Weekly review

ThreatNoir Morning Brief — June 1

2026-06-01Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 1, 2026

The threat landscape continues to evolve with sophisticated supply chain attacks targeting open-source ecosystems, malicious AI-powered forking campaigns, and critical vulnerabilities in widely-used development tools. Today's review covers emerging threats across PHP, Node.js, and WordPress environments that demand immediate attention from development teams and security practitioners.

AI-Powered Supply Chain Attack Targets Open Source Projects

Automated AI systems are now being weaponized to fork legitimate Linux open-source projects and inject malicious content disguised as professional documentation. The attack creates fake README files with download links that distribute malware-laden ZIP files to unsuspecting developers. This represents a new frontier in supply chain compromise where automation enables attackers to scale their operations across multiple projects simultaneously. Source: X/Twitter Post

APT Group Compromises PHP Package Repository to Target Developers

A sophisticated North Korean APT group designated Famous Chollima successfully compromised the Packagist PHP package repository by injecting obfuscated malicious JavaScript into the roberts/leads package development branch. The malware was hidden within a tailwind.js configuration file using whitespace obfuscation techniques and employed blockchain infrastructure as a dead drop mechanism to retrieve encrypted payloads. The malicious code leveraged TRON, Aptos, and BNB Smart Chain services to host payload material and utilized hardcoded XOR keys for decryption before executing the staged payload via eval(). The threat actors likely targeted this package as part of a fake job interview or developer task scenario consistent with their known social engineering tactics. Packagist's security team promptly removed the affected dev-drewroberts/feature/test-case version after notification. Source: Socket.dev Blog

Malicious npm Package Steals OpenAI Tokens from 27,000 Weekly Downloads

A compromised Codex UI npm package with substantial weekly download volume was discovered exfiltrating OpenAI refresh tokens from developer environments. The malicious package exposed thousands of developers to account takeover risks by stealing authentication credentials that could grant attackers full access to OpenAI accounts and associated resources. This incident highlights the persistent threat posed by supply chain compromise in the Node.js ecosystem where popular packages reach massive audiences before detection. Source: Hackread

WordPress Plugin Vulnerability Enables Unauthorized Admin Access

The WP Maps Pro WordPress plugin contains a critical vulnerability tracked as CVE-2026-8732 that allows attackers to create rogue administrator accounts on affected websites without authentication. Threat actors are actively exploiting this flaw to gain unauthorized administrative access to WordPress installations running vulnerable versions of the plugin. Website administrators should immediately patch or disable the affected plugin to prevent account hijacking. Source: Bleeping Computer

Today's threat intelligence underscores the critical importance of supply chain vigilance across all development ecosystems. Organizations must implement strict dependency management, conduct regular security audits of third-party packages, and maintain rapid incident response capabilities to address compromised libraries before they reach production environments.

Yesterday I got a funny DM. @s00pcan said some AI slop is automatically forking his Linux open-so...

Source: Yesterday I got a funny DM. @s00pcan said some AI slop is automatically forking his Linux open-so...

Yesterday I got a funny DM. @s00pcan said some AI slop is automatically forking his Linux open-source projects and adding goofy ass ReadMe files to look all fancy. The primary difference though is the ReadMe includes a "download here" link which delivers a .zip file.

The .zip https://t.co/F2Ixv6OemQ

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Famous Chollima Targets PHP Developers Through Compromised Packagist Package
MITRE ATT&CK6
Domain2
  • trongrid.io
    TRON API
  • aptoslabs.com
    Aptos API
URL2
  • hxxps://api[[.]]trongrid[[.]]io/v1/accounts/TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP/transactions?only_confirmed=true&only_from=true&limit=1
    TRON API to retrieve transaction data
  • hxxps://fullnode[[.]]mainnet[[.]]aptoslabs[[.]]com/v1/accounts/0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e/transactions?limit=1
    Aptos API to retrieve transaction data
SHA-2562
  • 522b28a2f787…
    Archive SHA256
  • 96afdba88204…
    tailwind.js SHA256