Veracode Daily Threat Intel Brief. - June 18 2026

Written by Andrea Mazzarini, Senior Principal CSM at Veracode

Subscribe to these daily briefings on LinkedIn

 

Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!

 

Executive Summary

Top threats as of 2026-06-18:

  • Mastra npm supply chain attack (easy-day-js typosquat): Attacker hijacked dormant contributor account, republished 140+ @mastra packages (incl. @mastra/core, ~900k weekly downloads). Injected multi-stage RAT stealing crypto wallets, LLM keys, credentials; cross-platform persistence.
    • Atomic Risk: 9/10 — direct OSS compromise, high blast radius in AI/dev tooling. Strong Veracode SCA/Package Firewall applicability.
  • CVE-2026-50656 (RoguePlanet) Microsoft Defender EoP zero-day: Public PoC for race condition enabling SYSTEM-level shell on patched Win10/11.
    • Atomic Risk: 8/10 — endpoint escalation vector, likely weaponization soon. Veracode applicability limited (endpoint focus).
  • CVE-2026-48907 (Joomla JCE): CISA KEV addition (improper access control, CVSS 10.0, active exploitation, public exploit).
    • Atomic Risk: 9/10 — automated attacks, arbitrary code exec.
  • Ongoing Miasma/Mini Shai-Hulud/Hades supply chain worm evolution: Persistent npm/PyPI/GitHub poisoning. High propagation risk.
    • Atomic Risk: 9/10.
  • Ransomware: DragonForce (Teams relay C2), LockBit5 activity; no major new campaigns in last 24h.

Prioritized by CVSS/exploitation/supply-chain impact. Supply chain worms dominate due to downstream reach.

 

Comprehensive Threats Table

threatintelbriefjune18 

 

Detailed First-Principles Analysis (Top Items)

  • Mastra Attack: Root cause = account takeover (dormant creds) + automated mass-publish of malicious dep (typosquat easy-day-js mimicking dayjs). Mechanism: postinstall dropper → disable TLS, RAT for credential/wallet theft + persistence. Blast radius: AI/dev supply chain, millions of downloads, worm-like spread via transitive deps. Veracode control: SCA + Package Firewall blocks malicious OSS at intake/CI.
  • RoguePlanet: TOCTOU race in Defender link resolution/quarantine. Mechanism: redirect file ops to attacker-controlled paths for SYSTEM shell. Why now: Public PoC post-Patch Tuesday; history of this researcher's chained exploits. Endpoint propagation risk high in unmonitored environments.
  • Supply Chain Worms (Miasma lineage): Evolution from leaked toolkit using GitHub commit C2 (no traditional infra). Phantom Gyp (binding.gyp) bypasses install-script guards. First-principles: Trust in registries/maintainers is broken; assume compromise.

 

Broader Signals

X volume moderate on RoguePlanet/Mastra; supply chain worms remain high-signal. APT notes: Possible North Korean links (crypto focus in Mastra). No major new ransomware campaigns in strict 24h window, but DragonForce active.

 

Veracode Tool Reference with Links

 

Veracode Recommendations

  • Malicious Packages & Supply Chain Worms: Mastra + Miasma. SCA + Package Firewall fits — blocks at source/CI. Action: Enable Package Firewall policies for npm/PyPI; scan all deps.
  • New/KEV CVEs: Joomla/Cisco. Risk Manager + EASM/DAST. Action: Prioritize KEV in Risk Manager; run EASM on exposed assets.
  • Web/Runtime: Joomla/DAST targets. Action: Targeted DAST on web apps/APIs. No strong custom code/containers today — focus governance via Policy Management for enforcement.

 

Prioritized Action Plan (SMART)

 

Today

  • Run full SCA scan + enable Package Firewall for npm ecosystems; triage Mastra-affected repos (wipe/reinstall/rotate).
  • Update Joomla/Cisco per KEV deadlines (June 19+); verify in Risk Manager.
  • Monitor for RoguePlanet patch; enhance endpoint controls.
  • Enforce Policy Management rules for OSS intake and CI/CD.

Daily: Review Risk Manager unified view; audit developer machines for Miasma IOCs.

 

This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.


Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.