Triaging the Week 113

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Phishing Campaign Exploits GitHub Notifications to Spread Malware

Cybercriminals are now weaponizing GitHub’s own notification system to target developers with fake “Visual Studio Code” security alerts. By creating malicious issues and comments that impersonate official support, attackers trick users into executing PowerShell scripts that compromise their entire development environment.

Key takeaways:

🚨 Abusing Platform Trust: Attackers leverage GitHub notifications to send official-looking emails and alerts, claiming that a “security vulnerability” in Visual Studio Code requires an urgent manual fix.

🦠 The “ClickFix” Technique: Victims are directed to a fraudulent website that prompts them to copy and paste a command into their terminal, a tactic specifically designed to bypass browser security filters and antivirus detection.

🛡️ High-Stakes Data Theft: The primary goal is to deploy “stealer” malware that exfiltrates browser credentials, session cookies, and cryptocurrency wallet information, posing a massive risk to the supply chain.

🔒 Verify Before You Paste: Developers should never run scripts or commands provided by unverified GitHub issues. Always check the sender’s profile and stick to official documentation for security updates.

Socket

Infiniti Stealer Targets macOS via Sophisticated ClickFix Lures

Cybersecurity researchers have identified a new, high-severity threat dubbed Infiniti Stealer that specifically targets macOS users via a deceptive “ClickFix” social engineering tactic. By impersonating legitimate Cloudflare verification pages, attackers trick users into manually compromising their own systems, bypassing traditional browser security and Gatekeeper protections.

Key takeaways:

🚨 Social Engineering Trap: Instead of exploiting software bugs, this campaign uses fake CAPTCHA pages to trick users into copying and pasting a malicious command directly into their macOS Terminal.

🦠 Stealthy Python Payload: The malware is a Python-based infostealer compiled with Nuitka, which turns it into a native macOS binary that is significantly harder for antivirus software to detect and analyze.

🔑 Broad Data Theft: Infiniti Stealer is designed to exfiltrate a wide range of sensitive information, including browser credentials, macOS Keychain entries, cryptocurrency wallets, and secrets found in developer .env files.

🛡️ Defense-in-Depth: To stay safe, never run Terminal commands provided by a website to “fix” an error. Organizations should monitor for suspicious command patterns involving curl | bash or base64 decoding.

🎯 Threat Hunting Package

Malwarebytes

macOS Terminal Gets a New Shield Against “ClickFix” Social Engineering Attacks

Apple has introduced a proactive warning in the macOS Terminal to intercept “ClickFix” tactics, in which attackers trick users into executing malicious code under the guise of fixing browser errors. This update directly targets the human element of the attack chain by alerting users to suspicious clipboard activity before they can inadvertently compromise their own systems.

Key takeaways:

🛡️ Proactive Warning System: The macOS Terminal now detects and warns users when they attempt to paste commands commonly associated with ClickFix campaigns, such as those that clear clipboards or execute hidden scripts.

🕵️‍♂️ Combating “Fake Fix” Lures: This feature specifically targets social engineering campaigns where malicious websites display forged error messages to convince users to run Bash or PowerShell commands.

🚨 Interrupting Self-Infection: By adding this safety net, Apple is interrupting the “self-infection” process, providing a critical layer of defense for users who might otherwise follow convincing instructions from untrusted sources.

🔒 Essential Mitigation: While this is a significant win for macOS security, users must remain vigilant: never paste and execute commands from unverified sources, regardless of the “fix” promised.

BleepingComputer

Axios NPM Package Targeted in New Supply Chain Attack

A critical security alert has been issued for the popular Axios HTTP client after a compromise was detected in its latest releases. Multiple versions have been found to import a malicious dependency that executes remote code on Windows, Linux, and macOS systems. This incident highlights the ongoing fragility of the software supply chain and the risks of automated updates.

Key takeaways

🚨 Affected Versions: The compromise specifically impacts axios versions 0.30.4 and 1.14.1. If your project uses these versions, it is currently importing plain-crypto-js (v4.2.1), a malicious package.

🦠 Malicious Behavior: The injected dependency contains an obfuscated payload in setup.js that connects to a remote server (sfrclak[.]com) to download and execute OS-specific malware.

🛡️ Immediate Mitigation: Security teams must uninstall the affected versions immediately and roll back to a known safe release.

🔒 Credential Rotation: Because the malware can exfiltrate environment variables, you should rotate all API keys, secrets, and credentials stored on any machine or CI/CD environment where the poisoned versions were installed.

🎯 Threat Hunting Package

Socket

DeepLoad: The New Malware Loader Hiding Behind Your Browser Errors

DeepLoad is a sophisticated new malware loader that leverages “ClickFix” social engineering tactics to trick users into manually compromising their own systems. By abusing Windows Management Instrumentation (WMI), this threat evades traditional security perimeters, establishing a persistent foothold and delivering high-risk payloads.

Key takeaways:

💡 Advanced Social Engineering: DeepLoad uses “ClickFix” overlays (forged browser error messages) that convince users to copy and paste malicious scripts into their terminal under the guise of “fixing” a connection issue.

🛡️ Living off the Land: The malware utilizes Windows Management Instrumentation (WMI) for execution and persistence, allowing it to blend in with legitimate system processes and bypass many standard antivirus solutions.

🌐 A Gateway for Greater Threats: As a loader, DeepLoad’s primary objective is to pave the way for more destructive attacks, often serving as the initial entry point for info-stealers and ransomware.

🚨 The Human Element: Because this attack requires user interaction to succeed, technical controls must be paired with robust security awareness training to help employees spot these deceptive “browser fix” lures.

🎯 Threat Hunting Package

ReliaQuest

OpenAI Patches Critical ChatGPT “DNS Smuggling” Data Leak Flaw

OpenAI has successfully addressed a sophisticated vulnerability in ChatGPT that allowed attackers to covertly exfiltrate sensitive user data through a “DNS side channel.” This flaw, discovered by Check Point Research, enabled malicious actors to bypass standard network security controls and silently transmit conversation history and uploaded files to external servers using a single malicious prompt.

Key takeaways:

🛡️ Invisible Data Exfiltration: The vulnerability exploited a gap in outbound traffic monitoring, using DNS requests to smuggle data. Because this didn’t look like standard web traffic, it remained invisible to users and bypassed OpenAI’s existing security guardrails.

⚠️ One Prompt to Compromise: Attackers could initiate the leak via a single malicious prompt, often hidden in shared “productivity” templates or AI tips, turning an otherwise normal conversation into a persistent data-drainage channel.

📁 High-Value Data at Risk: The flaw exposed personal messages, medical assessments, and confidential uploaded documents, demonstrating that even “secure” code execution environments can have unintended communication paths.

✅ Remediation & Vigilance: While OpenAI has rolled out a full fix, this discovery reinforces a critical truth: security in the AI era cannot be assumed. Continuous monitoring of how AI agents interact with external protocols is essential.

Checkpoint

RoadK1ll: The New WebSocket “Access Amplifier” Stealthily Pivoting Through Networks

A new Node.js-based implant dubbed RoadK1ll is being used by threat actors to turn a single compromised host into a powerful relay point. By leveraging the WebSocket protocol for outbound communication, this lightweight tool bypasses traditional perimeter defenses, granting attackers deep access to internal services and segments otherwise unreachable from the outside.

Key takeaways:

🕵️‍♂️ Stealthy WebSocket Tunneling: RoadK1ll establishes an outbound WebSocket connection rather than waiting for inbound traffic. This allows it to blend into legitimate web traffic and evade detection by standard firewall rules.

⚡ Access Amplification: Its primary function is to act as a “pivoting” point. Once inside, an attacker can relay TCP traffic to internal management interfaces and adjacent hosts, effectively inheriting the network trust of the infected machine.

🛡️ Bypassing Perimeters: Because the connections originate from within the network, they often bypass external security controls, allowing attackers to communicate with multiple internal destinations simultaneously over a single tunnel.

🔒 Transient Presence: Interestingly, RoadK1ll often lacks traditional persistence mechanisms like registry keys. It operates as a live process, making real-time process monitoring and outbound connection analysis critical for detection.

🎯 Threat Hunting Package

Blackpoint

AI-Powered Bug Hunting: Claude Uncovers Zero-Day RCEs in Vim and Emacs

AI-driven security research has reached a significant milestone as the Calif team leveraged Anthropic’s Claude to discover zero-day Remote Code Execution (RCE) vulnerabilities in two of the world’s most trusted text editors: Vim and GNU Emacs. These critical flaws can be triggered automatically when a user simply opens a specially crafted file, marking a new era of risk for legacy open-source software.

Key takeaways

🤖 AI as the New Lead Researcher: Using natural language prompts, researchers successfully tasked Claude with identifying deep-seated vulnerabilities in highly audited codebases that have existed for decades.

📂 The “File Open” Attack Vector: The discovered RCEs are particularly dangerous because they require no complex user interaction; the mere act of viewing a malicious file is enough to compromise the system.

🏛️ Legacy Software, Modern Risks: This discovery underscores that even “stable” tools we’ve relied on for over 30 years are not immune to the analytical power of modern LLMs, which can find patterns human auditors may have missed.

🛠️ Hardening and Mitigation: Users are urged to update to the latest patched versions immediately and to consider disabling potentially risky features, such as modelines (Vim) or file-local variables (Emacs), when handling untrusted files.

Calif

The 60MB Mistake: How a Simple Map File Leaked Anthropic’s Claude Code Source

In a massive blow to proprietary AI security, Anthropic accidentally exposed over 512,000 lines of source code for its flagship CLI tool, “Claude Code,” due to a packaging blunder on NPM. While the company confirms no customer data or credentials were compromised, the leak has handed the global developer community a detailed blueprint of Anthropic’s internal architecture and unreleased roadmap.

Key takeaways

⚠️ The Source Map Trap: The exposure occurred because version 2.1.88 included a 60MB cli.js.map file, a debugging tool that allows anyone to reconstruct the original TypeScript source from compiled JavaScript.

🕵️‍♂️ Secret Features Revealed: Researchers dissecting the code have already uncovered unreleased experimental features, including “Proactive mode” and “Dream mode,” which suggest upcoming 24/7 autonomous coding capabilities.

🛡️ Pipeline Hygiene is Critical: This incident is a stark reminder that even elite AI firms are vulnerable to “human error” – a single missing .npmignore rule or misconfigured build script can instantly leak years of intellectual property.

📉 The Speed of the Internet: Within hours of the discovery, the source code was forked over 41,500 times on GitHub, leaving Anthropic in a permanent game of “whack-a-mole” with DMCA takedown notices.

BleepingComputer

Google Drive Activates AI Ransomware Detection by Default for Paying Users

Google has announced the general availability of its AI-powered ransomware detection for all paying Google Workspace and Google One subscribers, providing a critical layer of proactive defense for cloud-stored data. By immediately pausing file synchronization upon detecting a threat, the system prevents ransomware from spreading from compromised desktops to the cloud.

Key takeaways

🛑 Immediate Sync Suspension: When ransomware encryption is detected, Google Drive for Desktop automatically halts syncing to isolate the threat and minimize data loss.

🤖 14x Improved Detection: Powered by a refined AI model, the system now detects 14x more infection types than its beta version, offering faster, more comprehensive protection.

🛡️ Simplified Restoration: Users can utilize a built-in restoration tool to undo ransomware-induced changes, ensuring that cloud versions remain recoverable even if local files are encrypted.

📊 Enterprise Oversight: IT administrators receive real-time alerts through the Google Admin console, enabling rapid incident response and centralized security management.

Google Workspace

Microsoft Warns of Sophisticated WhatsApp-Delivered Malware Targeting Windows Users

Microsoft security researchers have uncovered a dangerous new campaign that exploits WhatsApp users’ trust to deliver malicious Visual Basic Script (VBS) files, initiating a multi-stage infection designed to seize full control of Windows systems. By leveraging “Living-off-the-Land” techniques and renaming legitimate system tools to evade detection, attackers establish persistent remote access that traditional antivirus software cannot detect.

Key takeaways

📩 Malicious Attachments: The attack begins with a deceptive WhatsApp message containing a VBS file; once executed, it triggers a chain that downloads secondary payloads from trusted cloud services like AWS and Backblaze.

🎭 Binary Masquerading: Threat actors are hiding in plain sight by renaming common Windows utilities (e.g., curl.exe renamed as netapi.dll) to blend into normal system processes and evade security monitoring.

🛡️ UAC Exploitation: The malware repeatedly triggers User Account Control (UAC) prompts, banking on “alert fatigue” to trick users into granting the elevated privileges required for a full system takeover.

🔒 Critical Mitigations: Organizations should immediately restrict script hosts like wscript.exe and cscript.exe in untrusted paths and transition EDR solutions to “Block Mode” to intercept unsigned MSI installers.

🎯 Threat Hunting Package

Microsoft Security

New “EvilTokens” Phishing-as-a-Service Targets Microsoft Accounts via Device Code Abuse

Cybersecurity researchers have identified a sophisticated new phishing kit dubbed “EvilTokens” that leverages the OAuth 2.0 device authorization flow to bypass traditional security measures. By tricking users into authorizing a malicious device code, attackers gain persistent access to Microsoft 365 environments, enabling full-scale data theft and automated Business Email Compromise (BEC) attacks.

Key takeaways

🔄 Abusing Legitimate Flows: EvilTokens exploits the “device code” login method, designed for smart TVs and IoT devices, to lure victims into entering a code on legitimate Microsoft portals, granting attackers full account tokens without ever seeing a fake login page.

📄 Multi-Format Lures: Attackers are distributing malicious QR codes and links embedded in diverse file types, including PDF, HTML, and SVG, often impersonating trusted services like DocuSign or Adobe Acrobat.

🔓 Full Ecosystem Access: Once a “token” is captured, threat actors gain immediate, persistent access to Outlook emails, OneDrive files, Teams conversations, and the ability to perform SSO impersonation across the organization.

🤖 BEC Automation: The service includes advanced features that automate the next steps of a Business Email Compromise attack, significantly lowering the barrier for entry for less-skilled cybercriminals.

🎯 Threat Hunting Package

Sekoia

ISO Lures Fueling Sophisticated RAT and Crypto-Mining Campaign

Cybersecurity researchers have uncovered an active operation in which attackers are using malicious ISO image files to distribute a potent combination of Remote Access Trojans (RATs) and cryptocurrency miners. This campaign highlights a growing trend of using disk image formats to bypass standard email security filters and gain unauthorized access to high-value systems.

Key takeaways:

🚨 High-Risk Lures: Attackers are shifting toward ISO files because they often evade traditional security scanners that focus on executable files, making them a highly effective delivery mechanism for initial infections.

🛡️ Dual-Threat Impact: The malicious payload provides threat actors with total remote control for data exfiltration while simultaneously hijacking hardware resources to mine cryptocurrency, leading to severe performance degradation and increased costs.

🔒 Evasion & Persistence: The campaign leverages “living-off-the-land” techniques, using legitimate system utilities to execute malicious code, helping the malware evade basic antivirus solutions.

💡 Actionable Defense: To mitigate this risk, IT administrators should consider disabling the auto-mount feature for ISO and VHD files and implement strict policies against mounting disk images from unverified or external sources.

🎯 Threat Hunting Package

Elastic Security Labs 

The Reputation Trap: Why Your IP Blocklists Are Failing

A groundbreaking report reveals that 78% of malicious residential proxy sessions successfully evade standard IP reputation checks. Threat actors are increasingly weaponizing compromised home internet connections to mask their tracks, rendering traditional “allow” and “deny” lists nearly obsolete amid rapid IP rotation.

Key takeaways:

🚨 The Vanishing Act: Residential proxies often rotate after just a single session, disappearing long before security systems can flag them as malicious or update reputation databases.

🛡️ Reconnaissance Engine: These proxies are primarily used for silent scanning and mapping; once the “terrain” is understood, attackers switch to high-powered data center infrastructure for the final exploitation.

🔒 Human-Centric Patterns: Unlike server-based attacks, this traffic mimics human behavior, peaking during the day and dropping off at night, making it harder for automated tools to distinguish between a customer and a bot.

💡 Behavioral Shift: Security teams must move beyond static IP reputation and prioritize behavioral analysis and “living-off-the-land” detection to catch threats that no longer have a persistent digital address.

GreyNoise

Anthropic’s Claude Code Leak: From Human Error to Infostealer Lure

Anthropic inadvertently exposed over 512,000 lines of its “Claude Code” source code through a misconfigured npm package, triggering a wave of malicious mirrors and supply-chain risks. While the company confirmed the exposure was due to a packaging error rather than a breach, threat actors are already weaponizing the incident to distribute malware.

Key takeaways:

🚨 Weaponized Lures: Cybercriminals are currently using “leaked Claude Code” repositories on GitHub as lures to distribute Vidar infostealers and GhostSocks proxies.

🛡️ Supply Chain Vulnerability: The leak occurred because a JavaScript source map was accidentally included in version 2.1.88, allowing anyone to reconstruct the original TypeScript codebase.

🔒 Malicious Typosquatting: Attackers have begun registering internal-looking npm package names to target developers experimenting with the leaked source code.

💡 Defense Priority: Organizations should immediately audit internal npm mirrors for *.map files and enforce strict policies against installing software from unverified “leak” sources.

🎯 Threat Hunting Package

Zscalar


Feature Video

Are you ready to level up your cyber security career? 

🚀 Becoming a CTI Analyst is more than just tech skills – it’s about strategic thinking, proactive defense, and continuous learning!

Here is how you can become one:

1️⃣ Learn what CTI analysts do, their roles and responsibilities, and what their day-to-day tasks look like.

2️⃣ Discover the skills required to fulfill this work.

3️⃣ Learn the skills and apply the skills to showcase your capabilities.

4️⃣ Land a CTI analyst position!

This video walks you through how to progress through each of these steps so you can begin leveling up your cyber security career today!

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defense strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training equips students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools