Malicious Ad for Homebrew Leads to MacSync Stealer, (Fri, May 1st)
2026-05-02T01:23:49Z•e71075d9dec9fa00dd15f67ecad6c9aa56c06ada99a203208276e50c9d727b84
CVE-2026-33634SANDCLOCKTeamPCPUNC6780bitwardencanistersprawlcheckmarxcredential-thefthomebrewhoneypotisc-stormcastlibredtailmacosmacsyncmalwarenpmpypireconnaissancesupply-chainvercel
What happened
Collection of SANS ISC diary entries (late Apr–May 2026) covering multiple active threats: a malicious Homebrew advertisement delivering the MacSync macOS information stealer; a TeamPCP supply-chain campaign update describing a 26-day pause ending with three concurrent compromises (Checkmarx KICS, Bitwarden CLI cascade, xinference PyPI), identification of a CanisterSprawl npm worm, credential-monetization activity tied to operators designated UNC6780 and a stealer named SANDCLOCK, and mention of Cisco source code theft and the lapsed CISA KEV remediation for CVE-2026-33634. Additional notes: /
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- e71075d9dec9fa00dd15f67ecad6c9aa56c06ada99a203208276e50c9d727b84
- Enrichment time
- 2026-05-02T01:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.