- mouse5212-super-formatterMalicious npm package designed to steal files from Claude AI user directory
- Malware-SlopCampaign codename for the malicious npm package exfiltration campaign
ThreatNoir Morning Brief — May 28
Morning Review in IT Security — May 28, 2026
The threat landscape continues to evolve with attackers employing increasingly sophisticated hybrid approaches, from physical intrusions paired with digital exploitation to supply chain compromises targeting AI development environments. Today's briefing covers critical threats affecting legal services, open-source ecosystems, conference infrastructure, and government payroll systems across multiple sectors and geographies.
FBI Warns US-Based Law Firms of Silent Ransom Group's Hybrid Attack Strategy
The Federal Bureau of Investigation has issued a warning to US-based law firms regarding the Silent Ransom Group, a cybercrime organization that has demonstrated a distinctive operational approach combining social engineering with in-person visits to victim workstations. While not prolific in volume, the group has shown particular effectiveness in targeting the legal services sector through this dual methodology. Source: FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
The group's willingness to conduct physical reconnaissance and direct access operations represents a notable escalation in ransomware tactics, moving beyond purely remote exploitation. Law firms should implement enhanced access controls, monitor for unauthorized physical presence in sensitive areas, and train staff to recognize social engineering attempts that may precede data theft operations.
Malicious npm Package Targets Claude AI Users Through Supply Chain Attack
Cybersecurity researchers have identified a malicious package on the npm registry designed to steal files from Anthropic's Claude AI platform. The package, named "mouse5212-super-formatter," contains information-stealing capabilities specifically targeting the "/mnt/user-data" directory used by Claude for handling uploads and outputs. According to OX Security's analysis, this represents a direct attack on AI development workflows through the open-source software supply chain. Source: Malicious npm Package Stole Files From Claude AI User Directory via GitHub
This incident highlights the vulnerability of AI development environments to supply chain compromise. Developers working with Claude or other AI tools should exercise caution when installing npm packages, verify package authenticity, and implement strict dependency management practices to prevent unauthorized access to sensitive AI-generated content and user data.
Account Takeover Vulnerability Discovered in Pretalx Conference Management Software
Novee researchers have uncovered an account takeover vulnerability in Pretalx, an open-source call for papers management tool widely used by conference organizers. The vulnerability, identified as CVE-2026-41241, granted attackers the ability to achieve a 100% talk acceptance rate and gain unauthorized access to conference speaker accounts. Source: Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate
This vulnerability poses significant risks to conference infrastructure and the broader academic and technology communities that depend on Pretalx for event management. Organizations operating Pretalx instances should prioritize patching this vulnerability and review their account access logs for signs of unauthorized activity or suspicious speaker submissions during the vulnerability window.
Spanish Public Payroll Portal Breach Exposes 371 Government Employee Accounts
A threat actor has claimed access to 371 payroll accounts associated with a Spanish public management portal, with alleged capability to modify bank deposit details used for SEPA payroll payments. The compromise potentially allows attackers to redirect government employee salaries to unauthorized accounts. Source: 🚨🇪🇸 Spanish public payroll panel allegedly offered for sale
This incident represents a critical infrastructure threat with direct financial impact on government employees and broader implications for public sector security. Spanish authorities should immediately audit payroll system access controls, verify the integrity of banking information on file for all affected employees, and implement enhanced monitoring for unauthorized payment modifications.
Today's threat landscape demonstrates that attackers continue to innovate across multiple vectors—combining physical and digital tactics, exploiting trusted software repositories, compromising critical infrastructure, and targeting high-value sectors. Organizations should prioritize threat intelligence sharing, supply chain security assessments, and access control reviews across both digital and physical security domains.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Stored XSS vulnerability in Pretalx enabling account takeover via malicious talk submissions
- Spanish public payroll portal compromiseAlleged unauthorized access to 371 payroll accounts with modification capabilities