Weekly review

ThreatNoir Weekend Brief — July 12

2026-07-12Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 12, 2026

The threat landscape continues to evolve rapidly across multiple attack vectors. Today's security briefing covers critical vulnerabilities in popular development tools, state-sponsored espionage targeting law enforcement infrastructure, reconnaissance activities targeting software repositories, and a coordinated global campaign exploiting content management systems.

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A malicious version of the jscrambler npm package was published on July 11, 2026, introducing a significant supply chain risk to developers worldwide. The compromised 8.14.0 release executes a Rust-based infostealer automatically during installation through a preinstall hook mechanism. The malware drops and executes native binaries compiled for Windows, macOS, and Linux systems, ensuring broad compatibility across developer environments.

Security researchers at Socket detected the malicious release just six minutes after publication, demonstrating the critical importance of automated monitoring in the open source ecosystem. The threat actors leveraged infrastructure associated with IP addresses 185.220.101.105 and 185.220.101.106 in connection with this attack. Source: Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed a sustained cyber espionage campaign targeting Pakistani law enforcement organizations, with activity spanning from February 2024 through April 2026. The campaign involved suspected China- and India-aligned threat actors who compromised servers hosting critical web applications at Balochistan Police, gaining access to systems managing sensitive police and citizen data including criminal records.

The attackers employed multiple sophisticated tools including Cobalt Strike, PlugX, Remcos RAT, and ShadowPad to maintain persistent access and exfiltrate data from compromised infrastructure. The campaign demonstrates the ongoing threat posed by state-sponsored actors targeting government institutions in the region, with attackers leveraging infrastructure at IP address 142.171.183.8. Source: Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors are leveraging ghost accounts to conduct large-scale reconnaissance operations against GitHub organizations, systematically mapping repositories and identifying organizational members. These campaigns utilize the GitHub API to gather intelligence on target organizations while maintaining operational stealth through the use of disposable accounts.

The reconnaissance activity aligns with established adversary tactics for pre-attack planning and target identification. Source: Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms

The Australian Cyber Security Centre has issued an alert regarding a coordinated global exploitation campaign targeting vulnerable content management systems and associated plugins. The campaign exploits a substantial number of known vulnerabilities spanning multiple years, including CVE-2020-36847, CVE-2024-9234, CVE-2025-12057, CVE-2025-12352, CVE-2025-13486, CVE-2025-32432, CVE-2025-34085, CVE-2025-6389, CVE-2025-7443, CVE-2025-7852, CVE-2026-0740, CVE-2026-1357, CVE-2026-1969, CVE-2026-29014, CVE-2026-31843, CVE-2026-3395, CVE-2026-3844, and CVE-2026-48907.

The breadth of targeted vulnerabilities indicates attackers are systematically scanning for unpatched systems across the internet and exploiting them for initial access. Organizations operating CMS platforms must prioritize patching efforts to mitigate exposure to this widespread threat. Source: Australia warns of global campaign targeting vulnerable CMS platforms


Today's threat intelligence reinforces the critical importance of timely security updates, supply chain vigilance, and robust monitoring of both development infrastructure and public-facing web applications. Organizations should prioritize patching vulnerable systems and implementing additional controls around package management and API access.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Malware4
  • Remcos RAT
    Malware family linked to an India-nexus threat actor.
  • PlugX
    Malware family deployed by China-nexus threat actors.
  • ShadowPad
    Malware family deployed by China-nexus threat actors, successor to PlugX.
  • Cobalt Strike
    Malware family deployed by China-nexus threat actors.
IP Address1
  • 142.171.183.8
    Command-and-control (C2) server used by Cobalt Strike activity cluster.
Australia warns of global campaign targeting vulnerable CMS platforms
CVE18