logo

Hackers exploit RCE flaws in Qinglong task scheduler for cryptomining

ID: ea46d46f-53d1-5b88-95d7-4fff036f9b98

STIX ID: report--ea46d46f-53d1-5b88-95d7-4fff036f9b98

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Bill Toulas

...
...

Snyk researchers report that two authentication-bypass flaws in the Qinglong open-source task scheduler (affecting versions ≤2.20.1: CVE-2026-3965 and CVE-2026-4047) were chained to achieve remote code execution and actively exploited beginning February 7 to install cryptominers. Attackers modified Qinglong config.sh to download miner binaries (Linux x86_64, ARM64, macOS) to /ql/data/db/.fullgc and run them in the background; infections were confirmed across various setups (including behind Nginx/SSL). The maintainer issued a partial mitigation before a correct authentication-fix PR, and Snyk notes the root cause is a mismatch between middleware auth logic and Express.js routing behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.