Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation
2026-04-24T08:52:18Z•a11a2d7bd376acc157a18faef4d96bcc7892bcc0d06b5a3fd9a6d39ec6a4fad2
CVE-2024-3721CVE-2026-33032Miraiai-agentsapk-malformationav-killingcredential-theftddosformbookiot-botnetmalwarenginx-uinpmoperation-poweroffoperational-technologypasskeys','nvd-enrichmentprompt-injectionproxysmartransomwaresigned-adwaresim-farmssupply-chainvulnerability-researchworm-propagationzionsiphon
What happened
A wave of active and emerging threats across software supply chains, cloud services, AI agents and critical infrastructure: malicious npm packages exhibiting worm‑like propagation and credential theft target developers; a critical nginx-ui MCP authentication bypass (CVE-2026-33032, CVSS 9.8) is being actively exploited; a Mirai‑based botnet campaign exploits TBK DVR command injection (CVE-2024-3721); ZionSiphon malware targets water OT systems for sabotage; ProxySmart powers large‑scale SIM farms; prompt‑injection payloads and unchecked AI agents are causing data exposures; supply‑side and end
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- a11a2d7bd376acc157a18faef4d96bcc7892bcc0d06b5a3fd9a6d39ec6a4fad2
- Enrichment time
- 2026-04-24T08:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.