Summary & highlights
Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243). DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and Credential Theft. DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT.
Highlights
- TL-2026-0557 — Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)
- TL-2026-0558 — DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and Credential Theft
- TL-2026-0559 — DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT
- TL-2026-0560 — Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)
- TL-2026-0561 — ROADtools Misuse in Cloud Intrusions — Nation-State Abuse of the Open-Source Entra ID Offensive Toolkit (Unit 42)
Theme of the day
DPRK and nation-state activity dominated, with Contagious Interview npm keyloggers, Famous Chollima's InvisibleFerret, UNC1549 espionage, and Ghostwriter targeting Ukraine. Infostealers, Composer/npm supply-chain backdoors, and M365 device-code phishing rounded out a credential-theft-heavy day.
- active-exploitation
- windows
- lateral-movement
- infostealer
- linux
Threats published
14 threat lines in the 2026-05-22 debrief, most severe first. Each links to its full profile.
- Ubiquiti UniFi OS — Three Max-Severity Pre-Auth Vulnerabilities (CVE-2026-34908 / 34909 / 34910) in Security Advisory Bulletin 064CRITICAL
- UNC2891 Bank Heist — CAKETAP Solaris Rootkit and 4G Raspberry Pi Physical Implant Targeting ATM Switching NetworkCRITICAL
- LiteSpeed User-End cPanel Plugin 0-Day CVE-2026-48172 — lsws.redisAble Local Privilege Escalation Exploited in the WildCRITICAL
- art-template npm Supply Chain Backdoor — Coruna Respawned iOS Safari Watering-Hole Exploit Kit (v4.13.3/4.13.5/4.13.6, CVE-2024-23222)CRITICAL
- Laravel Lang Supply Chain Compromise — 700+ Backdoored Composer Versions Across 4 Packages Deliver RCE Backdoor and Cloud Credential Theft via flipboxstudio[.]info C2CRITICAL
- Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)HIGH
- DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and Credential TheftHIGH
- DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RATHIGH
- Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)HIGH
- ROADtools Misuse in Cloud Intrusions — Nation-State Abuse of the Open-Source Entra ID Offensive Toolkit (Unit 42)HIGH
- Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via AppDomainManager HijackingHIGH
- Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing Chain Drops OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK → Cobalt Strike Against Ukrainian GovernmentHIGH
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview)HIGH
- 2026 FIFA World Cup Phishing Campaign — 222 Typosquatting Domains, 203 IPs, 4 Operator Clusters (Flare)HIGH
Techniques observed
171 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.008
- T1005
- T1014
- T1021.004
- T1027
- T1027.001
- T1027.002
- T1033
- T1036
- T1036.005
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.004
- T1068
- T1069
- T1069.003
- T1070
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1078
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.003
- T1087.004
- T1090
- T1090.001
- T1090.004
- T1091
- T1095
- T1098
- T1098.002
- T1098.003
- T1098.004
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1112
- T1113
- T1114.002
- T1114.003
- T1115
- T1119
- T1120
- T1124
- T1133
- T1136
- T1136.001
- T1137.005
- T1140
- T1185
- T1189
- T1190
- T1195
- T1199
- T1200
- T1203
- T1204
- T1204.002
- T1211
- T1213
- T1213.002
- T1217
- T1218
- T1486
- T1491.002
- T1496
- T1497
- T1497.001
- T1497.003
- T1498
- T1505
- T1518
- T1526
- T1528
- T1530
- T1531
- T1534
- T1537
- T1539
- T1543
- T1543.002
- T1547
- T1547.006
- T1548
- T1548.001
- T1548.003
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.002
- T1555
- T1556.003
- T1556.006
- T1557
- T1560
- T1562.006
- T1564
- T1564.008
- T1564.013
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1568.002
- T1571
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.014
- T1578
- T1580
- T1583
- T1583.001
- T1583.002
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1585
- T1585.002
- T1586
- T1587
- T1587.001
- T1588
- T1588.002
- T1588.003
- T1588.004
- T1589
- T1589.001
- T1589.002
- T1592
- T1595
- T1601
- T1602
- T1606.002
- T1608
- T1608.001
- T1608.004
- T1608.005
- T1620
- T1657
Threat actors
6 named threat actors across the reports.
- Contagious Interview (DPRK / Famous Chollima)
- Kali365 PhaaS operators (cluster overlap with Storm-1755; opportunistic abuse by APT29 / Midnight Blizzard)
- Screening Serpens (UNC1549)
- Ghostwriter (UAC-0057 / UNC1151)
- Void Dokkaebi (Famous Chollima)
- UNC2891
Nation-state attribution
- North Korea (DPRK)
- Russia / Iran
- Iran
- Belarus
- North Korea
Threat categories
- MALWARE
- SUPPLY_CHAIN
- PHISHING
- CLOUD
- APT
- VULNERABILITY
- ZERO_DAY
Severity breakdown
- critical5
- high9
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 99
- network 82
- file 63
- infrastructure 32
- technique 19
- malware 18
- entity 17
- package 17
- tool 14