Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 11.5%top 4.4%

Critical SimpleHelp flaw exploited to deploy new stealer malware

0
Medium
Published: 06/30/2026 (06/30/2026, 02:01:09 UTC)
Source: Bleeping Computer

Description

An intrusion was investigated that began with exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM software. The threat actor obtained unauthorized technician access and deployed two previously undocumented malware samples: TaskWeaver and Djinn Stealer. TaskWeaver is a heavily obfuscated Node.js loader that establishes encrypted communications and delivers additional payloads. Djinn Stealer targets credentials across Windows, macOS, and Linux systems, collecting authentication data for cloud platforms, source control, package registries, AI development assistants, browsers, SSH keys, and cryptocurrency wallets. The attacker leveraged legitimate RMM capabilities to transfer files and execute commands across managed systems. Stolen AI assistant tokens provided extensive access to repositories, databases, and cloud accounts. The intrusion demonstrated how a single authentication bypass in trusted management infrastructure can enable widespread credential theft and p...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 20:52:14 UTC

Technical Analysis

CVE-2026-48558 is a critical authentication bypass vulnerability in SimpleHelp RMM software that affects servers using OpenID Connect authentication. Attackers exploit this flaw to create privileged technician accounts without authentication, gaining trusted administrative access. This access is used to deploy TaskWeaver, a malware loader that downloads and executes JavaScript modules, including Djinn Stealer. Djinn Stealer is a new cross-platform information stealer targeting Windows, macOS, and Linux, focusing on harvesting a wide range of developer and infrastructure credentials such as cloud provider tokens, AI development tool tokens, cryptowallets, SSH keys, package manager credentials, and more. The stolen data is compressed, encrypted, and exfiltrated to attacker-controlled servers. The vulnerability was disclosed in June 2026, with approximately 1,000 exposed vulnerable SimpleHelp servers identified. The malware leverages the compromised RMM platform's trusted administrative channel to execute commands and transfer files on managed systems.

Potential Impact

Successful exploitation allows attackers to bypass authentication and create privileged technician accounts on SimpleHelp servers, enabling deployment of malware loaders and information stealers. This results in theft of sensitive developer and infrastructure credentials, including AI tool tokens, cloud credentials, cryptowallets, and other authentication data. The compromise can lead to unauthorized access to repositories, cloud resources, internal APIs, and private packages, potentially causing extensive data breaches and further system compromise across Windows, macOS, and Linux environments.

Defensive Guidance

Administrators should urgently update SimpleHelp instances to the latest patched versions once available. In the meantime, invalidate any technician sessions that are not recognized. If a breach is suspected or confirmed, rotate all credentials and API keys associated with compromised systems. Monitor vendor advisories for official patches or updates. Patch status is not yet confirmed—check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/","fetched":true,"fetchedAt":"2026-06-29T14:06:26.462Z","wordCount":1023}
Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}

Indicators of Compromise

Cve

ValueDescriptionCopy
cveCVE-2026-48558

Hash

ValueDescriptionCopy
hash00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4c
hashf4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc

Domain

ValueDescriptionCopy
domaina.dev-tunnels.com

Threat ID: 6a427be327e9c79719f8b119

Added to database: 06/29/2026, 14:06:27 UTC

Last enriched: 07/30/2026, 20:52:14 UTC

Last updated: 08/13/2026, 21:13:41 UTC

Views: 185

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses