FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

ChainDrop Worm: Sophisticated npm Supply Chain Attack Leveraging GitHub Actions and Trusted Publishing

The ChainDrop worm is a self-propagating supply-chain attack that has compromised 444 npm packages, affecting ecosystems with over 2 billion monthly downloads. By compromising high-reputation GitHub accounts, attackers inject malicious code into main branches to trigger automated releases via GitHub Actions. Critically, the use of OpenID Connect (OIDC) through "Trusted Publishing" allows the poisoned packages to arrive with valid provenance and digital signatures, neutralizing traditional integrity checks. The malware employs a multi-stage execution pattern, utilizing the Bun JavaScript runtime to deploy a 710KB obfuscated payload. It utilizes "EtherHiding"—a Command and Control (C2) mechanism leveraging the Ethereum blockchain—to evade network-based detection while targeting cloud credentials, AI-agent configurations, and cryptocurrency keystores.

AmnesiaStealer: macOS Malware Leveraging Fake GitHub Lures for Live Browser Hijacking

AmnesiaStealer is a sophisticated Rust-based infostealer targeting macOS users via "ClickFix" social engineering on counterfeit GitHub repositories. The malware utilizes a multi-stage execution flow to exfiltrate macOS Keychain data, saved passwords, and browser cookies from Safari and Chromium-based browsers. Critically, it leverages the Chrome DevTools Protocol (CDP) to grant remote operators live, real-time control over active browser sessions, allowing attackers to bypass multi-factor authentication (MFA) and facilitate immediate account takeover by manipulating the victim's authenticated browser instance.

Kimsuky Integration of Local LLMs Ollama, GPT4All, Msty and GitHub C2

Kimsuky, a North Korean-linked threat actor, is evolving its social engineering and command-and-control (C2) methodologies through the integration of local Large Language Models (LLMs) and developer-centric infrastructure. By utilizing local frameworks such as Ollama, GPT4All, and Msty, the group generates high-fidelity AI-driven decoy documents to enhance spear-phishing efficacy while maintaining operational security against cloud-based monitoring. Concurrently, Kimsuky is leveraging GitHub and Git for C2 communication and payload distribution, alongside "Living-off-the-Land" (LotL) techniques using PowerShell and LNK files. This shift from manual phishing to AI-augmented, infrastructure-obfuscated operations targets diplomatic, military, and cryptocurrency sectors, necessitating a transition from signature-based detection to advanced behavior-based EDR and SaaS usage monitoring.

GitHub Internal Repository Breach via Poisoned Nx VS Code Extension

A high-impact supply chain attack has compromised approximately 3,800 of GitHub's internal repositories. The breach originated from a poisoned version of the 'nrwl.angular-console' (Nx Console) Microsoft Visual Studio Code extension. By infiltrating a GitHub employee's development environment, the threat actor likely leveraged token-stealing mechanisms or a VS Code zero-day vulnerability to exfiltrate authentication tokens and access proprietary source code. The compromised data, including sensitive internal intellectual property, has reportedly been listed for sale on underground dark web forums. This incident highlights critical risks in developer tooling and the potential for secondary compromises through stolen credentials.

GitHub API Exploitation via Aged 'Ghost Accounts'

Threat actors are executing coordinated reconnaissance campaigns against corporate entities by leveraging "Ghost Accounts"—dormant GitHub profiles aged 2-5 years designed to bypass heuristic-based detection of new "burner" accounts. The attack utilizes a two-stage methodology: initial unauthenticated mapping of organizational social graphs via public GraphQL and REST API endpoints, followed by a high-velocity exfiltration phase. During this second phase, attackers utilize "Identity Dark Matter"—compromised OAuth tokens and Personal Access Tokens (PATs)—to pivot from public data to private repository cloning. This approach effectively evades traditional rate-limiting and anomaly detection by mimicking legitimate developer telemetry and leveraging high-abuse infrastructure like 3xK Tech.

Hades Malware Campaign: AI-Driven Evasion in PyPI, npm, and RubyGems

The Hades campaign is a cross-registry supply chain attack targeting PyPI, npm, and RubyGems via the leaked Miasma toolkit. Attackers deploy malicious wheel artifacts and setup.pth files to exfiltrate CI/CD credentials and environment variables. The campaign utilizes an "AI Safety-Evasion Paradox," injecting terminology related to biological and nuclear weaponry into the codebase. This triggers safety guardrails in AI-based security scanners, forcing the models to terminate analysis to avoid policy violations, thereby creating a blind spot that allows the malicious payload to bypass detection. Impact includes 19 poisoned PyPI packages and approximately 304 affected software components across 73 GitHub repositories.

Novo Nordisk Breach: GitHub Secrets Management Failure Exploited by FulcrumSec

The threat actor group FulcrumSec successfully compromised Novo Nordisk's internal IT infrastructure by exploiting mismanaged or exposed credentials within GitHub repositories. This failure in secrets management served as the initial entry vector, allowing the actor to exfiltrate approximately 1.3TB of highly sensitive data. The stolen dataset includes proprietary pharmaceutical research, internal IT system logs, and confidential patient information from clinical trials. Following Novo Nordisk's refusal to meet a $25 million ransom demand, FulcrumSec initiated a public data leak to maximize extortionary pressure, highlighting the critical risks of improper credential lifecycle management in DevOps workflows.


LINK COPIED TO CLIPBOARD