Find notable cyber news and cases, enriched with sources, timelines, and signals.

TaskWeaver and Djinn Stealer delivered through exploited SimpleHelp servers

Malware Activity
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

A SimpleHelp exploitation chain is now delivering TaskWeaver and Djinn Stealer, creating a direct path from server-side access to credential theft on managed endpoints. The loader runs as jquery.js through node.exe and acts as an encrypted staging channel rather than a fixed command set. The second stage targets Windows, macOS, and Linux, and it is built to steal cloud, source-control, AI, SSH, browser, and wallet data. Harvested material is packed, encrypted, and exfiltrated to attacker-controlled infrastructure.

Related Happenings

SimpleHelp remote management software privileged technician account creation security flaw (CVE-2026-48558)

Vulnerability
H score46 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

How related: In the attack chain documented by Blackpoint Cyber, successful exploitation of the flaw in the Remote Monitoring and Management (RMM) software is said to have enabled the threat actor to obtain an authenticated "Technician" session on a publicly-accessible server, which was then abused to deploy TaskWeaver and Djinn Stealer.

About this happening: CVE-2026-48558 is a critical authentication bypass in SimpleHelp RMM that affects OIDC authentication and can let an unauthenticated attacker forge a token and obt...

Timeline

  1. 30.06.2026 14:18 2 articles · 15d ago

    Unknown threat actor exploits SimpleHelp CVE-2026-48558 to deploy TaskWeaver and Djinn Stealer

    Initial Disclosure

    An unknown threat actor is observed abusing CVE-2026-48558 in SimpleHelp to bypass OIDC authentication, obtain a Technician session on a publicly accessible RMM server, and deploy TaskWeaver and Djinn Stealer. TaskWeaver is delivered as jquery.js and executed through node.exe as a heavily obfuscated Node.js loader, while Djinn Stealer targets Windows, macOS, and Linux to harvest cloud, source-control, AI, SSH, browser, and wallet credentials before the data is packed, encrypted, and exfiltrated to attacker-controlled infrastructure. CISA adds CVE-2026-48558 to the Known Exploited Vulnerabilities catalog and requires Federal Civilian Executive Branch agencies to apply the fixes by July 2, 2026.

    Show sources