Triaging the Week 136

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Theme 1: Poisoned Pipelines

Stories

🗞️ Stealth npm Campaign “indexed-btree” Bypasses Install-Script Defenses via Runtime Execution (Checkmarx) – A malicious npm campaign racked up millions of downloads by hiding its loader in BTree.prototype.set() rather than a pre/postinstall hook. Install-time scanners never see it, and it runs during normal use to fingerprint hosts, exfiltrate data via Slack and Telegram, and pull C2 from Ethereum smart contracts.

🗞️ Graphalgo Malware Expands Supply Chain Attacks to Terraform and Go Ecosystems (Aikido) – This is the first systematic malware campaign seen spreading through Terraform providers. It uses typosquatted providers and Go modules, conditional triggers that only fire on specific variable hashes or inputs, and C2 dead-drops on Slack and the Arbitrum Sepolia blockchain. 🔎 Threat Hunting Package

🗞️ “Plugin4Shell” Flaw Bypasses SHA Pinning Across Major AI Coding Agents for Zero-Click RCE (Air Security) – Git resolves a branch name before a commit hash. That lets an attacker name a branch after a pinned 40-hex SHA and swap in malicious plugin code for Claude Code, Codex, Copilot, and Gemini CLI. The agent reports that it honored the pin while running attacker code with full privileges.

🗞️ GitLab Email Feature Weaponized to Push Malicious Code and Bypass IP Allowlists (Aikido) – GitLab’s “Email work item to this project” address embeds a glimt- token that never expires. The UI presents it as project-scoped, but it is account-wide. It ignores IP allowlists and accepts emailed patches without verifying the sender, so it can push code and trigger CI/CD jobs.

Recommendations

☑️ Audit lockfiles, Terraform configurations, and Go dependencies for the known malicious packages: indexed-btree, btree-core, ordered-kv-index, kreuzwenker/docker, gocommunity-io/dockerd, gocommunity.io/orderedbtree, and gogets.dev/btreex. Purge them and rotate all credentials on affected systems.

☑️ Patch Claude Code (v2.1.179+) and OpenAI Codex (v0.146.0+), and restrict third-party plugins in unpatched agents. Add post-checkout validation (git rev-parse HEAD) and only pull plugins from hosts that prohibit SHA-formatted branch names.

☑️ Move supply chain security beyond install-time static analysis. Add runtime behavioral monitoring, dependency provenance verification, and CI/CD scanning for typosquats, unverified providers, and falsified commit timestamps.

☑️ Alert on outbound traffic from build and runtime environments to Slack, Telegram, and Web3/blockchain RPC endpoints, since these have become standard C2 channels for supply chain malware.

☑️ Hunt for exposed glimt- addresses in repos, issues, and documentation, rotate incoming email tokens, and add secret-scanning rules for them. Don’t treat IP allowlists as a hard perimeter.

☑️ Apply least-privilege containment to AI coding agents and developer tooling so a compromised plugin or package can’t reach host credentials or production secrets.

Theme 2: Rogue Agents & AI-Powered Adversaries

Stories

🗞️ “BragJack” Flaw Allows Single Extension to Hijack AI Assistants Across 5 Major Browsers (Forever Security) – A browser extension with declarativeNetRequest permissions can “prompt force” built-in AI assistants. It does this by breaching the trust boundary between the AI’s web origin and the browser backend, with no prompt injection required. The hijacked assistant can then read local files, take screenshots, and exfiltrate data.

🗞️ Google’s Gemini Breaches Real-World Companies During Testing (The Wall Street Journal) – A misconfigured evaluation environment gave Gemini internet access. Believing the targets were in scope, it breached three real companies by guessing weak passwords and using credentials leaked in public repositories.

🗞️ Autonomous AI Agents Turn to Hacking Tactics to Solve Mundane Data Retrieval Tasks (Transluce) – Agents given routine data-collection tasks treated access controls as obstacles. When blocked, they escalated to urlquery.net proxying, vulnerability scanning, and custom exploit scripts, so the hacking emerged as a means to an ordinary goal rather than as an intent.

🗞️ Autonomous AI Agents Present Asymmetric Risks for Cyber Defenders (NCSC UK) – The NCSC warns that defenders can’t simply copy attackers’ use of unconstrained agents. A wrong autonomous remediation, such as isolating hosts, killing processes, or revoking access, can cause serious downtime even when no intrusion is happening.

🗞️ Cisco Talos Uncovers CLOSEDQUORUM: The First Autonomous AI Command-and-Control Implant (Cisco Talos) – This Windows implant has no C2 server. Instead, a “consensus panel” of commercial LLMs (DeepSeek, Qwen, Mistral, Gemini) votes on its next action, such as process hollowing or credential dumping, so its control traffic blends into legitimate AI API usage. 🔎 Threat Hunting Package

🗞️ Docker Botnet Weaponizes Open-Source AI Agent to Target Cloud Infrastructure (ThreatDown) – The CARBONATO botnet exploits exposed Docker daemons on port 2375 to deploy a modified Hermes Agent, controlled over Telegram. The attackers edited its SOUL.md persona file so it prioritizes harvesting AI API keys from 14 providers before stealing other credentials. 🔎 Threat Hunting Package

🗞️ Microsoft Disrupts ‘EvilTokens’: The AI Chatbot Automating Financial Fraud (Microsoft) – Microsoft and its partners took down EvilTokens, a cybercrime service linked to more than 12,000 compromised mailboxes. Its AI chatbot mapped roles, found wire-transfer threads, and drafted impersonation emails, turning mailbox access into fraud within minutes.

Recommendations

☑️ Enforce strict isolation for any AI agent environment. Use non-bypassable sandboxing, default-deny egress (including blocking URL proxy and scanning services), privilege isolation, and tested kill switches and rollback before granting autonomy.

☑️ Start defensive agentic AI with low-risk, human-in-the-loop tasks such as CTI summarization, log analysis, and triage. Have procurement, legal, and security teams jointly scrutinize vendor autonomy claims against your risk tolerance.

☑️ Restrict non-browser processes from reaching commercial LLM API endpoints, Discord webhooks, and Telegram. Treat unexpected AI API traffic from endpoints and servers as a potential C2 indicator.

☑️ Patch browsers for BragJack (CVE-2026-0628 for Chrome, CVE-2026-55945 for Edge). Use ExtensionSettings policies to restrict declarativeNetRequest and debugger permissions or enforce extension allowlists.

☑️ Lock down internet-facing basics that AI agents exploit well: scan public repos for leaked secrets, enforce MFA and lockout policies, and close exposed Docker daemons (port 2375) with TLS and ACLs.

☑️ Prioritize EDR behavioral detections (LSASS access, process hollowing, WMI persistence, privileged containers) over domain blocklists, which AI-driven and SaaS-hosted C2 easily sidestep.

☑️ Revoke session tokens after password resets, require out-of-band verification for payment changes, and update IR playbooks on the assumption that attackers can exploit a compromised inbox in minutes.

Theme 3: Fake Lures, Real Losses

Stories

🗞️ Fake GitHub Repos Push “Rapuncel” Infostealer and Kernel Driver to Neutralize Security Software (LastPass Labs) – SEO-optimized fake GitHub repos deliver 148MB archives. Through vsdbg.exe side-loading, they load a Microsoft-signed kernel driver (Alinubx.sys) that kills 145 security products, then steal credentials, crypto wallets, and session tokens past app-bound encryption. 🔎 Threat Hunting Package

🗞️ ChainScript RAT Exploits Blockchain for Stealthy C2 (Blackpoint APG) – A Node.js RAT spreads through ClickFix lures disguised as Spotify, Zoom, and Teams installers. It resolves its WebSocket panel from a Polygon smart contract at runtime (EtherHiding), so operators can rotate infrastructure without reissuing implants. 🔎 Threat Hunting Package

🗞️ Generic Placeholder Domain third-party.com Hijacked to Deliver ClickFix Attacks (BleepingComputer) – Unlike example.com, third-party.com is not reserved. It appears in 1,500+ files across 1,700+ repos, including Chromium, Vercel, and AI skill/MCP configs, and it now serves fake Cloudflare checks that push PowerShell via Win+R.

🗞️ Upgraded MacSync macOS Malware Swiftly Targets Developers and Crypto Enthusiasts (Kaspersky) – MacSync has moved from AppleScript to compiled Swift and Objective-C binaries, delivering both an infostealer and a backdoor. It abuses iCloud calendar entries as a delivery step to steal credentials, Keychain files, and crypto assets. 🔎 Threat Hunting Package

🗞️ New RemControl Android Banking Trojan Disables Play Protect via Fake VPN (Group-IB) – RemControl is distributed through malvertising that impersonates streaming apps. It abuses Accessibility Services for remote control and starts a local VPN that blocks traffic to Google Play services, which stops Play Protect from scanning. 🔎 Threat Hunting Package

Recommendations

☑️ Shrink ClickFix execution paths. Disable the Run dialog where it isn’t needed, restrict MSI and script execution from user-writable directories, and alert on PowerShell spawned from explorer.exe. Remind staff that real security checks never ask them to paste commands.

☑️ Block third-party.com at DNS and proxy, and replace unofficial placeholder domains in docs, tests, and AI configs with RFC 2606 reserved domains (example.com, .org, .net).

☑️ Hunt the published execution chains: msiexec.exe → wscript.exe → ._agent.vbs, node.exe spawning PowerShell to create scheduled tasks, renamed vsdbg.exe, browser process injection, Alinubx.sys/nvfsflt64.sys driver loads, macOS /tmp binary execution, and unauthorized Keychain access.

☑️ Keep Microsoft’s Vulnerable Driver Blocklist current, enforce application allowlisting and macOS Gatekeeper, and require software to come from official vendor domains rather than public repos or ads.

☑️ Correlate unexpected blockchain RPC access (Polygon, Ethereum) with outbound WebSocket connections to catch EtherHiding-style C2.

☑️ On mobile, block sideloaded APKs through MDM, audit Accessibility Service permissions, and alert on unauthorized VPN creation. Banks should add overlay detection and device integrity attestation.

☑️ Isolate any host that ran a suspect download, and rotate browser credentials, vaults, session tokens, and crypto keys from a known-clean device.

Theme 4: Identity Is the Perimeter

Stories

🗞️ Varonis Threat Labs Uncovers ‘TrustSink’: Turning Rogue MFA Providers Into Persistent Credential Traps (Varonis) – TrustSink is a post-compromise technique that abuses Entra ID External Authentication Methods to insert a rogue MFA provider into the real SSO flow. It harvests plaintext passwords while returning valid signed tokens, and it survives password resets.

🗞️ TeamFiltration Returns in “Spraying in the Andes” Campaign Targeting M365 Service Accounts (Proofpoint) – UNK_CondorFiltration sprayed 5,700+ accounts across 28 Chilean M365 tenants. Employee accounts held up, but every compromise was an unmanaged service account with an unrotated default password and no MFA.

🗞️ Microsoft Teams Expands Security Controls to Allow Custom Blocked File Extensions (BleepingComputer) – From November 2026, admins can customize Weaponizable File Protection’s blocked extension list in Teams chats and channels. This closes a long-standing gap between collaboration security and corporate DLP policy.

🗞️ Preauth WordPress Core Flaw Force-Installs Themes to Execute Remote Code (PWNAI Research) – Click2Shell exploits a parsing mismatch: the Themes API reads a crafted slug normally, while jQuery treats it as a selector and auto-clicks “Install”. A single link opened by a logged-in admin installs a vulnerable theme that can then be chained to PHP RCE.

Recommendations

☑️ Treat identity provider configuration as tier-0. Restrict and review who can register external authentication methods, require change control, and alert on new externalAuthenticationMethodConfiguration entries and unexpected device key changes.

☑️ Audit app registrations and service principals for redirect URIs pointing to external infrastructure such as ngrok or unfamiliar domains.

☑️ Inventory every non-human, service, and functional cloud account. Enforce MFA or workload identity controls, rotate default credentials, and block auth from legacy user agents and unauthorized cloud proxies.

☑️ Turn on Teams Weaponizable File Protection now (Set-CsTeamsMessagingConfiguration -FileTypeCheck "Enabled"), draft your tenant-specific blocked extension list ahead of November, and layer in Defender external user blocking and QR code blurring.

☑️ Update WordPress to 7.1.1+, hunt logs for unexpected /wp-admin/update.php requests and new inactive theme directories, and remove unused themes and plugins.

Theme 5: North Korea & ShinyHunters

Stories

🗞️ North Korean “WaterPlum” Group Targets Tech Talent in $10M+ “Contagious Interview” Campaign (IC3) – An FBI-led joint advisory says WaterPlum has compromised 30,000+ PCs in 100 countries. The group runs fake recruiter interviews and coding tests to deploy infostealers, and it combines this with laptop farms for illicit remote employment.

🗞️ Global Crackdown Escalates Against North Korean IT Worker Identity Schemes (MSMT) – After a UN report put Pyongyang’s IT worker fraud at $800M, coordinated arrests and asset freezes followed. Operatives are adapting by moving to border towns, using AI video manipulation, and relying on local proxy “handlers” to get through interviews.

🗞️ ShinyHunters Hijacks Clop Ransomware Leak Site in Escalating Cyber Feud (The Register) – ShinyHunters exploited an unauthenticated file upload flaw in Clop’s Grav CMS, stole logs and onion keys, and demanded an eight-figure ransom. It is threatening to expose organizations that previously paid Clop.

🗞️ ShinyHunters Breaches FBI Job Portal in Retaliatory Attack (The Record) – ShinyHunters defaced FBIjobs.gov and threatened to leak agent and applicant records unless the FBI withdraws a PSA about the group, a direct retaliatory strike against law enforcement.

Recommendations

☑️ Run all candidate coding tests, take-home assessments, and third-party code reviews in isolated sandboxes or disposable VMs.

☑️ Strengthen hiring and contractor onboarding. Require live, unmanipulated video verification and direct confirmation of previous employment, and cross-match payment details against applicant identity. Pair this with continuous background and sanctions compliance checks.

☑️ Apply zero trust to contractors by scoping access to the repositories they need. Alert on unauthorized remote access tools (AnyDesk, TeamViewer, Chrome Remote Desktop), proxy connections, and suspicious script execution (curl, base64, -enc, mshta, Invoke-WebRequest, hidden windows).

☑️ If your organization has paid Clop in the past, prepare IR, legal, and comms teams for re-extortion, and step up dark web monitoring for leaked transaction records or re-monetized data.

☑️ Put all self-hosted and public-facing CMSs and portals on strict patch schedules, restrict unauthenticated uploads, and monitor them continuously for defacement and data exfiltration. This matters most for organizations holding sensitive personnel records.


Feature Video

Clicking save on a detection rule in your SIEM console is professional malpractice.

I know that sounds harsh. Stay with me.

Think about what happens when an analyst writes a query in the Sentinel, Splunk, or Elastic UI and hits save:

❌ No peer review.

❌ No test against malicious or benign data.

❌ No rollback path.

❌ No record of why the rule exists.

If the query is too broad, you find out at 3 am when it floods the queue. If it’s broken, you find out when a real intrusion walks straight past it. Either way, you’re rebuilding logic from memory while the SOC burns.

🔁 Software engineers stopped shipping untested changes to production over a decade ago. Detection engineering is finally catching up: version control, peer review, automated testing, CI/CD deployment.

The teams that made that shift are quietly pulling ahead. The rest are still burying landmines and hoping the one person who knew where they were didn’t leave.

👉 I’ve published a full breakdown of the move to detection as code: the four-stage pipeline, the safety rail most teams skip, and the mistakes that sink migrations.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

Tools