Threats Tagged 'mal-2026-14039'
View all threats tagged with 'mal-2026-14039'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-14039'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @cdnshell/loader (npm) 0 The @cdnshell/loader npm package masquerades as a CDN static-asset distribution library but contains 19 pre-compiled Mach-O binaries targeting iOS versions 13 to 19. These binaries reference private iOS entitlements and WebKit GPU-process IPC symbols consistent with a WebKit renderer-to-kernel exploit chain. The package includes an obfuscated JavaScript loader that dynamically fetches and executes remote code, selecting payload variants based on the visitor's user agent. The malicious behavior activates only when the loader is embedded in a webpage served to iOS/macOS users, enabling targeted exploitation. There are no npm lifecycle hooks or main entry points, so the package does not execute on installation or require, making detection harder. This combination of obfuscation, multi-version exploit payloads, and dynamic remote code execution is inconsistent with legitimate static asset distribution libraries. Join the discussion | GCVE Database | 08/14/2026, 15:18:55 UTC Added: 08/14/2026, 16:35:59 UTC |
Showing 1 to 1 of 1 result