Skip to main content

Four Malicious npm Packages Delivering Infostealers and Phantom Bot DDoS Malware

Scope: npm Ecosystem (chalk-tempalte, @deadcode09284814/axios-util, axois-utils, color-style-utils)

MiniPlasma – Windows Cloud Files Mini Filter Driver Zero-Day Bypasses 2020 Patch, Grants SYSTEM Access

Scope: Windows 11 and Windows Server 2022, 2025, 2026 (All Fully Patched Builds as of May 2026)

DirtyDecrypt (DirtyCBC) – Linux Kernel rxgk Missing COW Guard Grants Root Access (CVE-2026-31635)

Scope: Linux Kernel with CONFIG_RXGK Enabled (Fedora, Arch Linux, openSUSE Tumbleweed)

Exim "Dead.Letter" – Unauthenticated RCE via BDAT Use-After-Free in GnuTLS Builds (CVE-2026-45185)

Scope: Exim Versions 4.97 – 4.99.2 (GnuTLS Builds Only – Debian/Ubuntu Default)

Fragnesia – Linux Kernel Local Privilege Escalation via XFRM ESP-in-TCP (CVE-2026-46300)

Scope: Linux Kernel (All Distributions – Kernels Released Before May 13, 2026)

YellowKey – BitLocker Bypass via Windows Recovery Environment (WinRE) Zero-Day

Scope: Windows 11, Windows Server 2022 and 2025

Severity: Red

GreenPlasma – Windows CTFMON Arbitrary Section Creation Zero-Day LPE

Scope: Windows 11, Windows Server 2022, 2025, and 2026

Severity: High

"Mini Shai-Hulud" Supply Chain Worm Compromises TanStack, Mistral AI, and 170+ npm/PyPI Packages (CVE-2026-45321)

Scope: npm (@tanstack, @mistralai, @uipath, @squawk, and others) / PyPI (mistralai, guardrails-ai)

Checkmarx Jenkins AST Plugin Backdoored by TeamPCP in Third Supply Chain Attack

Scope: Checkmarx Jenkins AST Plugin (Version 2026.5.09)

Severity: Red

Subscribe to