Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware
2026-04-08T08:51:41Z•36ddc6afb6fbf98deeefedc96ad102eb147d7ca44ff89066e01ec1bba0fa3046
AI-injectionBrowserGateChrome-extensionCloudflareEmDash CMS','passkey-authentication','non-human-identities','AI‑GrafanaGrafanaGhostMoneroNode.jsQR-code-phishingUNC1069UNC4736browser-extensioncredential-theftcryptominerdata-exfiltrationmalwareopen-sourcephishingprivacyprompt-injectionsocial-engineeringspywaresupply-chain-compromisevulnerability
What happened
Multiple high-impact threats reported: a critical 'GrafanaGhost' vulnerability in Grafana AI components enables indirect prompt-injection and protocol-relative URL bypasses to exfiltrate data; crypto-mining campaigns distribute Monero miners via fake non‑profit installers and stealth tactics; nation-state actors (UNC4736) stole ~$285M via long‑running social‑engineering of a DeFi protocol and UNC1069 is targeting Node.js maintainers with fake LinkedIn/Slack profiles to compromise open‑source supply chains. Additional incidents include phishing campaigns exploiting geopolitical events to steal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 36ddc6afb6fbf98deeefedc96ad102eb147d7ca44ff89066e01ec1bba0fa3046
- Enrichment time
- 2026-04-08T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.