Weekly review

ThreatNoir Weekend Brief — August 29

2026-08-29Morning8 articles
Audio
Listen to the episode

Morning Review in IT Security — August 29, 2026

The threat landscape on August 29, 2026 reflects intensifying supply-chain attacks, critical infrastructure vulnerabilities, and coordinated campaigns targeting both open-source ecosystems and enterprise software. A major npm package compromise with sophisticated credential-harvesting capabilities, multiple zero-day exploitations in widely-deployed business software, and significant breaches at healthcare and government entities underscore the expanding attack surface facing organizations globally.

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack

Ten malicious versions of the npm package @7nohe/openapi-react-query-codegen were published on August 28, 2026, carrying sophisticated credential-harvesting and supply-chain propagation capabilities. All ten versions remain installable, with the latest tag resolving to malicious version 3.0.4. The package receives approximately 150,000 weekly downloads across all versions. Source: Socket Threat Research Team

The malicious releases execute threat actor-controlled code during installation through a bundled, obfuscated JavaScript loader that decrypts and executes a second-stage payload. This payload targets cloud credentials, package registry credentials, GitHub Actions secrets, and AI agent configuration while incorporating self-propagation functionality consistent with the Mini Shai-Hulud campaign. Notably, all ten malicious versions carry valid npm provenance attestations issued through GitHub Actions trusted publishing, demonstrating how attackers exploited a comment-triggered publishing workflow to invoke untrusted code under the repository's trusted publishing identity.

The attack chain reveals extensive capabilities including filesystem and process-memory credential scanning, validation of stolen credentials across multiple registries and cloud providers, encrypted collection exfiltration through attacker-created GitHub repositories, npm and RubyGems package poisoning, GitHub Actions workflow modification to expose repository secrets, developer-tool configuration persistence targeting AI coding assistants, and SSH-based propagation to reachable hosts. The payload also implements a signed GitHub-commit command channel and persistent GitHub token monitoring on macOS and Linux systems.

GiveWP WordPress Donation Plugin Flaw Enables Unauthenticated Server Command Execution

A maximum-severity vulnerability tracked as CVE-2026-82222 in the GiveWP plugin for WordPress allows unauthenticated attackers to execute arbitrary commands on hosting servers. Source: Bleeping Computer

The vulnerability exposes over 100,000 WordPress installations running the GiveWP donation plugin to immediate remote code execution risk. The flaw permits direct server-level command execution without requiring authentication, making it a critical priority for website administrators to patch immediately.

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Malicious actors are actively exploiting newly patched security vulnerabilities in PaperCut NG and MF to execute arbitrary code on vulnerable instances. The vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, allow unauthenticated attackers to gain remote control over PaperCut's trusted configuration and execute arbitrary Java code within the application. Source: The Hacker News

The chaining of these two flaws eliminates authentication requirements entirely, enabling direct compromise of PaperCut deployments without valid credentials. PaperCut's widespread use in enterprise print management infrastructure makes this vulnerability chain a significant threat to organizational security.

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2023-49105, a critical ownCloud vulnerability with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog following reports that a Chinese-speaking threat actor weaponized the flaw against a nuclear research body in the Philippines. Source: The Hacker News

The exploitation demonstrates nation-state targeting of critical infrastructure and sensitive nuclear research data. The vulnerability, combined with CVE-2024-28000, enabled attackers operating from IP address 31.58.209.241 to access and exfiltrate classified nuclear records. The incident underscores the persistent risk posed by unpatched critical vulnerabilities in widely-deployed collaboration platforms.

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications, with the ShinyHunters extortion group claiming theft of 284 million patient data records. Source: Bleeping Computer

The breach represents one of the largest healthcare data compromises on record, exposing sensitive patient information across McKesson's extensive customer base. The incident highlights the vulnerability of healthcare supply-chain infrastructure to both external threat actors and insider threats, with significant implications for patient privacy and regulatory compliance.

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government confirmed it is the target of an extortion attempt following the August compromise of the city's state administrative network and announced it will not meet the extortionists' demands. The Rhysida ransomware group, attributed to Storm-0832, exploited CVE-2020-1472 to compromise the network and exfiltrate 5.79 terabytes of data from the Senate Department for Mobility, Transport, Climate Protection and Environment. Source: The Hacker News

Forensic investigation identified further data outflows beyond the initial compromise, indicating prolonged attacker presence within Berlin's critical government infrastructure. The incident demonstrates the ongoing exploitation of known vulnerabilities in government networks and the targeting of municipal services by organized ransomware operations.

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

Cosmos Labs warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2 and rated Critical, was published without a CVE identifier, weakness classification, or CVSS score. Source: The Hacker News

The delayed disclosure and silent patching approach allowed attackers to exploit the vulnerability across multiple blockchain networks before public awareness, resulting in significant financial losses. The incident illustrates the risks of non-standard vulnerability disclosure practices in decentralized finance infrastructure and the importance of coordinated disclosure timelines.

Malicious Browser Extensions Target Crypto Wallets via Supply Chain Hijacking

Cybersecurity researchers discovered a cluster of 18 Google Chrome extensions and one Microsoft Edge extension published over the preceding six months that harbor wallet secret stealing and cryptocurrency draining capabilities. The extensions share similarities in code and tradecraft, with evidence indicating an active campaign targeting cryptocurrency users through browser extension supply chains. Source: The Hacker News

The campaign demonstrates attackers' continued focus on compromising browser extension ecosystems to gain access to cryptocurrency wallets and sensitive financial credentials. The six-month campaign duration indicates sustained operator activity and successful evasion of platform security controls, highlighting the need for enhanced vetting of browser extension publishers and runtime behavior monitoring.

The August 29, 2026 threat landscape reflects a coordinated escalation across multiple attack vectors, from supply-chain compromise of development tools to direct exploitation of critical infrastructure vulnerabilities. Organizations should prioritize immediate patching of disclosed vulnerabilities, credential rotation across all exposed systems, and enhanced monitoring of development and CI/CD environments for indicators of compromise.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Malware1
  • Mini Shai-Hulud
    Threat actor campaign name
URL4
  • hxxps://api[.]github[.]com/search/commits
    Endpoint for command channel
  • hxxps://registry[.]npmjs[.]org/
    npm registry endpoint
  • hxxps://upload[.]pypi[.]org/legacy/
    PyPI upload endpoint
  • hxxps://rubygems[.]org/
    RubyGems endpoint
SHA-2563
  • 59370c67b54a…
    Hash for 3FWCvzduYZg.js
  • b49afb7dba04…
    Hash for 3FWCvzduYZg.js
  • d3246926b20a…
    Hash for binding.gyp