Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users

2026-05-20T20:52:18Z5ac9dcbf5c6117557b3f21518981474221007bfda0d5096d41f6b914936cbfb6
androidantvcarrier-billing-fraudcypherlocdirty-fragexchange-zero-dayfragnesiagitub-breachgrafanagremlin-stealerlinux-kernelmini-shai-huludmobile-malwarenpmpremium-deceptionpypiransomware-enablersscarewaresupply-chaintanstackteampcpverizon-dbirvs-code-extensionvulnerability-exploitationzero-day

What happened

Multiple high-impact cyber incidents and trends reported: a large Android 'Premium Deception' campaign used ~250 fake apps to silently enroll users in paid services; supply-chain malware (Mini Shai‑Hulud) hit hundreds of npm packages across AntV and TanStack and spread to PyPI; a claimed GitHub breach via a malicious VS Code extension (attributed to TeamPCP) exposed internal repositories and led to reported source-code theft (Grafana); Microsoft disclosed a severe zero‑day impacting on‑prem Exchange Server 2016/2019/Subscription Edition; several Linux kernel vulnerabilities (including the 'Fr{

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
5ac9dcbf5c6117557b3f21518981474221007bfda0d5096d41f6b914936cbfb6
Enrichment time
2026-05-20T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.