Security researchers at SafeDep discovered that a malicious npm package called mathmain, disguised as a copy of the popular mathjs library, contains a hidden remote access implant. The malicious code stays encrypted and dormant until a specific equation is solved using the library's lusolve() solver function, which acts as a decryption key to unlock and execute the payload.
safedep.io
· 2026-09-21
LastPass and Delphos Labs identified a malware campaign that uses SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to distribute a previously unseen infostealer called Rapuncel. Victims searching for tools like LastPass Authenticator are led to fake repos where oversized ZIP files hide a renamed Microsoft debugger that sideloads the malicious payload and a Microsoft-signed kernel driver capable of killing 145 different antivirus and EDR products.
bleepingcomputer.com
· 2026-09-18
Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.
bleepingcomputer.com
· 2026-09-17
A threat actor breached the website of Admin Menu Editor Pro maintainer Janis Elsts and pushed a malicious version 2.35 update that installed a web shell and created a hidden admin account on customer sites. Even after Elsts released a clean version 2.36, the attacker retained access and compromised that release too, affecting an estimated 230 customers and at least 1,500 sites.
bleepingcomputer.com
· 2026-09-15