Malicious Ad for Homebrew Leads to MacSync Stealer, (Fri, May 1st)
2026-05-03T13:23:46Z•2ce8dbba434877e3f0e35ca9c0ea530a0f4d8b8de7bfc7646a7d66ff4a77e2a3
BitwardenCanisterSprawlCheckmarxHomebrewMacSyncSANDCLOCKTeamPCPUNC6780X-Vercel-Set-Bypass-Cookiecredential-stealerhoneypotlibredtailmacOSnpm-wormreconnaissancesupply-chainxinference
What happened
Collection of SANS ISC diary posts (late Apr–May 2026) describing multiple active threats and honeypot telemetry: a malicious advertisement impersonating Homebrew distributing the MacSync macOS credential stealer; reconnaissance and unusual HTTP requests observed in honeypots (including requests with X-Vercel-Set-Bypass-Cookie headers); a guest diary warning about Libredtail; and a major TeamPCP supply-chain campaign update reporting a 26-day pause ending with multiple concurrent compromises (Checkmarx KICS, Bitwarden CLI, xinference PyPI), identification of an npm worm (CanisterSprawl), and a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 2ce8dbba434877e3f0e35ca9c0ea530a0f4d8b8de7bfc7646a7d66ff4a77e2a3
- Enrichment time
- 2026-05-03T13:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.