logo

npm supply-chain attacks escalate; Zimbra RCE, Android malware evolves

ID: 3a5956ed-3a9d-50ca-863a-dd2d4fb51dbd

STIX ID: report--3a5956ed-3a9d-50ca-863a-dd2d4fb51dbd

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-07-13

Date Updated: 2026-07-13

Author: defend.network

...
...

Three high-severity active threats demand immediate action: a compromised jscrambler npm package (v8.14.0) that executes a malicious preinstall hook to drop a cross-platform native infostealer; a critical stored XSS in Zimbra Classic Web Client that can run arbitrary code when users view crafted emails; and a RedHook Android variant abusing Wireless ADB to obtain shell-level privileges without a connected computer. The briefing also notes separate China- and India-aligned espionage campaigns against the Balochistan Police and the FBI seizure of NetNut/Popa infrastructure; recommended responses include urgent patching, auditing npm dependencies and lockfiles, secret rotation, disabling wireless debugging, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.