236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

2026-06-29T13:24:10Zac6d25bf0e8d553bf59c0e63ed04ce02ed6d0b737664d97fd3446c1796c9c33a
Amazon QCISA KEVCVE-2026-12957CVE-2026-43503CVE-2026-46331CVE-2026-55200Chrome extension vulnerabilityDCloud Uni‑AppDirtyCloneEdge extensionsGoPTC Windchill RCEStegoAdcrypto scamsinfostealerkernel privilege escalation (local)libssh2npmpackage hijackpedit COWphishingpublic PoCsteganographysupply chain compromisewallet drainers

What happened

A collection of security reports describing widespread fraud, active malware campaigns, and multiple high-severity vulnerabilities and public exploits. Infoblox found 236,000+ DCloud Uni‑App sites hosting crypto scams, phishing and wallet‑draining templates. Researchers disclosed a public PoC for a critical libssh2 client‑side flaw (CVE‑2026‑55200) allowing memory corruption and possible code execution. Multiple Linux privilege escalation bugs have public exploits (pedit COW CVE‑2026‑46331 and DirtyClone CVE‑2026‑43503). Supply‑chain attacks and hijacked npm/Go packages deploy Python infosteal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ac6d25bf0e8d553bf59c0e63ed04ce02ed6d0b737664d97fd3446c1796c9c33a
Enrichment time
2026-06-29T13:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.