- me.exeUndeclared cryptominer executable installed to C:\Program Files\Hola\
- HolaMonitorService.exeCopy of miner running as Windows service 'hola_monitor_svc'
- Monero cryptocurrency minerObfuscated binary miner discovered in Hola Browser distribution
ThreatNoir Morning Brief — June 5
Morning Review in IT Security — June 5, 2026
The threat landscape continues to evolve with multiple supply chain attacks dominating today's security news cycle. From compromised browsers to malicious npm packages, attackers are increasingly targeting the software distribution channels that organizations depend on. Additionally, a critical Cisco vulnerability with public exploit code has raised urgent patching priorities across enterprise networks.
Hola Browser for Windows Compromised to Deliver Cryptominer
The Windows version of the Hola Browser has fallen victim to a supply chain attack that injected an undeclared executable into the application. Security researchers identified the malicious payload as a cryptocurrency miner, specifically detecting files named HolaMonitorService.exe and me.exe that function as a Monero cryptocurrency miner. This incident underscores the vulnerability of even widely-used applications to supply chain compromise, where attackers intercept the distribution pipeline to inject malicious code before reaching end users. Source: Hola Browser for Windows compromised to deliver cryptominer
Credit Card Theft Campaign Abuses Stripe to Host Stolen Payment Info
A sophisticated Magecart campaign has leveraged Stripe's legitimate API infrastructure to both deliver credit card-stealing payloads and exfiltrate stolen payment card data from compromised checkout pages. The attackers exploited trusted third-party services by hosting their malicious code on api.stripe.com and googletagmanager.com, making the attack difficult to detect through standard security filters. This technique demonstrates how threat actors weaponize the trust placed in legitimate service providers to bypass security controls and compromise payment card information at scale. Source: Credit card theft campaign abuses Stripe to host stolen payment info
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has released patches for CVE-2026-20230, a critical vulnerability in Unified Communications Manager that allows unauthenticated attackers on the network to write files to the system and escalate privileges to root level. The flaw is rooted in a server-side request forgery vulnerability that significantly reduces the barrier to exploitation. With proof-of-concept exploit code now publicly available, the window for attackers to leverage this vulnerability before organizations patch their systems has narrowed considerably. Cisco's Product Security Incident Response Team reports no active exploitation has been observed to date, but the public PoC accelerates the risk timeline. Source: Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
New IronWorm Malware Hits 36 Packages in npm Supply-Chain Attack
A newly discovered infostealer malware called IronWorm has compromised 36 packages on the Node Package Manager index in a significant supply chain attack targeting the open-source development community. The malware was distributed through compromised developer accounts and injected into legitimate npm packages, potentially affecting thousands of applications that depend on these libraries. The presence of malicious build configuration files such as binding.gyp indicates a sophisticated approach to maintaining persistence within the npm ecosystem. Source: New IronWorm malware hits 36 packages in npm supply-chain attack
Organizations face mounting pressure to strengthen their supply chain security posture as attackers continue to exploit trusted distribution channels. Today's incidents reinforce the critical importance of implementing robust verification mechanisms, monitoring third-party dependencies, and maintaining rapid patch deployment capabilities across all enterprise systems.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- MagecartCredit card skimming malware family targeting checkout pages
googletagmanager.comLegitimate Google domain abused to host malicious GTM container and skimmer payloadapi.stripe.comLegitimate Stripe API domain abused to exfiltrate stolen payment card data
- Critical SSRF in Cisco Unified Communications Manager enabling unauthenticated file write and root escalation
- Hard-coded root SSH account in Unified CM (CVSS 10), patched July 2025
- Unauthenticated RCE in Cisco voice products, exploited in the wild, added to CISA KEV catalog
- binding.gypJavaScript-based malware performing registry poisoning and GitHub Actions infection
- IronWormRust-based infostealer malware targeting npm packages