SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, July 12, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Compromised Jscrambler NPM Package Drops Rust Infostealer | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 7 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by a severe supply chain compromise of the jscrambler npm package (v8.14.0) delivering a Rust-based infostealer, alongside a critical stored XSS vulnerability in Zimbra's Classic Web Client that allows arbitrary code execution. Additionally, threat actors are leveraging a novel "Ghostcommit" prompt injection technique hidden in PNG files to exploit AI code reviewers, while global campaigns target vulnerable CMS platforms and GitHub APIs for reconnaissance. |
|
■ CRITICAL STORIES Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install A compromised version of a popular npm package uses preinstall hooks to execute a native Rust infostealer, representing a severe supply chain risk for JavaScript developers. |
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions A stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client allows attackers to execute arbitrary code within user sessions via malicious emails. |
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets Researchers demonstrated a novel attack vector where prompt injections are hidden inside PNG images to bypass AI reviewers like CodeRabbit and Bugbot, potentially stealing repository secrets. |
Ghost Accounts Abuse GitHub API in Mass Recon Campaign Threat actors are utilizing ghost accounts on GitHub to systematically map organizations, repositories, and members, highlighting automated API abuse for reconnaissance. |
|
■ CVEs IDENTIFIED [CVE-TBD] jscrambler npm package (v8.14.0) — Malicious code execution via preinstall hook |
[CVE-TBD] Zimbra Classic Web Client — Stored Cross-Site Scripting (XSS) leading to Arbitrary Code Execution |
[CVE-TBD] Wireshark (pre-4.6.7) — Multiple vulnerabilities (12 bugs fixed) |
[CVE-TBD] Content Management Systems (CMS) & Plugins — Global exploitation of vulnerable CMS platforms |
|
■ THREAT ACTORS Suspected China-aligned actors | APT |
Targeting Pakistani law enforcement organizations and Balochistan Police Portal |
Suspected India-aligned actors | APT |
Targeting Pakistani law enforcement organizations and Balochistan Police Portal |
Unknown Actors (Ghost Accounts) | Cybercriminals |
Abusing GitHub API for mass reconnaissance and organization mapping |
|
|
|
■ ATT&CK TTPs | T1195.002 | | Supply Chain Compromise: Compromised Software Dependency | Compromised jscrambler npm package version 8.14.0 |
| T1059 | | Command and Scripting Interpreter | Preinstall hook executing native binary in compromised npm package |
| T1566.001 | | Phishing: Spearphishing Attachment | Malicious emails targeting Zimbra Classic Web Client |
| T1594 | | Search Victim-Owned Websites | Ghost accounts abusing GitHub API to map organizations and members |
| T1190 | | Exploit Public-Facing Application | Weaponization of Balochistan Police Portal and CMS vulnerabilities |
| T1204.002 | | User Execution: Malicious File | PNG files containing hidden prompt injections ('Ghostcommit') executed by AI agents |
|
■ PATCH PRIORITY jscrambler npm package (8.14.0) — Malicious preinstall hook drops Rust infostealer — [THN] |
Zimbra Classic Web Client — Stored XSS allows arbitrary code execution in user sessions — [THN] |
Wireshark — 12 vulnerabilities fixed in version 4.6.7 — [SANS] |
Content Management Systems (CMS) — Global exploitation campaign targeting vulnerable platforms and plugins — [BC] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately audit and remove jscrambler npm package version 8.14.0 from all environments and replace with a clean version to mitigate the [CVE-TBD] malicious preinstall hook. |
| 2 | [P1] Apply the latest Zimbra updates immediately to secure the Classic Web Client against the [CVE-TBD] stored XSS vulnerability. |
| 3 | [P2] Update Wireshark installations to version 4.6.7 to patch the 12 identified vulnerabilities [CVE-TBD]. |
| 4 | [P2] Implement strict validation and sanitization of image files (PNGs) reviewed by AI coding agents (like CodeRabbit and Bugbot) to prevent 'Ghostcommit' prompt injection exploits. |
| 5 | [P3] Audit GitHub API access logs for anomalous reconnaissance activity and restrict public visibility of sensitive organization repositories and member lists. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |