Weekly review

ThreatNoir Morning Brief — June 5

2026-06-05Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 5, 2026

The threat landscape continues to evolve with multiple supply chain attacks dominating today's security news cycle. From compromised browsers to malicious npm packages, attackers are increasingly targeting the software distribution channels that organizations depend on. Additionally, a critical Cisco vulnerability with public exploit code has raised urgent patching priorities across enterprise networks.

Hola Browser for Windows Compromised to Deliver Cryptominer

The Windows version of the Hola Browser has fallen victim to a supply chain attack that injected an undeclared executable into the application. Security researchers identified the malicious payload as a cryptocurrency miner, specifically detecting files named HolaMonitorService.exe and me.exe that function as a Monero cryptocurrency miner. This incident underscores the vulnerability of even widely-used applications to supply chain compromise, where attackers intercept the distribution pipeline to inject malicious code before reaching end users. Source: Hola Browser for Windows compromised to deliver cryptominer

Credit Card Theft Campaign Abuses Stripe to Host Stolen Payment Info

A sophisticated Magecart campaign has leveraged Stripe's legitimate API infrastructure to both deliver credit card-stealing payloads and exfiltrate stolen payment card data from compromised checkout pages. The attackers exploited trusted third-party services by hosting their malicious code on api.stripe.com and googletagmanager.com, making the attack difficult to detect through standard security filters. This technique demonstrates how threat actors weaponize the trust placed in legitimate service providers to bypass security controls and compromise payment card information at scale. Source: Credit card theft campaign abuses Stripe to host stolen payment info

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco has released patches for CVE-2026-20230, a critical vulnerability in Unified Communications Manager that allows unauthenticated attackers on the network to write files to the system and escalate privileges to root level. The flaw is rooted in a server-side request forgery vulnerability that significantly reduces the barrier to exploitation. With proof-of-concept exploit code now publicly available, the window for attackers to leverage this vulnerability before organizations patch their systems has narrowed considerably. Cisco's Product Security Incident Response Team reports no active exploitation has been observed to date, but the public PoC accelerates the risk timeline. Source: Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

New IronWorm Malware Hits 36 Packages in npm Supply-Chain Attack

A newly discovered infostealer malware called IronWorm has compromised 36 packages on the Node Package Manager index in a significant supply chain attack targeting the open-source development community. The malware was distributed through compromised developer accounts and injected into legitimate npm packages, potentially affecting thousands of applications that depend on these libraries. The presence of malicious build configuration files such as binding.gyp indicates a sophisticated approach to maintaining persistence within the npm ecosystem. Source: New IronWorm malware hits 36 packages in npm supply-chain attack

Organizations face mounting pressure to strengthen their supply chain security posture as attackers continue to exploit trusted distribution channels. Today's incidents reinforce the critical importance of implementing robust verification mechanisms, monitoring third-party dependencies, and maintaining rapid patch deployment capabilities across all enterprise systems.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hola Browser for Windows compromised to deliver cryptominer
Malware3
  • me.exe
    Undeclared cryptominer executable installed to C:\Program Files\Hola\
  • HolaMonitorService.exe
    Copy of miner running as Windows service 'hola_monitor_svc'
  • Monero cryptocurrency miner
    Obfuscated binary miner discovered in Hola Browser distribution
Credit card theft campaign abuses Stripe to host stolen payment info
Malware1
  • Magecart
    Credit card skimming malware family targeting checkout pages
Domain2
  • googletagmanager.com
    Legitimate Google domain abused to host malicious GTM container and skimmer payload
  • api.stripe.com
    Legitimate Stripe API domain abused to exfiltrate stolen payment card data