logo

ModHeader, CrashStealer, Joomla RCE active exploits; npm supply-chain risk

ID: e91f1764-2d45-5c79-9aa8-2a801ba556de

STIX ID: report--e91f1764-2d45-5c79-9aa8-2a801ba556de

Feed Name: defend.network

Threat Score
80/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: defend.network

...
...

This briefing describes multiple high-risk incidents: ModHeader was removed from browser stores after a dormant browsing-history collector affecting ~1.6M users was discovered; CrashStealer, a notarized macOS infostealer, is impersonating Apple crash reporting to steal credentials and wallets; CISA warns of active RCE exploitation in Joomla iCagenda and Balbooa Forms via arbitrary uploads; the Jscrambler npm package was backdoored in a supply-chain compromise; and Lidl disclosed a service-provider breach affecting customers in Germany, Belgium, and the Netherlands. Recommended actions include patching, third-party audits, dependency checks, removing suspicious extensions, rotating credentials, and monitoring logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.