- Lumma stealerInfostealer malware used to obtain Context.ai employee credentials in February 2026, facilitating access chain
ThreatNoir Afternoon Brief — April 20
Afternoon Review in IT Security — April 20, 2026
The cybersecurity landscape continues to present critical challenges across multiple vectors today, with vulnerabilities affecting widely-deployed open-source libraries, breaches impacting infrastructure providers, and emerging threats targeting cryptocurrency users on mainstream platforms. These developments underscore the persistent risks facing organizations and individuals relying on third-party tools and services.
52M-Download protobuf.js Library Hit by RCE in Schema Handling
A critical remote code execution vulnerability has been discovered in the protobuf.js library, which has accumulated over 52 million downloads. The flaw allows attackers to execute arbitrary code by crafting malicious schemas, posing a significant risk to applications that depend on this widely-used JavaScript library for protocol buffer handling. Organizations utilizing affected versions must prioritize patching to prevent exploitation of this vulnerability in their supply chains. Source: Hackread
Next.js Creator Vercel Hacked
Vercel, the company behind the popular Next.js framework, has confirmed a security breach after a threat actor claiming affiliation with ShinyHunters publicly offered to sell stolen data for $2 million. The incident highlights the risks posed by compromises at infrastructure and platform providers, where attackers can gain access to sensitive information affecting numerous downstream users and developers. The Lumma stealer malware has been identified in connection with this incident. Source: SecurityWeek
Network 'Background Noise' May Predict the Next Big Edge-Device Vulnerability
Researchers at GreyNoise have identified a consistent pattern in network reconnaissance activity that precedes major vulnerabilities affecting security tools and edge devices. By analyzing what appears as background noise in network traffic, defenders can potentially gain an early-warning system for imminent attacks targeting vulnerable infrastructure. This discovery provides security teams with a proactive methodology for anticipating and preparing for exploitation of zero-day and newly-disclosed vulnerabilities. Source: CyberScoop
FakeWallet Crypto Stealer Spreading Through iOS Apps in the App Store
Over twenty malicious applications masquerading as legitimate cryptocurrency wallets have been discovered in the Apple App Store as of March 2026. The FakeWallet malware steals user credentials and funds by deceiving users into believing they are interacting with trusted wallet services. This campaign demonstrates how threat actors continue to exploit the app store review process, bypassing security controls to distribute credential-stealing malware to unsuspecting users. Source: Securelist
Today's threat landscape reflects a multi-layered attack surface spanning open-source ecosystems, cloud infrastructure providers, network reconnaissance patterns, and consumer-facing platforms. Organizations and individuals must maintain vigilance across all these domains while prioritizing rapid patching and verification of third-party application authenticity.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- FakeWalletiOS crypto stealer malware masquerading as legitimate wallets in App Store