- FortiBleedName of the ongoing attack campaign and credential leak
- INC/Lynx ransomwareRansomware affiliate benefiting from FortiBleed attacks
- Payload ransomwareRansomware affiliate benefiting from FortiBleed attacks
ThreatNoir Morning Brief — October 8
Morning Review in IT Security — October 8, 2026
The threat landscape continues to intensify with critical vulnerabilities affecting enterprise infrastructure, persistent supply chain attacks targeting developers, and coordinated campaigns exploiting cryptocurrency users. Today's briefing covers active exploitation of VPN appliances, malicious package distribution, critical patching requirements, and a sophisticated browser extension fraud operation.
FBI Warns of Ongoing FortiBleed Attacks Against VPN Administrators
The Federal Bureau of Investigation has issued an alert regarding continued FortiBleed attacks targeting Fortinet FortiGate firewalls and SSL VPN gateways. The campaign specifically focuses on locking out legitimate administrators from their own systems, preventing proper management and response to the intrusions. The malware families identified in these attacks include FortiBleed, INC/Lynx ransomware, and Payload ransomware, indicating a coordinated effort to compromise critical network access points. Source: FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
Supply Chain Attack Delivers RAT and Stealer Through npm Ecosystem
Researchers have disclosed a long-running malware campaign distributed through the npm package repository, with eight malicious packages downloaded over 40,000 times. The campaign, tracked as MALFEX by CloudSEK and Checkmarx, appears to be the work of a single threat actor who has published twelve packages since August 2023, delivering the Overlord RAT and stealer payloads to compromised systems. The campaign exploits CVE-2026-60137 and CVE-2026-63030 alongside the movinlike malware variant, targeting developers who unknowingly incorporate these packages into their projects. Source: Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
SonicWall Releases Critical Patches for Maximum-Severity SSRF Vulnerability
SonicWall has released hotfixes addressing four vulnerabilities in its SMA1000 appliances, which provide remote access gateways for enterprise networks. The most severe flaw carries a CVSS score of 10.0 and allows unauthenticated attackers to send requests through the appliance to reach internal functions without requiring login credentials. The vulnerability set includes CVE-2026-102255, CVE-2026-102256, CVE-2026-102257, CVE-2026-102258, CVE-2026-15409, CVE-2026-15410, CVE-2026-83548, and CVE-2026-83549. SonicWall reports no evidence of active exploitation at this time, but organizations should prioritize immediate patching given the maximum severity rating and the critical role these appliances play in network security. Source: SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
Coordinated Firefox Extension Campaign Steals Cryptocurrency Wallet Credentials
Socket Threat Research has identified a coordinated campaign comprising sixteen malicious Firefox extensions that target cryptocurrency wallet users through credential theft. The campaign operates two distinct families: four large extensions impersonating Rabby Wallet under the misspelled brand "Raabby WaIIet," and twelve smaller extensions posing as OKX Wallet. The malware intercepts recovery phrases and private keys during wallet import workflows and transmits them to attacker-controlled Cloudflare Workers endpoints, including silent-wind-get.icy-star-f45c.workers.dev, green-firefly-ab28.icy-star-f45c.workers.dev, small-boat-969c.icy-star-f45c.workers.dev, and flat-wildflower-f954.fondationanimalaidrelief.workers.dev. The Rabby clone family transmits secrets via GET requests with exposed query parameters, while OKX variants use POST requests with the raw phrase in parameter w. Mozilla unpublished all identified extensions as of October 5th, and users who entered real recovery phrases or private keys into any variant should immediately create new wallets from clean environments and transfer assets, as changing only the extension password does not invalidate compromised seed phrases or private keys. Source: 16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
The convergence of infrastructure vulnerabilities, supply chain compromises, and targeted credential theft campaigns underscores the importance of rapid patching, dependency management, and user awareness across all technology domains. Organizations and individual users should prioritize remediation of the identified vulnerabilities and removal of the malicious extensions while implementing enhanced monitoring for related attack indicators.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- WordPress vulnerability exploited in a separate campaign involving Overlord RAT.
- WordPress vulnerability exploited in a separate campaign involving Overlord RAT.
- movinlikeNode.js stealer targeting Discord, browsers, Telegram, and cryptocurrency wallets.
- Overlord RATRemote access trojan delivered by malicious npm packages.
- Previously exploited command injection vulnerability in SMA1000 appliance.
- Stored XSS vulnerability in SMA1000 Appliance Management Console (AMC).
- Previously exploited SSRF vulnerability in SMA1000 WorkPlace portal.
- Previously exploited command injection vulnerability in SMA1000 appliance.
- Previously exploited SSRF vulnerability in SMA1000 WorkPlace portal.
- Critical SSRF vulnerability in SMA1000 WorkPlace portal.
- OS command injection vulnerability in SMA1000 appliance.
- Zip Slip vulnerability in SMA1000 Appliance Management Console (AMC).
- Raabby WaIIetMalicious Firefox extension campaign cloning Rabby Wallet
silent-wind-get.icy-star-f45c.workers.devRabby-clone C2 endpoint for credential exfiltration via GET requestssmall-boat-969c.icy-star-f45c.workers.devOKX-clone C2 endpoint for credential exfiltrationgreen-firefly-ab28.icy-star-f45c.workers.devOKX-clone C2 endpoint for credential exfiltrationflat-wildflower-f954.fondationanimalaidrelief.workers.devBroken variant OKX-clone C2 endpoint
c550f0860012…OKX-clone Web3 Portal background.js varianteb134bbf7304…Shared OKX-clone frontend across all 12 OKX variants7d9d7e80ed52…Rabby-clone background.js shared across all four Rabby-clone extensionsda447fe02e45…OKX-clone core background.js variantbe246ca5cb13…Broken OKX-clone variant background.js