CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
2026-04-12T19:24:12Z•b763880ed674dd4c4683324f8a72fd8f37672a533ec82b6dc3d417cea0a4bd16
Adobe Acrobat/ReaderCVE-2026-34040CVE-2026-34621CVE-2026-39987Docker EngineEngageLab SDKGlassWormGoIDE compromiseMarimoPyPIRust packages spreader (Contagious Interview)STX RATSmart Slider 3 ProWordPress plugin compromiseactive-exploitationbackdoordeveloper-targetingmalicious-packagesnpmremote-access-trojansupply-chaintrojanvulnerability-disclosurezero-day
What happened
A wave of high-impact incidents and active exploitations was reported: CPUID's website was briefly compromised to serve trojanized CPU‑Z/HWMonitor installers that deploy the STX RAT; Adobe released emergency patches for an actively exploited Acrobat Reader flaw (CVE-2026-34621); Marimo’s pre-auth RCE (CVE-2026-39987) was exploited within hours of disclosure; Docker Engine authorization-bypass (CVE-2026-34040) was disclosed; and an EngageLab Android SDK flaw potentially exposed ~50M users including crypto-wallet installs. Multiple supply‑chain and developer-targeting campaigns were highlighted—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b763880ed674dd4c4683324f8a72fd8f37672a533ec82b6dc3d417cea0a4bd16
- Enrichment time
- 2026-04-12T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.