Vulnerabilities

CVE-2026-48558 Exploited to Deploy Djinn Stealer Malware

June 30, 2026 00:12 · 12 min read
CVE-2026-48558 Exploited to Deploy Djinn Stealer Malware

Critical SimpleHelp Vulnerability Exploited

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. The SimpleHelp platform is primarily used by managed service providers (MSPs), IT departments, helpdesks, and system administrators for remote monitoring and management (RMM).

Earlier this month, offensive security company Horizon3.ai published details about CVE-2026-48558, saying that the flaw could be leveraged to create highly privileged technician accounts without authentication. Exploiting the vulnerability is possible on servers using the OpenID Connect (OIDC) authentication protocol.

Exploitation and Malware Deployment

According to the researchers, around 1,000 SimpleHelp servers exposed online were running a vulnerable configuration at the time of the disclosure. In an incident investigated by managed detection and response (MDR) provider Blackpoint, a threat actor exploited the critical authentication bypass vulnerability to establish an authenticated technician session on an internet-facing SimpleHelp server before deploying the TaskWeaver malware loader and the Djinn Stealer.

Both pieces of malware are new and have not been documented before. The compromised RMM platform provided the operator with a trusted administrative channel capable of transferring files and executing commands on systems managed through the server, according to Blackpoint.

TaskWeaver and Djinn Stealer Malware

TaskWeaver was downloaded in the form of an obfuscated JavaScript file named ‘jquery.js’ from a temporary Cloudflare domain. TaskWeaver is a generic malware loader that fingerprints the compromised device and communicates with the command-and-control (C2) infrastructure to receive new JavaScript modules for execution.

The loader then installs Djinn Stealer to collect in a single pass all the sensitive data it can find on a developer's machine, be it Windows, macOS, or Linux. Djinn Stealer has a particular focus on AI development tools, but targets a broad collection of developer and infrastructure credentials, including cloud provider credentials, identity services, deployment platforms, and cloud management tools.

On Linux, the malware also attempts to read the /proc//cmdline and /proc//environ virtual files that contain information about a running process, including secrets (e.g., API keys, credentials, session tokens, file paths, URLs).

Consequences and Recommendations

Blackpoint researchers warn that stealing credentials for AI development tooling, which is widely used for coding and software development, could allow attackers to inherit the AI assistant's authorized access to repositories, cloud resources, databases, and APIs.

Before exfiltrating the sensitive data to the C2 server, Djinn Stealer packs it into a TAR archive, then compresses it with GZIP, and encrypts it with an AES-256-GCM key protected by an RSA-2048 public key embedded in TaskWeaver.

Active exploitation of CVE-2026-48558 should serve as an urgent call for system administrators to prioritize updating SimpleHelp instances to the latest versions. It is also recommended to invalidate technician sessions that they don’t recognize. If breached, rotate all credentials and API keys.

Blackpoint's report provides indicators of compromise (IoCs) observed in the investigated intrusion, which include hashes for the TaskWeaver loader and Djinn Stealer, network infrastructure, host and behavioral indicators.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free