Weekly review

ThreatNoir Afternoon Brief — April 6

2026-04-06Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — April 6, 2026

The security landscape continues to face mounting pressure from sophisticated threat actors exploiting supply chain vulnerabilities, conducting extended social engineering campaigns, and targeting critical infrastructure. Today's briefing covers malicious package distribution, multi-million-dollar cryptocurrency theft, coordinated attacks on open-source maintainers, and emergency patching efforts for critical zero-days.

Guardarian Users Targeted With Malicious Strapi NPM Packages

Threat actors have published 36 malicious NPM packages designed to impersonate Strapi plugins, targeting users of the Guardarian cryptocurrency gateway. These packages contain multiple attack payloads including credential harvesting mechanisms, Docker escape exploits, Redis remote code execution capabilities, and shell execution functionality. The distribution of these packages demonstrates the ongoing risk posed by supply chain attacks targeting the cryptocurrency and development communities through popular package repositories.

Source: SecurityWeek

North Korean Hackers Pose as Trading Firm to Steal $285M from Drift

A North Korean threat actor group designated UNC4736 conducted an extended social engineering operation against Drift Protocol, maintaining a false trading firm persona for six months before executing a theft of $285 million in cryptocurrency. The prolonged engagement allowed the attackers to build trust and bypass security measures without triggering suspicion. This campaign highlights the effectiveness of patient, long-term social engineering tactics against even security-conscious cryptocurrency platforms.

Source: Hackread

North Korean Hackers Target High-Profile Node.js Maintainers

The same threat actor responsible for the Axios supply chain attack has expanded its targeting to other prominent Node.js package maintainers through sophisticated social engineering campaigns. The attackers are employing remote access trojans as part of their arsenal to compromise these critical open-source developers. This coordinated effort against the Node.js ecosystem represents a significant threat to the integrity of widely-used software dependencies.

Source: SecurityWeek

Fortinet Rushes Emergency Fixes for Exploited Zero-Day

Fortinet has released emergency patches addressing critical improper access control vulnerabilities in FortiClient EMS that allow unauthenticated attackers to execute arbitrary code remotely. The affected vulnerabilities are tracked as CVE-2026-21643 and CVE-2026-35616. The rapid deployment of these fixes reflects the severity of the zero-day exploitation and the immediate risk posed to organizations relying on Fortinet's endpoint management solutions.

Source: SecurityWeek

Today's threat landscape demonstrates a coordinated assault across multiple attack vectors, from package repository poisoning to extended social engineering operations and active zero-day exploitation. Organizations should prioritize supply chain security assessments, implement enhanced verification procedures for third-party relationships, and maintain aggressive patching schedules for critical infrastructure components.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Guardarian Users Targeted With Malicious Strapi NPM Packages
Malware4
  • Malicious Strapi NPM packages (36 total)
    Campaign targeting Guardarian cryptocurrency payment gateway via NPM package poisoning
  • Redis RCE payload
    Injects crontab entries, deploys PHP webshells, Node.js reverse shells, SSH key injection
  • Docker escape payload
    Exploits overlay filesystem, writes shells to host, launches reverse shells, exfiltrates credentials
  • Credential harvesting payload
    Targets PostgreSQL, Elasticsearch, wallet files, Strapi configurations, persistent implants