CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

2026-04-12T13:24:11Z79d842f27ad09108e7211ab59d47e55c2c78a5f161060ce2ecf1b743287a640e
APTAdobeDockerGlassWormIDE-compromiseIoTMarimoRATSDK-vulnerabilitySTX-RATWordPressactive-exploitationbackdoorbotnetbrowser-extensionscloud-misconfigurationcryptominingmalwarepackage-poisoningprivacy-surveillancesupply-chain-compromisetrojanvulnerabilitywebloczero-day

What happened

A broad set of security incidents and research headlines from The Hacker News: a CPUID website compromise briefly distributed trojanized CPU-Z/HWMonitor installers to deploy the STX RAT; multiple high-severity vulnerabilities were disclosed and actively exploited (Adobe Acrobat Reader CVE-2026-34621, Marimo RCE CVE-2026-39987 exploited within 10 hours, and Docker Engine CVE-2026-34040); supply-chain/backdoor incidents (Smart Slider 3 Pro update via compromised Nextend servers, malicious packages across npm/PyPI/Go/Rust, and a trojanized Open VSX extension used by the GlassWorm campaign); large

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
79d842f27ad09108e7211ab59d47e55c2c78a5f161060ce2ecf1b743287a640e
Enrichment time
2026-04-12T13:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.