Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 29, 2026

10 min read
shutterstock 2225722675

Summary

A single typo in a developer’s workflow can now open the door to a self-spreading Linux worm. The DirtyBlanket npm campaign, tracked by SafeDep, leverages nine impostor packages to hijack build systems, steal SSH keys and npm tokens, and propagate across engineering environments. Cyware highlights how this attack chain threatens to poison software supply chains and grant attackers unauthorized access to critical infrastructure.

A critical flaw in GitLab, cataloged as CVE-2026-85706 with a maximum CVSS score of 10.0, is under active exploitation. Attackers can bypass controls by URL-encoding a single letter in the commits API, exposing sensitive server files and configuration secrets. With CISA adding this bug to its Known Exploited Vulnerabilities list, organizations must urgently patch to prevent data leaks and unauthorized access.

GPU rental platforms have become a new battleground as the VHX Harvester operation targets vast[.]ai’s exposed infrastructure. The campaign has already scanned 13,368 endpoints, enumerated 297 host IPs, and exfiltrated metadata from 416 services. This surge in attacks underscores the risks of shared AI compute environments, where one misstep can expose entire clusters to compromise.

CTA_1_LI_Tuesday_Saturday_DTI_MTI_After_Overview

Top Malware Reported in the Last 24 Hours

DirtyBlanket npm worm spreads via impostors

DirtyBlanket is a malicious npm campaign that turns typosquatted developer packages into a self-spreading Linux worm, aiming to hijack the very systems used to build and ship software. It rides in nine packages—xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, and exptredd—published in quick succession on September 29, 2026 by the npm user dirtyblanket. It kicks off through a preinstall hook that pulls in a Node binary and then runs a Linux script, after which it drops a backdoor, steals SSH keys and npm tokens, and uses them to spread to other hosts and even tamper with additional npm packages. Researchers at SafeDep linked the activity to this coordinated package set, warning that a single mistaken install can cascade into wider compromise across an engineering environment. Affected teams face a practical fallout: stolen SSH keys and tokens can translate into unauthorized server access and poisoned builds; removal of the identified packages, key and token revocation, and watching for unusual Tor-related network traffic were advised.

DarkSword scam hits iPhones on open

DarkSword is an exploit chain being pushed through a fake Apple-style “iPhone Duo” preorder page that claims to offer a $500 voucher, attempting to steal sensitive data the moment the page loads. It targets iOS 18.4 through 18.6.2 and is designed to run without any user interaction beyond opening the link, aiming to break through device protections and reach valuable information. If it succeeds, the payload tries to contact its server with device details and then reaches for cryptocurrency wallet data, saved credentials, and personal content like messages and call history, while attempting to delete diagnostic reports to reduce traces. Malwarebytes described the operation as a scam-led delivery mechanism where a convincing shopping lure doubles as the trigger for exploitation. For iPhone owners, the consequence is immediate: a single visit can put accounts and wallets at risk; updating to the latest iOS version, avoiding unfamiliar links, and securing crypto wallets were recommended.

RatHat Trojan uses Gemini to triage

RatHat is an Android banking trojan built around a web console that lets operators remotely control infected phones, and it uses Google’s Gemini AI to assess bank balances and sort victims into “high-value” and “mid-value” buckets. It spreads through text messages and online ads that funnel people to third-party download sites, turning everyday mobile browsing into a route for credential and funds theft. Once installed, it can enable intrusive control such as streaming the screen and sending taps, and it aims to keep access even when victims think they have removed the app. Cleafy reported nearly 100 deployments of the RatHat console since April 2026, framing it as a malware-as-a-service operation with tooling meant to help multiple operators run campaigns. For consumers and businesses with Android devices on the road, that translates into a higher chance of account takeover and fraudulent transfers; Cleafy recommended blocking the identified C2 infrastructure and monitoring for signs of unauthorized shell access.

Top Vulnerabilities Reported in Last 24 hours

GitLab bug exposes server files

A critical GitLab vulnerability (CVE-2026-85706, CVSS 10.0) lets unauthenticated attackers read files directly from the server filesystem, potentially exposing configuration secrets, internal logs, and source paths. The attack works by URL-encoding a letter in the commits API to bypass expected controls and pull back sensitive file contents. Attackers are already exploiting this in the wild, and CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog. Researchers at EQSTLab shared a proof-of-concept at hxxps://github[.]com/EQSTLab/CVE-2026-85706. A fix is available in GitLab 19.1.8, 19.2.6, and 19.3.2 (affected versions are prior to those releases).

Citrix NetScaler flaws hit at scale

Two critical Citrix NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) are being exploited to remotely take control of internet-facing access infrastructure many organizations rely on for remote connectivity and traffic management. Reports say attackers are keeping access by planting unique webshells and using anti-forensic steps to make investigations harder, raising the odds that some compromises won’t be immediately obvious. Attackers are already exploiting this in the wild, with CERT Europe, GreyNoise, and multiple independent researchers describing widespread activity, and CISA directing federal agencies to conduct forensics. Security researchers Simo Kohonen and Kevin Beaumont have been among those documenting the webshell tradecraft. A fix is available via Citrix security updates released on September 27, 2026, and the wave of attacks echoes prior NetScaler crises such as Citrix Bleed.

Zero-day Citrix exploitation predates disclosure

GreyNoise says attackers attempted to exploit Citrix NetScaler Gateway via CVE-2026-88771 as a zero-day, with activity observed on September 24, 2026—days before public disclosure on September 27. The observed activity centered on login command injection behavior consistent with an attempt to execute arbitrary commands and establish deeper control of the appliance. Attackers are already exploiting this in the wild, and follow-on reporting describes the same campaign family using webshell-based persistence and cleanup actions to reduce evidence. GreyNoise published the activity based on telemetry from its Global Observation Grid (GOG) and Project Swarm. A fix is available for CVE-2026-88771.

Top Threat Actors Reported in Last 24 hours

VHX Harvester probes vast.ai GPU rentals

VHX Harvester is an active operation positioned to turn rented GPU infrastructure into an attack surface, targeting the vast[.]ai marketplace after a misconfigured control panel exposed source code. They have already enumerated 297 host IPs, scanned 13,368 service endpoints, and exfiltrated metadata from 416 services as they map what’s available to exploit. For teams relying on GPU rentals for AI workloads, the consequence is that a shared hosting model can turn one renter’s activity into another renter’s intrusion risk. The campaign stands out for tactics like deploying a “bridge agent” model, injecting stored XSS into Caddy auth portals, and using npm typosquats to discover GPU infrastructure. The operator has deployed 25 bridge agents and reached one confirmed root shell on a victim’s Jupyter notebook, though researchers say no cryptocurrency miners have been planted yet.

Nigeria-linked scammers hijack U.S. university mail

West African fraud actors, linked by researchers to Nigeria, are targeting U.S. universities by taking over email accounts and using them to run job-based advanced fee fraud (AFF) schemes. They start by harvesting credentials with form-based phishing hosted on legitimate services, then use the compromised campus mailboxes to send job-scam messages that funnel victims into fake “application” forms designed to capture personal information. For students and job seekers, the fallout can be identity theft and escalating financial pressure once scammers have enough details to impersonate trusted institutions. Proofpoint says the actors also lean on tracking links and impersonation of university staff and even law enforcement (including FBI agents) to coerce payments. The report also calls out multifactor authentication (MFA) as a key control universities can implement to deter account takeovers.

AgtaBackup RAT delivered through trusted RMM

Threat actors are abusing trusted remote monitoring and management (RMM) tools to quietly deliver a new .NET remote access trojan called AgtaBackup RAT to Windows endpoints. They lure victims through a fraudulent Microsoft Store-style page impersonating a videoconferencing app, then trick them into installing legitimate RMM software such as LogMeIn Resolve or ConnectWise ScreenConnect, which the adversary uses as a stepping stone to deploy the RAT. For businesses, this approach makes malicious activity harder to spot because the initial foothold blends into normal admin tooling and can lead to surveillance and data theft, including browser credentials and cookies. The malware is described as masquerading as Windows Credential Guard and mimicking Dell and Windows Security executables, while setting persistence via SYSTEM scheduled tasks and leaving artifacts like AgtaBackupAgentSvc, AgtaBackupAgentWatchdog, and AgtaBackupAgentGuardian. The write-up also recommends blocking the RAT’s communication endpoints and adding IOCs to blocklists.

CTA_2_LI_Tuesday_Saturday_DTI_MTI_Before_FAQ

Frequently Asked Questions

  1. What is DirtyBlanket? DirtyBlanket is a malicious npm campaign that turns typosquatted developer packages into a self-spreading Linux worm, aiming to hijack the very systems used to build and ship software. It rides in nine packages—xeprews, express-javascript, express-nodejs, react-nodejs, exprdd, exprrdd, exptrdd, exptred, and exptredd—published in quick succession on September 29, 2026 by the npm user dirtyblanket.

  2. What is DarkSword? DarkSword is an exploit chain being pushed through a fake Apple-style “iPhone Duo” preorder page that claims to offer a $500 voucher, attempting to steal sensitive data the moment the page loads. It targets iOS 18.4 through 18.6.2 and is designed to run without any user interaction beyond opening the link, aiming to break through device protections and reach valuable information.

  3. What is RatHat? RatHat is an Android banking trojan built around a web console that lets operators remotely control infected phones, and it uses Google’s Gemini AI to assess bank balances and sort victims into “high-value” and “mid-value” buckets. It spreads through text messages and online ads that funnel people to third-party download sites, turning everyday mobile browsing into a route for credential and funds theft.

  4. What is CVE-2026-85706? A critical GitLab vulnerability (CVE-2026-85706, CVSS 10.0) lets unauthenticated attackers read files directly from the server filesystem, potentially exposing configuration secrets, internal logs, and source paths. The attack works by URL-encoding a letter in the commits API to bypass expected controls and pull back sensitive file contents.

  5. What is CVE-2026-88771? Two critical Citrix NetScaler ADC and Gateway vulnerabilities (CVE-2026-88771 and CVE-2026-88772, CVSS 9.5) are being exploited to remotely take control of internet-facing access infrastructure many organizations rely on for remote connectivity and traffic management. Reports say attackers are keeping access by planting unique webshells and using anti-forensic steps to make investigations harder, raising the odds that some compromises won’t be immediately obvious.

  6. What is VHX Harvester? VHX Harvester is an active operation positioned to turn rented GPU infrastructure into an attack surface, targeting the vast[.]ai marketplace after a misconfigured control panel exposed source code. They have already enumerated 297 host IPs, scanned 13,368 service endpoints, and exfiltrated metadata from 416 services as they map what’s available to exploit.

  7. What is AgtaBackup RAT? Threat actors are abusing trusted remote monitoring and management (RMM) tools to quietly deliver a new .NET remote access trojan called AgtaBackup RAT to Windows endpoints. They lure victims through a fraudulent Microsoft Store-style page impersonating a videoconferencing app, then trick them into installing legitimate RMM software such as LogMeIn Resolve or ConnectWise ScreenConnect, which the adversary uses as a stepping stone to deploy the RAT.

Discover Related Resources