Threat reportVulnerabilityTL-2026-0441

Qinglong Task Scheduler Auth Bypass Chain to RCE (CVE-2026-3965, CVE-2026-4047) — .fullgc Cryptomining Campaign

criticalACTIVE

Qinglong Task Scheduler Auth Bypass Chain to RCE (TL-2026-0441) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-05-01. It has no confirmed attribution, references 2 CVEs (CVE-2026-3965, CVE-2026-4047), maps to 19 MITRE ATT&CK techniques (T1036, T1053, T1059), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
9.3/10Critical
CVEs
2Referenced vulnerabilities
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0441

Threat ID
TL-2026-0441
Severity
CRITICAL
CVSS
9.3
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Target sectors
technology, software-development, individual-developers, self-hosted-automation
Target regions
Global, China, East Asia, North America, Europe
Detection rules
9
Indicators of compromise
20

Malware and tooling in Qinglong Task Scheduler Auth Bypass Chain to RCE

Malware and tooling: fullgc

How Qinglong Task Scheduler Auth Bypass Chain to RCE works

An unidentified threat actor is chaining two unauthenticated authentication bypass vulnerabilities in the Qinglong open-source task scheduler (@whyour/qinglong, versions ≤ 2.20.1) to take over publicly exposed developer panels and deploy a multi-architecture cryptominer named .fullgc. CVE-2026-3965 (CWE-94, CVSS 9.3) abuses an Express.js URL rewrite that maps /open/* to /api/$1, exposing protected admin endpoints; CVE-2026-4047 (CWE-178, CVSS 9.3) bypasses the auth middleware via case-sensitivity mismatch (/aPi/...) so any privileged route can be reached unauthenticated. In-the-wild exploitation has been observed since 2026-02-07, with payloads served from file.551911.xyz to /ql/data/db/.fullgc on Linux x86_64, ARM64, and macOS.

The Qinglong Task Scheduler (@whyour/qinglong on npm; ~19k GitHub stars, ~3.2k forks) is a popular Node.js task automation panel used heavily by developers — particularly in the Chinese-language community — to run scheduled scripts. In early February 2026, Qinglong users began reporting a hidden process named .fullgc consuming 85-100% CPU on their hosts. The process name imitates Java's "Full GC" garbage collection logs to evade casual inspection.

Investigation by Snyk (disclosed 2026-02-26 and 2026-02-27, published 2026-03-12) identified two distinct authentication bypass primitives that together allow an unauthenticated remote attacker to achieve RCE on any Internet-exposed Qinglong instance running version 2.20.1 or older.

CVE-2026-3965 (CWE-94, Improper Control of Generation of Code, CVSS 9.3): Qinglong configures Express.js middleware that rewrites incoming /open/* requests to /api/$1 to expose a small set of public endpoints. The rewrite is performed BEFORE the authentication middleware decides whether the request is privileged, so the security middleware sees an /open/ path (treated as public) while the router resolves to a fully privileged /api/ endpoint. An attacker can therefore call PUT /open/user/init with a JSON body containing a new admin username/password and the panel will reinitialize its credentials, granting full administrative control. From the panel an attacker can register and execute arbitrary scripts.

CVE-2026-4047 (CWE-178, Improper Handling of Case Sensitivity, CVSS 9.3): The authentication middleware checks req.path.startsWith('/api/') in case-sensitive fashion, while the Express.js router matches routes case-insensitively on the same paths. By requesting /aPi/system/command-run (or any other capitalization variant) an attacker bypasses the middleware entirely and reaches the command execution endpoint with no authentication. A single PUT to /aPi/system/command-run with a JSON {"command":"..."} body executes shell commands on the host.

In the observed campaign, the attacker chains either bypass to inject into Qinglong's config.sh, which is executed by the panel on schedule. The injected payload uses uname to detect platform and architecture and downloads a matching cryptominer binary from https://file.551911.xyz/fullgc/$(uname -s)_$(uname -m), saving it to /ql/data/db/.fullgc, chmod +x'ing it, and running it via nohup so it survives session exit. Binaries are provided for Linux x86_64, Linux ARM64 (aarch64), and macOS variants. The miner contains persistence logic that restarts itself if killed.

Qinglong maintainers initially responded with PR #2924, attempting to block command-injection patterns (curl, wget, shell metacharacters) at an input-validation layer — a mitigation that did not fix the underlying auth bypass. The effective patch landed in PR #2941 (commit 6bec52dca158481258315ba0fc2f11206df7b719 / ce599d306f81e3ebb0f6eaa5b540d701a6d4085d), shipped in @whyour/qinglong 2.20.2-0. Many Internet-exposed instances likely remain unpatched given Qinglong's distribution as a self-hosted Docker/npm app and the gap between exploitation (2026-02-07) and effective fix release.

No formal threat-actor attribution exists. The infrastructure (.xyz domain, multi-architecture cryptominer, no espionage tooling) and target (Chinese-language developer community running Qinglong) are consistent with an opportunistic financially-motivated cryptojacking operator rather than an APT.

MITRE ATT&CK techniques used in TL-2026-0441

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts

Persistence

T1053 Scheduled Task/Job; T1098 Account Manipulation; T1546 Event Triggered Execution

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Impact

T1496 Resource Hijacking

Credential Access

T1555 Credentials from Password Stores; T1606 Forge Web Credentials

Reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

CVEs associated with Qinglong Task Scheduler Auth Bypass Chain to RCE

CVE-2026-3965, CVE-2026-4047

Timeline of Qinglong Task Scheduler Auth Bypass Chain to RCE

  • First Qinglong users report a hidden .fullgc process consuming 85-100% CPU; in-the-wild exploitation of the auth bypass chain begins before any public disclosure.
  • Multiple Qinglong panel operators independently report the same .fullgc cryptominer behaviour across Linux x86_64, ARM64, and macOS hosts.
  • Qinglong community members request a public security warning from the maintainers after observing widespread compromise.
  • Further compromise reports surface; payload consistently sourced from file.551911.xyz with platform-specific binaries.
  • CVE-2026-3965 (URL rewrite /open/* to /api/$1 auth bypass, CWE-94) discovered and reported to maintainers.
  • CVE-2026-4047 (case-sensitive auth middleware vs case-insensitive Express router, CWE-178) publicly reported via GitHub Issue #2934.
  • Qinglong maintainer publicly confirms both vulnerabilities and active exploitation.
  • PR #2924 attempts to block command-injection patterns at the input-validation layer; does not address the auth bypass and is superseded.
  • PR #2941 lands the actual auth-middleware fix (commits 6bec52dca158481258315ba0fc2f11206df7b719 and ce599d306f81e3ebb0f6eaa5b540d701a6d4085d), released as @whyour/qinglong 2.20.2-0.
  • Snyk publishes both CVE-2026-3965 and CVE-2026-4047 advisories with CVSS 9.3 (Critical).
  • BleepingComputer, Snyk Labs, and other outlets publish detailed campaign analysis; many Internet-exposed instances likely remain unpatched.
  • Threadlinqs Intelligence publishes TL-2026-0441 with full IOC, MITRE, and detection coverage.
  • As of 2026-05-29, the Qinglong auth-bypass chain (CVE-2026-3965/4047, CVSS 9.3) remains actively exploited: a fix shipped in v2.20.2-0 (PR #2941), but late-April reporting (BleepingComputer, Snyk, SC Media) confirms the .fullgc cryptomining campaign is ongoing with live file.551911.xyz infra and many self-hosted panels unpatched. Not in CISA KEV; no takedown reported.

Sources cited for Qinglong Task Scheduler Auth Bypass Chain to RCE

Detection coverage for TL-2026-0441

As of 2026-05-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0441 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats