Malicious Ad for Homebrew Leads to MacSync Stealer, (Fri, May 1st)
2026-05-01T19:23:56Z•0a090a8a2b8f30e206833bb1fb4adb0d904edea52bf9caf2109d4c1ef7be5357
BitwardenCanisterSprawlCheckmarxHomebrewLibredtailMacSyncPyPISANDCLOCKTeamPCPUNC6780X-Vercel-Set-Bypass-Cookiehoneypotinfo-stealermacOSmalicious-adnpmreconnaissancesupply-chain
What happened
SANS ISC diary entries (late Apr–May 1, 2026) report multiple active threats: a malicious advertisement impersonating Homebrew distributing a macOS info‑stealer called MacSync; ongoing TeamPCP supply‑chain campaign activity (UNC6780 / SANDCLOCK) with recent compromises of Checkmarx KICS, Bitwarden CLI cascade, and xinference PyPI, plus an identified CanisterSprawl npm worm; reconnaissance web requests observed in honeypots (including requests with an X-Vercel-Set-Bypass-Cookie header) and a guest diary warning about Libredtail. The TeamPCP writeup references CVE-2026-33634 and ongoing supply‑s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 0a090a8a2b8f30e206833bb1fb4adb0d904edea52bf9caf2109d4c1ef7be5357
- Enrichment time
- 2026-05-01T19:23:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.