Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation

2026-04-24T08:52:18Za11a2d7bd376acc157a18faef4d96bcc7892bcc0d06b5a3fd9a6d39ec6a4fad2
CVE-2024-3721CVE-2026-33032Miraiai-agentsapk-malformationav-killingcredential-theftddosformbookiot-botnetmalwarenginx-uinpmoperation-poweroffoperational-technologypasskeys','nvd-enrichmentprompt-injectionproxysmartransomwaresigned-adwaresim-farmssupply-chainvulnerability-researchworm-propagationzionsiphon

What happened

A wave of active and emerging threats across software supply chains, cloud services, AI agents and critical infrastructure: malicious npm packages exhibiting worm‑like propagation and credential theft target developers; a critical nginx-ui MCP authentication bypass (CVE-2026-33032, CVSS 9.8) is being actively exploited; a Mirai‑based botnet campaign exploits TBK DVR command injection (CVE-2024-3721); ZionSiphon malware targets water OT systems for sabotage; ProxySmart powers large‑scale SIM farms; prompt‑injection payloads and unchecked AI agents are causing data exposures; supply‑side and end

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
a11a2d7bd376acc157a18faef4d96bcc7892bcc0d06b5a3fd9a6d39ec6a4fad2
Enrichment time
2026-04-24T08:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.