SECURITY Affairs’ Malware Newsletter Round 116, published on 27 September 2026, is a curated list of malware-related research and threat reports rather than a single incident. It links to investigations covering malware-as-a-service campaigns using GitHub for distribution, PAYLOAD ransomware abusing Active Directory Group Policy Objects, a Node.js remote access trojan tracked through blockchain infrastructure, and North Korean activity targeting IT professionals.
Other entries examine malicious npm packages, including campaigns affecting developers integrating Twilio and the “btree” package campaign reportedly involving millions of downloads.
The collection also highlights research into an autonomous AI command-and-control implant, fake websites delivering Chrome and Windows zero-day exploits, an Android banking trojan that steals victims’ PINs through overlays, and malware campaigns affecting Terraform providers and Go modules.
Additional reports cover Android spyware targeting logistics companies, ClickFix attacks, MacSync delivery methods, an AI-agent botnet called CARBONATO, a fake CAPTCHA installer targeting Ukraine, and GitHub Actions exposing repositories to “Mini Shai-Hulud”. The newsletter also includes academic studies on metamorphic malware detection, Android malware classification and attribution, and infostealer victims.
The page provides links to the underlying research but does not itself give further technical details, affected versions, confirmed exploitation evidence or specific remediation steps.