Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users
2026-05-20T20:52:18Z•5ac9dcbf5c6117557b3f21518981474221007bfda0d5096d41f6b914936cbfb6
androidantvcarrier-billing-fraudcypherlocdirty-fragexchange-zero-dayfragnesiagitub-breachgrafanagremlin-stealerlinux-kernelmini-shai-huludmobile-malwarenpmpremium-deceptionpypiransomware-enablersscarewaresupply-chaintanstackteampcpverizon-dbirvs-code-extensionvulnerability-exploitationzero-day
What happened
Multiple high-impact cyber incidents and trends reported: a large Android 'Premium Deception' campaign used ~250 fake apps to silently enroll users in paid services; supply-chain malware (Mini Shai‑Hulud) hit hundreds of npm packages across AntV and TanStack and spread to PyPI; a claimed GitHub breach via a malicious VS Code extension (attributed to TeamPCP) exposed internal repositories and led to reported source-code theft (Grafana); Microsoft disclosed a severe zero‑day impacting on‑prem Exchange Server 2016/2019/Subscription Edition; several Linux kernel vulnerabilities (including the 'Fr{
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 5ac9dcbf5c6117557b3f21518981474221007bfda0d5096d41f6b914936cbfb6
- Enrichment time
- 2026-05-20T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.