185.220.101.105IP address contacted by the dropped infostealer binary.185.220.101.106IP address contacted by the dropped infostealer binary.
ThreatNoir Weekend Brief — July 12
Morning Review in IT Security — July 12, 2026
The threat landscape continues to evolve rapidly across multiple attack vectors. Today's security briefing covers critical vulnerabilities in popular development tools, state-sponsored espionage targeting law enforcement infrastructure, reconnaissance activities targeting software repositories, and a coordinated global campaign exploiting content management systems.
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
A malicious version of the jscrambler npm package was published on July 11, 2026, introducing a significant supply chain risk to developers worldwide. The compromised 8.14.0 release executes a Rust-based infostealer automatically during installation through a preinstall hook mechanism. The malware drops and executes native binaries compiled for Windows, macOS, and Linux systems, ensuring broad compatibility across developer environments.
Security researchers at Socket detected the malicious release just six minutes after publication, demonstrating the critical importance of automated monitoring in the open source ecosystem. The threat actors leveraged infrastructure associated with IP addresses 185.220.101.105 and 185.220.101.106 in connection with this attack. Source: Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cybersecurity researchers have disclosed a sustained cyber espionage campaign targeting Pakistani law enforcement organizations, with activity spanning from February 2024 through April 2026. The campaign involved suspected China- and India-aligned threat actors who compromised servers hosting critical web applications at Balochistan Police, gaining access to systems managing sensitive police and citizen data including criminal records.
The attackers employed multiple sophisticated tools including Cobalt Strike, PlugX, Remcos RAT, and ShadowPad to maintain persistent access and exfiltrate data from compromised infrastructure. The campaign demonstrates the ongoing threat posed by state-sponsored actors targeting government institutions in the region, with attackers leveraging infrastructure at IP address 142.171.183.8. Source: Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Threat actors are leveraging ghost accounts to conduct large-scale reconnaissance operations against GitHub organizations, systematically mapping repositories and identifying organizational members. These campaigns utilize the GitHub API to gather intelligence on target organizations while maintaining operational stealth through the use of disposable accounts.
The reconnaissance activity aligns with established adversary tactics for pre-attack planning and target identification. Source: Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Australia Warns of Global Campaign Targeting Vulnerable CMS Platforms
The Australian Cyber Security Centre has issued an alert regarding a coordinated global exploitation campaign targeting vulnerable content management systems and associated plugins. The campaign exploits a substantial number of known vulnerabilities spanning multiple years, including CVE-2020-36847, CVE-2024-9234, CVE-2025-12057, CVE-2025-12352, CVE-2025-13486, CVE-2025-32432, CVE-2025-34085, CVE-2025-6389, CVE-2025-7443, CVE-2025-7852, CVE-2026-0740, CVE-2026-1357, CVE-2026-1969, CVE-2026-29014, CVE-2026-31843, CVE-2026-3395, CVE-2026-3844, and CVE-2026-48907.
The breadth of targeted vulnerabilities indicates attackers are systematically scanning for unpatched systems across the internet and exploiting them for initial access. Organizations operating CMS platforms must prioritize patching efforts to mitigate exposure to this widespread threat. Source: Australia warns of global campaign targeting vulnerable CMS platforms
Today's threat intelligence reinforces the critical importance of timely security updates, supply chain vigilance, and robust monitoring of both development infrastructure and public-facing web applications. Organizations should prioritize patching vulnerable systems and implementing additional controls around package management and API access.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Remcos RATMalware family linked to an India-nexus threat actor.
- PlugXMalware family deployed by China-nexus threat actors.
- ShadowPadMalware family deployed by China-nexus threat actors, successor to PlugX.
- Cobalt StrikeMalware family deployed by China-nexus threat actors.
142.171.183.8Command-and-control (C2) server used by Cobalt Strike activity cluster.
- Sneeit Framework vulnerability
- WPvivid Backup (WordPress) vulnerability
- Gravity Forms (WordPress) vulnerability
- GutenKit/Hunk Companion (WordPress) vulnerability
- Simple File List (WordPress) vulnerability
- MaxSite CMS vulnerability
- MetInfo CMS vulnerability
- Joomla JCE vulnerability
- Craft CMS vulnerability
- Simple File List (WordPress) vulnerability
- WavePlayer (WordPress) vulnerability
- BerqWP (WordPress) vulnerability
- WPBookit (WordPress) vulnerability
- Ninja Forms (WordPress) vulnerability
- ThemeREX Addons (WordPress) vulnerability
- Breeze Cache (WordPress) vulnerability
- pay-uz (WordPress) vulnerability
- ACF Extended (WordPress) vulnerability