# Threat Intel Brief — June 2, 2026

TL;DR

  • Critical supply chain attacks compromised Red Hat npm packages with Miasma credential-stealing malware, affecting developer environments and CI/CD pipelines globally.
  • Active exploitation of a critical Windows Netlogon RCE vulnerability threatens domain controllers; Belgium's cybersecurity center confirms in-the-wild attacks.
  • WordPress plugin WP Maps Pro under mass exploitation allowing unauthenticated attackers to create rogue administrator accounts on vulnerable sites.
  • China-aligned espionage campaign Operation Dragon Weave targets Czech Republic and Taiwan government, research, and technology sectors via spear-phishing.
  • Meta AI support bot exploited to hijack high-profile U.S. government Instagram accounts, defaced with pro-Iranian messaging; exploit instructions circulating on Telegram.

Critical Threats

Miasma Supply Chain Attack Compromises Red Hat npm Ecosystem

What happened: Threat actors compromised over 30 npm packages in the @redhat-cloud-services namespace, distributing a new variant of the Shai-Hulud credential stealer called Miasma. The malware executes automatically during package installation, harvesting developer credentials, environment variables, SSH keys, cloud provider tokens, and secrets from infected workstations and CI/CD pipelines. The attack includes self-propagating worm capabilities and encrypted exfiltration mechanisms.

Impact: Organizations using affected Red Hat Cloud Services packages face immediate credential compromise across development infrastructure. Stolen credentials grant attackers access to source code repositories, production cloud environments, and internal networks. The self-propagating nature amplifies the blast radius beyond initial infection points. CI/CD pipeline compromise enables potential injection of malicious code into production deployments.

Recommendations:

  • Immediate (0-24h): Audit all projects for @redhat-cloud-services dependencies using npm ls and remove compromised packages. Rotate all credentials, API keys, and secrets on developer machines and build servers that installed affected packages.
  • 24-72h: Review npm audit logs and package-lock.json files to identify installation timeframes and exposure scope. Scan developer workstations and CI/CD systems with updated EDR signatures for Miasma/Shai-Hulud indicators.
  • This week: Implement package integrity verification using npm signatures and lock files. Restrict npm registry access to approved packages only and require security review for new dependencies.

Windows Netlogon RCE Under Active Exploitation

What happened: Belgium's Centre for Cybersecurity warns that a recently patched critical Windows Netlogon remote code execution vulnerability is now being actively exploited in attacks. The flaw affects domain controllers and systems running the Netlogon service across all Windows versions prior to the latest security updates.

Impact: Successful exploitation enables remote code execution on domain controllers, potentially leading to full Active Directory domain compromise, lateral movement across enterprise networks, and establishment of persistent access. Organizations with unpatched Windows servers face immediate breach risk. The vulnerability's criticality and active exploitation status demand urgent response.

Recommendations:

  • Immediate (0-24h): Apply the latest Microsoft security updates to all Windows domain controllers and systems running Netlogon service. Verify patch deployment using WSUS, SCCM, or equivalent management tools.
  • 24-72h: Monitor Windows Event Logs (Security and System) for unusual Netlogon activity, failed authentication attempts, and unexpected service behavior on domain controllers. Review network traffic to/from domain controllers for anomalous connections on ports 445/TCP and 135/TCP.
  • This week: Implement network segmentation to restrict direct access to domain controllers from untrusted networks and workstations.

WP Maps Pro Plugin Exploited for WordPress Takeover

What happened: Attackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin, allowing unauthenticated creation of rogue administrator accounts on affected sites. The plugin has over 15,000 installations via Envato Market. No CVE has been assigned yet, and patch availability remains unclear.

Impact: Complete site compromise via unauthorized admin account creation. Attackers gain full administrative control, enabling malware injection, data theft, defacement, SEO spam, or use of compromised sites as attack infrastructure. The lack of CVE assignment complicates threat intelligence correlation and patch tracking.

Recommendations:

  • Immediate (0-24h): Audit all WordPress sites for WP Maps Pro installation and check for unauthorized administrator accounts in the wp_users database table. Disable or remove the plugin until a verified patch is available.
  • 24-72h: Review WordPress access logs and authentication events for suspicious admin account creation activity. If unauthorized accounts are found, perform full incident response including site isolation and webshell detection in wp-content/uploads and theme directories.
  • This week: Monitor Envato Market and WP Maps Pro vendor channels for security updates and apply immediately when available.

Threat Actor Activity

DriveSurge Mass Malware Distribution Campaign

The threat actor DriveSurge is conducting large-scale malware distribution using ClickFix and FakeUpdate techniques across thousands of compromised websites. The campaign employs social engineering to trick victims into executing malicious code disguised as legitimate system updates or required actions. The scale of website compromises—thousands of sites—suggests either a mature operation with significant resources or collaboration with access brokers specializing in website compromise.

Defensive focus: Deploy web application firewalls and conduct vulnerability assessments of public-facing web infrastructure. Implement user awareness training on recognizing fake update prompts. Enable endpoint detection for scripts downloaded from browsers, particularly PowerShell, JavaScript, or HTA files originating from web sources.

Operation Dragon Weave: China-Aligned Espionage

China-aligned threat actors are conducting Operation Dragon Weave, a cyber espionage campaign targeting officials and citizens in the Czech Republic and Taiwan. The campaign delivers the AdaptixC2 agent through spear-phishing emails with malicious ZIP attachments, targeting government, research, academic, technology, and financial services sectors. The geographic focus aligns with established Chinese intelligence priorities regarding cross-strait relations, European Union policy positions, and technology transfer.

Defensive focus: Implement robust email security controls to detect and quarantine spear-phishing attempts with ZIP attachments. Deploy endpoint detection rules to identify suspicious execution chains from archive files. Establish network monitoring for AdaptixC2 C2 traffic patterns and anomalous outbound connections from workstations in targeted sectors.

Geopolitical Context

European Cybersecurity Enforcement and Infrastructure Defense

Spain arrested an individual for doxing government cybersecurity personnel, including members of the National Cybersecurity Institute (INCIBE), highlighting operational security risks to cyber defense staff. The incident reflects broader European concerns about protecting the identities of individuals in sensitive cyber roles amid heightened geopolitical tensions.

Dutch authorities dismantled a massive botnet controlling at least 17 million infected devices globally, seizing over 200 command-and-control servers in the Netherlands. The operation represents one of the largest law enforcement actions against botnet infrastructure in recent years and demonstrates Western law enforcement capability to disrupt large-scale malicious infrastructure within friendly jurisdictions.

U.S.-Iran Cyber Tensions Escalate via Social Media

Attackers exploited Meta's AI support bot to hijack high-profile U.S. government-linked Instagram accounts, including those of the Obama White House and U.S. Space Force Chief Master Sergeant, defacing them with pro-Iranian content. Exploit instructions were circulated on Telegram, suggesting intent to democratize access to the technique. The incident represents a convergence of technical exploitation and information operations consistent with Iranian influence campaigns.

Recommended Actions

Immediate (0-24 hours)

1. Patch Windows Netlogon vulnerability on all domain controllers and Netlogon-enabled systems.
2. Audit npm dependencies for @redhat-cloud-services packages and rotate all developer credentials on affected systems.
3. Disable WP Maps Pro plugin on all WordPress installations and audit for unauthorized administrator accounts.
4. Review Instagram account security for government and high-profile organizational accounts; enable authenticator-based 2FA.

24-72 hours

1. Scan developer workstations and CI/CD pipelines for Miasma/Shai-Hulud malware indicators.
2. Monitor domain controller logs for unusual Netlogon activity and authentication anomalies.
3. Review WordPress access logs for suspicious admin account creation patterns.
4. Assess exposure to hard-coded credential vulnerabilities CVE-2026-25600 (Trac PDBM) and CVE-2026-42251 (KS-SOMED) if these products are deployed in your environment.

This week

1. Implement package integrity verification for npm dependencies and restrict registry access to approved sources.
2. Deploy network segmentation to restrict domain controller access from untrusted networks.
3. Conduct vulnerability assessments of public-facing web infrastructure to prevent compromise for malware distribution.
4. Review IoT and endpoint security following Dutch botnet takedown; scan for unusual persistence mechanisms on consumer devices.

Watch List

  • WordPress ecosystem: Monitor for additional plugin vulnerabilities under active exploitation; nearly 2,000 WordPress sites infected with malware using Steam Community profiles for C2 communications.
  • Microsoft service disruptions: Recent outages affecting Teams, Office for the web, and MFA setup services indicate potential stability or security concerns requiring monitoring.
  • Dashlane password manager: Users experiencing account lockouts following brute-force attacks; monitor for credential stuffing campaigns targeting password management platforms.
  • Malicious npm packages: codexui-android package (29,000 weekly downloads) stole OpenAI authentication tokens; continue vigilance for typosquatting and malicious packages in JavaScript ecosystem.

Sources

  • BleepingComputer: Multiple reports on supply chain attacks, WordPress vulnerabilities, Windows Netlogon exploitation
  • The Hacker News: Miasma campaign analysis, Operation Dragon Weave, WP Maps Pro exploitation, Dutch botnet takedown
  • Krebs on Security: Meta AI bot exploitation and Instagram account hijacking
  • CERT.PL: CVE-2026-42251 disclosure (KS-SOMED hard-coded credentials)
  • SI-CERT: CVE-2026-25600 disclosure (Trac PDBM credential exposure)

---

*This brief synthesizes open-source intelligence from trusted cybersecurity vendors and national CERTs. Organizations should correlate these findings with internal telemetry and threat intelligence feeds for comprehensive risk assessment.*