Weekly review

ThreatNoir Morning Brief — July 10

2026-07-10Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 10, 2026

The threat landscape continues to shift toward supply-chain attacks targeting payment systems and cryptocurrency infrastructure, while destructive backdoors emerge as a growing concern for enterprise Windows environments. Three significant incidents spanning NuGet, npm, and Windows systems underscore the persistent vulnerability of software distribution channels and the evolving sophistication of malware frameworks designed for maximum operational impact.

Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials

Socket's AI scanner detected a sophisticated typosquat attack targeting payment developers on July 3, 2026, when a malicious NuGet package masquerading as the official Braintree payment gateway client was flagged within ten minutes of publication. The malicious package, published under the name Braintree.Net rather than the legitimate Braintree identifier, implements a multi-stage .NET implant that intercepts live payment card data, exfiltrates Braintree merchant API keys, and harvests host environment secrets upon assembly load. Source: Socket.dev

The attack leverages multiple deception techniques to target developers searching for the legitimate library. The malicious package uses a mismatched version scheme (3.36.1 versus the official 5.x line), includes metadata pointing to the real braintree/braintree_dotnet GitHub repository, and bundles a README copied directly from official Braintree documentation. The package name variation and documentation inconsistencies create multiple discovery paths for developers who mistype the package name or copy-paste installation instructions without careful review. Confirmed malicious versions include Braintree.Net 3.35.8 through 3.36.1, with approximately 334 real installations despite inflated download counts reaching 14 million through namespace pre-squatting with 120 empty placeholder versions.

The implant activates three independent exfiltration paths when a .NET application references the poisoned package. The CardOperationLogger class intercepts payment card data before legitimate Braintree API calls, capturing full primary account numbers, CVV values, expiration dates, and customer identifiers. The BraintreeGateway.PrivateKey property setter triggers credential theft when production environment credentials are configured, exfiltrating merchantId, publicKey, and privateKey to attacker infrastructure. A companion dependency, DependencyInjector.Core, runs module initializers at assembly load to harvest environment variables, application configuration files, cloud provider metadata, Kubernetes service account tokens, and database connection strings. All exfiltration paths route to api.348672-shakepay[.]com with silent failure handling that prevents merchant applications from detecting the compromise.

The attacker employed deliberate operational security measures including production-only gating for payment data theft while environment reconnaissance runs unconditionally, plaintext C2 strings in the payment stealer combined with XOR-encoded analytics endpoints in the companion dependency, and empty catch blocks on every exfiltration path to prevent exceptions that might trigger investigation. The domain 348672-shakepay[.]com uses Shakepay branding but resolves to Cloudflare anycast addresses consistent with attacker-controlled origin hiding. Socket has reported the package to NuGet for removal and publisher account suspension.

Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs

Microsoft has detailed GigaWiper, a destructive Windows backdoor capable of wiping disks, encrypting files, and providing attackers with remote access to compromised systems across global networks. Source: HackRead

The backdoor represents a significant escalation in destructive malware design by bundling three separate destructive programs into a single framework that operators can invoke as modular commands. This architecture allows attackers to choose between disk wiping, Windows drive overwriting, or fake ransomware that scrambles files with encryption keys never retained for recovery. The modular approach provides operational flexibility while maintaining plausible deniability through the appearance of unrelated destructive events.

Injective SDK on npm Infected with Cryptocurrency Wallet Stealer

Hackers compromised the Injective Labs SDK project's GitHub repository and deployed a malicious package on the Node Package Manager that steals cryptocurrency wallet private keys and mnemonic seed phrases from developers. Source: BleepingComputer

The attack demonstrates the continued targeting of cryptocurrency infrastructure through compromised developer tooling. By gaining access to the legitimate GitHub repository, attackers were able to publish malicious versions to npm that harvest sensitive cryptographic material from developers integrating the SDK into applications. This vector directly threatens wallet security and poses risks to both individual developers and applications built on the compromised dependency.

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft's technical analysis reveals that GigaWiper consolidates three destructive capabilities into a single operator-controlled backdoor, offering modular commands that enable disk erasure, Windows drive overwriting, or file encryption with irreversible key destruction. Source: The Hacker News

The backdoor's architecture represents a significant departure from traditional single-purpose malware by providing attackers with multiple destructive options that can be deployed selectively against target systems. The combination of disk wiping, fake ransomware functionality, and spyware capabilities creates a comprehensive toolkit for maximum operational impact. The modular design allows operators to tailor destruction methods to specific objectives, whether complete data annihilation, financial extortion simulation, or persistent surveillance.

Supply-chain compromises targeting both payment processing and cryptocurrency infrastructure continue to dominate the threat landscape, while destructive backdoors demonstrate the evolution toward multi-purpose frameworks that consolidate capabilities previously distributed across separate malware families. Organizations must prioritize dependency auditing, credential rotation, and network monitoring to detect and respond to these sophisticated attacks before they reach production environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Fake Braintree NuGet Package Skims Credit Cards and Harvests Merchant Credentials
Malware2
  • DependencyInjector.Core (NuGet package)
    Companion harvester dependency; versions 1.0.0, 1.3.0, 1.4.0, 1.4.1 confirmed malicious
  • Braintree.Net (NuGet package)
    Typosquat payment SDK stealer; versions 3.35.8, 3.35.9, 3.36.0, 3.36.1 confirmed malicious
Domain1
  • api.348672-shakepay.com
    C2 infrastructure for exfiltrating payment card data, merchant credentials, and environment secrets
URL3
  • hxxps://api[.]348672-shakepay[.]com/api/analytics/report
    Endpoint for environment variable, configuration file, and cloud metadata exfiltration
  • hxxps://api[.]348672-shakepay[.]com/api/account
    Endpoint for Braintree merchant key (merchantId, publicKey, privateKey) theft
  • hxxps://api[.]348672-shakepay[.]com/api/card
    Endpoint for PAN/CVV exfiltration
SHA-2562
  • efec1e537445…
    DependencyInjector.Core.dll malicious assembly hash
  • 7a9f19ed663c…
    Braintree.dll malicious assembly hash