify secure settings and capture low-level touch events without rooting the device. The malware is distributed through fake government and financial websites hosting malicious APKs on GitHub and Amazon S3, has expanded from Vietnam into Indonesia, supports 53 command-and-control instructions and uses multiple persistence techniques including cross-process resurrection, silent audio playback, WakeLocks and automatic privilege restoration after reboot.
Daily Coverage