securityaffairs.com 11 Oct 2026, 15:23 UTC

Malware roundup spotlights Linux backdoor, npm threats and AhsayCBS attacks

Malware roundup spotlights Linux backdoor, npm threats and AhsayCBS attacks

SECURITY Affairs’ Malware Newsletter Round 118, published on 11 October 2026, is a collection of links to malware research and reporting rather than a single incident report. It highlights work on ClingSTUN, a Linux backdoor that abuses public STUN infrastructure; a campaign using ClickFix on compromised websites to distribute LUNEXSTEALER; and MALFEX, a malicious npm post-install script that reportedly went without an advisory for fourteen months.

Other entries cover a compromised TensorLake npm SDK linked to credential theft, the Wazza phishing kit targeting organisations in banking, government and manufacturing, and attacks exploiting critical AhsayCBS flaws to install webshells and the XMRig cryptominer.

The roundup also links research on the PoeLLM malware, a P7 DarkSword variant, a fake-Git repository network, and “Midnight Mimosa”, described by its researchers as malware present on a phone before the user switched it on. It includes academic work on malware detection, analysis and deception using large language models and deep learning.

The newsletter itself provides no technical details, evidence, affected versions, exploitation figures or remediation instructions for these items; readers must consult the linked research for those specifics.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline