Obfuscated JavaScript or Nothing, (Thu, Apr 9th)

2026-04-13T01:23:52Zd8db2c123fca90e89e97fb50ea9863ca35a9e046d994c3544bac3434d41ff18a
CISA-KEVCisco-source-code-theftTeamPCPTrivy-linked-breachUNC6780honeypot-fingerprintingmalicious-jsobfuscated-javascriptopen-redirectspassword-trendsphishingrar-attachmentsha256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788bsupply-chainvirus-total-low-detectionweb-shells

What happened

SANS ISC diary collection (Apr 6–10, 2026) covering multiple active threats and observations. Key items: an obfuscated JavaScript file delivered in a phishing RAR (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) with low detection on VirusTotal (~15 engines), indicating a likely targeted or novel payload; an update on the TeamPCP supply-chain campaign reporting Cisco source-code theft via a Trivy-linked breach and attribution/track as UNC6780 by Google GTIG; ancillary topics include honeypot fingerprinting techniques, attacker use of web shells (persistent

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
d8db2c123fca90e89e97fb50ea9863ca35a9e046d994c3544bac3434d41ff18a
Enrichment time
2026-04-13T01:23:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Obfuscated JavaScript or Nothing, (Thu, Apr 9th) · Baitaphish