VMTech
Discuss a project →

ThreatsDay roundup highlights package compromises and Windows RAT

ThreatsDay roundup highlights package compromises and Windows RAT

The latest ThreatsDay roundup brings together a compromised npm package, malicious RubyGems, a self-propagating Linux worm, a WhatsApp-delivered Windows RAT and authentication weaknesses that can enable impersonation. Among the most concrete supply-chain findings, StepSecurity said @subql/common version 5.8.3 was altered to include a hidden payload that collects credentials and supports remote shell access.

The code runs during installation and when the package is imported, targeting developer workstations, CI environments, GitHub Actions runners and accessible cloud services. SafeDep separately identified 42 malicious gems published from the RubyGems account reqthrottle_3474, most aimed at cryptocurrency developers.

Developer tools become an intrusion path

SafeDep said the malicious gems avoid acting in CI and sandbox environments. On a developer machine, they wait 20 to 40 minutes before either opening a reverse shell or downloading an archive and executing its installation script. The activity illustrates how environment-aware behaviour can make malicious dependencies harder to spot during routine checks.

A separate cluster of nine npm packages, published by the account dirtyblanket within 33 minutes on September 29, 2026, embedded a Linux worm. The worm installs a fake systemd font service called systemd-fontd that is the open-source CHAOS remote access tool. It can provide a shell, file access and screenshots over Tor.

The worm uses SSH private keys available on a compromised machine to log in to hosts listed in known_hosts and run itself there. It also uses npm tokens found on the system to publish new versions of developers’ npm packages, creating a route for further propagation through trusted publishing credentials.

Phishing and endpoint chains remain active

Morphisec described a financial-document lure named Statement.exe, reportedly distributed through WhatsApp, that deploys VulcanRAT207. The multi-stage Windows chain screens the host, attempts privilege elevation and injects a downloader into the LocalSystem Task Scheduler process. It uses a signed GoFly driver to terminate selected Baidu security processes and creates a Vulkan DLL side-loading task before launching the WebSocket RAT.

VulcanRAT207 can collect system metadata, offer interactive shell access, inject processes, enumerate local accounts, replace clipboard content and terminate itself. Elsewhere, Huntress reported phishing emails that used legitimate Microsoft Power BI domains to lead recipients to fake reference documents and ultimately rogue ScreenConnect installers.

Design decisions can create direct access risks

Resecurity disclosed an authentication bypass in an unspecified yard management system caused by a hard-coded session-cookie signing secret and use of a public database identifier rather than an unpredictable session identifier. It said the combination could allow valid cookies to be generated for arbitrary users whose IDs are obtainable through the application API, including accounts with elevated privileges.

For businesses, the common thread is that trusted software, credentials and established services can become delivery mechanisms. Dependency controls, restricted and rotated CI or publishing tokens, monitoring for unexpected build-environment connections, phishing-resistant workflows and unpredictable server-side session identifiers should be treated as operational safeguards rather than optional hardening.

#cybersecurity#supplychain#npmsecurity#threatintel
Open analytics
On the site 1 views
min read 4 08.10.2026
Instagram

ThreatsDay roundup highlights package compromises and Windows RAT

Open the post on Instagram ↗