Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware

2026-04-08T08:51:41Z36ddc6afb6fbf98deeefedc96ad102eb147d7ca44ff89066e01ec1bba0fa3046
AI-injectionBrowserGateChrome-extensionCloudflareEmDash CMS','passkey-authentication','non-human-identities','AI‑GrafanaGrafanaGhostMoneroNode.jsQR-code-phishingUNC1069UNC4736browser-extensioncredential-theftcryptominerdata-exfiltrationmalwareopen-sourcephishingprivacyprompt-injectionsocial-engineeringspywaresupply-chain-compromisevulnerability

What happened

Multiple high-impact threats reported: a critical 'GrafanaGhost' vulnerability in Grafana AI components enables indirect prompt-injection and protocol-relative URL bypasses to exfiltrate data; crypto-mining campaigns distribute Monero miners via fake non‑profit installers and stealth tactics; nation-state actors (UNC4736) stole ~$285M via long‑running social‑engineering of a DeFi protocol and UNC1069 is targeting Node.js maintainers with fake LinkedIn/Slack profiles to compromise open‑source supply chains. Additional incidents include phishing campaigns exploiting geopolitical events to steal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
36ddc6afb6fbf98deeefedc96ad102eb147d7ca44ff89066e01ec1bba0fa3046
Enrichment time
2026-04-08T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.