๐จ ACTIVE EXPLOITATION
-
Mini Shai-Hulud Worm Compromises Popular npm Codegen Package
Attackers compromised the npm package @7nohe/openapi-react-query-codegen with a Mini Shai-Hulud worm.- The affected package is @7nohe/openapi-react-query-codegen, a TanStack Query code-generation library with more than 150,000 weekly downloads.
- Malicious releases were 0.0.0-365d4eb738d3146583431948d3ba6e27a32556be, 0.0.0-ec7876d6c917dad516ba69bbfafc948b834bf0ab, 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, and 3.0.4.
- An attacker abused a GitHub Actions workflow that allowed pull-request comments to trigger npm publishing from forked code, producing valid npm provenance.
- Installation launched the obfuscated 3FWCvzduYZg.js loader through binding.gyp and, in later releases, a preinstall script.
- The payload targeted GitHub, npm, PyPI, RubyGems, cloud, Kubernetes, Vault, SSH, and CI/CD credentials, then supported propagation through writable packages; related SHA-256 IOCs include b49afb7dba04cd99b357ce7c652c823a3707f28e130bd5c6645851a7adc030d6 and 59370c67b54a0ccaedd265e2356f04540b2fba1e1845300ef6de4d5437d99380.
๐ Source: socket.dev ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Malicious Packagist Themes Target iPhones With Spyware and Wallet Theft
Attackers used 13 malicious Composer themes to target iPhones with spyware and crypto-wallet theft.- Vietnamese movie and comic streaming sites using OphimCMS or KKPhim were affected, exposing their visitors.
- Trojanized Packagist themes targeted iPhone XS through iPhone 16 devices running iOS 18.4โ18.6.x.
- The packages exploited WebKit CVE-2025-31277 and CVE-2025-43529 through a browser-to-kernel attack chain.
- Spyware stole keychain data, messages, photos, cookies, and wallet seeds from Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, and OKX.
- Identified namespaces included vsmov, vsphim, haiau009, chilltvcms, and ophimcms; delivery infrastructure included union[.]macoms[.]la.
๐ Source: socket.dev ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Five Venezuelan nationals plead guilty to attempted Kansas ATM jackpotting
Five Venezuelan nationals pleaded guilty to attempted ATM jackpotting in Kansas.- Banks and credit unions operating ATMs in Wamego and Manhattan, Kansas, were targeted.
- The suspects attempted to install malware that would force ATMs to dispense cash without authorized transactions.
- One conspirator was to physically install the malware before the group remotely activated it.
- The attempts failed, triggered alarms, and were captured on surveillance cameras.
๐ Source: justice.gov ยท ๐ Coverage: therecord.media ยท ๐ via BleepingComputer
๐ ADVISORIES
-
WatchGuard patches three critical Fireware OS VPN flaws
WatchGuard patched three critical Fireware OS vulnerabilities enabling unauthenticated remote code execution.- WatchGuard Firebox customers using Fireware OS are affected.
- The three flaws affect the Fireware iked process that handles IKE/IPsec VPN traffic.
- Remote unauthenticated attackers can send crafted VPN traffic to trigger heap overflow, stack overflow, or type-confusion memory corruption.
- Affected versions include Fireware 2025.0โ2026.2.1, 12.0โ12.12.1, and T15/T35 builds below 12.5.20; CVEs are CVE-2026-19313, CVE-2026-19315, and CVE-2026-19318.
๐ Source: watchguard.com ยท ๐ Coverage: blog.gridinsoft.com ยท ๐ via SecurityWeek
-
๐ Source for Attackers Exploit Critical Ruby on Rails KindaRails2Shell Flaw โ docs.vulncheck.com