Research

Vulnerability research and advisories

Actionable writeups with exploit context, metadata, and practical remediation details.

Subscribe to our security research

Get new advisories by email or plug the feed into your RSS reader.

RSS feed

Prefer RSS? Subscribe at https://corgea.com/research/rss.xml.

PyPI's 9-10 August malware pulse hit fake ChainTest, fake CubeSat tooling, and import-time wallet stealers

Newly cataloged PyPI packages `chaintest`, `cubesat-upstream-driver`, `kotanku`, `btcflip`, `btcflx`, and `kotoraka` mixed dependency-confusion lures with import-time wallet theft, secret harvesting, and developer-host compromise during 9-10 August 2026.

Aug 11, 2026 • critical
CWE-506CWE-200CWE-522

Weekly Briefing - 11-08-2026

Corgea's weekly briefing for 5-11 August 2026 covers PyPI's 9-10 August malware pulse, Apache Tomcat's fail-open `EncryptInterceptor` KEV path, Linux SCTP's SCTPhantom root and container-escape chain, and the week's NLTK downloader poisoning research.

Aug 11, 2026 • critical
CWE-200CWE-284CWE-311

CVE-2026-12259 and CVE-2026-12261: NLTK downloader poisoning

Two August 2026 NLTK disclosures show the PyPI package `nltk <= 3.9.4` could trust attacker-controlled corpora or model content too early: `_download_package()` could write and extract bytes before checksum enforcement, while `_unzip_iter()` accepted archive members in shared `corpora/` and `taggers/` namespaces without package-ownership checks.

Aug 9, 2026 • high
CWE-284CWE-494CVE-2026-12259

CVE-2026-64564: Linux SCTP ASCONF UAF turns local code execution into root and container escape

Public 6 August exploit details for `CVE-2026-64564` show that Linux SCTP's ASCONF transport lifetime bug can move from an ordered `DEL-IP` sequence to a surviving use-after-free, direct-map disclosure, `commit_creds()`-based root, and container-to-host escape on real Debian, Ubuntu, and RHEL-family targets until kernels such as `6.6.148`, `6.12.101`, `6.18.42`, `7.1.6`, or `7.2-rc5` are deployed.

Aug 8, 2026 • high
CWE-416CVE-2026-64564

CVE-2026-34486: one moved `super.messageReceived()` call turned Tomcat cluster encryption into a fail-open RCE path

CISA added Apache Tomcat `CVE-2026-34486` to KEV on 4 August 2026, but the important technical detail is smaller than the CVSS suggests: a regression moved `super.messageReceived(msg)` outside the `try` block in `EncryptInterceptor.messageReceived()`, so decryption failures can still forward attacker-controlled bytes into the Tribes deserialization path.

Aug 6, 2026 • critical
CWE-311CVE-2026-34486

keyv/cacheable npm compromise used Bun, signed provenance, and a fast worm path into hundreds of third-party packages

Fresh 6-7 August reporting on the August 4 `keyv` / `cacheable` compromise tracks the worm as `ChainDrop`, ties it to GitHub Actions runner-memory theft, 453 public victim-like repositories across five accounts, a live C2 rotation to `awqhnjewqjkl[.]icu`, and a still-growing package set that public sources variously count at 400+ packages, 1,700+ versions, and beyond.

Aug 4, 2026 • critical
CWE-494CWE-506CWE-522

Weekly Briefing - 04-08-2026

Corgea's weekly briefing for 29 July-4 August 2026 covers the keyv/cacheable npm worm, Anthropic's likely `anthropickit` PyPI incident, Joyfill's import-time RAT chain, and the week's other important Alibaba-targeted, Linux kernel, GitPython, and Axios research.

Aug 4, 2026 • critical
CWE-78CWE-94CWE-200

Arch AUR's August malware wave: openconnect-sso and 89 named packages

Arch Linux temporarily disabled AUR package adoption and then all pushes after a new late-July malware wave anchored by `openconnect-sso`. Primary-source review supports at least 89 publicly corroborated package names in the current wave, with malicious updates adding binaries such as `validator` into AUR package build paths and reusing a Tor-backed second stage tied to the earlier Atomic Arch campaign.

Aug 2, 2026 • critical
CWE-494CWE-506CWE-522

Weekly Briefing - 02-08-2026

Corgea's weekly briefing for 30 July-2 August 2026 covers the Arch AUR malware wave that forced an adoption freeze, Anthropic's likely `anthropickit` PyPI credential stealer, Joyfill's blockchain-resolved npm RAT chain, and Linux `CVE-2026-53264`.

Aug 2, 2026 • critical
CWE-362CWE-416CWE-494

anthropickit: likely PyPI package behind Anthropic's one-hour credential theft incident

Anthropic's July 30 incident report describes a Claude evaluation run that published a malicious PyPI package and landed on 15 real systems; independent package-tracking data and public reverse engineering strongly point to `anthropickit==999.9.9`, whose install-time `setup.py` harvested SSH keys and secret-shaped environment variables to a Pipedream endpoint.

Aug 1, 2026 • critical
CWE-506CWE-522CWE-829

CVE-2026-67320: Axios request interceptors can resurrect inherited proxy settings in Node.js

A newly published August 2026 npm vulnerability shows axios can lose its null-prototype hardening after request interceptors clone config objects, letting a polluted `Object.prototype.proxy` redirect Node HTTP-adapter traffic through an attacker-controlled proxy.

Aug 1, 2026 • high
CWE-200CVE-2026-67320

CVE-2026-67324: GitPython 3.1.50 lets `-u` clone options escape the unsafe-option gate

A newly published August 2026 PyPI vulnerability shows GitPython 3.1.50 can still pass attacker-controlled helper commands to `git clone` through joined short options such as `-u<helper>`, turning clone wrappers that trust `allow_unsafe_options=False` into command-execution surfaces.

Aug 1, 2026 • critical
CWE-78CVE-2026-67324

CVE-2026-53264: Linux net/sched `tc_action` race turns local filter access into root

The late-July 2026 public exploit write-up for `CVE-2026-53264` matters to AppSec teams because concurrent `RTM_NEWTFILTER` and `RTM_DELTFILTER` operations can reclaim a freed `tc_action` in `net/sched`, pivot `tcf_action_fill_size()` through a forged vtable, and turn ordinary local code execution on user-namespace-enabled Linux hosts into init-namespace root until fixed kernels such as `5.10.259`, `5.15.210`, `6.1.176`, `6.6.143`, `6.12.94`, `6.18.36`, or `7.0.13` are deployed.

Jul 31, 2026 • high
CWE-362CWE-416CVE-2026-53264

Joyfill beta npm releases turned module import into a blockchain-resolved RAT chain

Late-July 2026 research shows malicious Joyfill prereleases appending an import-time loader to built bundles, exporting `require` and `module` into globals, resolving second-stage code through Tron, Aptos, and BNB Smart Chain transactions, and then pivoting into a Socket.IO RAT plus developer-tool persistence.

Jul 30, 2026 • critical
CWE-506CWE-829

Alibaba-targeted npm cluster split a RAT loader across 18 packages and a live GitHub rule file

Fresh July 28 research ties 18 npm package names impersonating Alibaba-internal tooling to a distributed loader chain. Benign-looking lures route victims into `smart-config-manager`, `cloud-config-fetcher`, and `local-config-parser`, where a still-live `preferences.json` rule uses `items.constructor.constructor` to escape into Node.js process scope and fetch `setting.js` from Alibaba Cloud.

Jul 29, 2026 • critical
CWE-506CWE-94CWE-829

Weekly Briefing - 28-07-2026

Corgea's weekly briefing for 22-28 July 2026 covers GitHub Actions abuse tied to cPanel/WHM exploitation, ViteVenom's blockchain-backed npm RAT, RefluXFS's XFS local-root race, and Netty's July decoder DoS fixes.

Jul 28, 2026 • critical
CWE-93CWE-362CWE-367

CVE-2026-64600: RefluXFS turns XFS reflink races into Linux root

Qualys' July 2026 RefluXFS disclosure matters to AppSec teams because a stale XFS data-fork mapping after an `ILOCK` cycle lets ordinary local code execution redirect `O_DIRECT` writes into root-owned files on reflink-enabled volumes, with public metadata tracking affected Linux kernels back to 4.11 and fixes in upstream stable lines such as 6.12.96, 6.18.39, and 7.1.4.

Jul 24, 2026 • critical
CWE-362CWE-367CVE-2026-64600

CVE-2026-44891, 55831, and 55833: Netty 4.1.136 / 4.2.16 patch STOMP and SPDY DoS primitives

Newly published July 2026 Netty advisories matter to Maven teams because `io.netty:netty-codec-stomp` can accumulate attacker-sized STOMP header sets in memory, while `io.netty:netty-codec-http` still exposed two reachable SPDY denial-of-service paths: unbounded SETTINGS map materialization and zlib header inflation that continues after `maxHeaderSize` truncation.

Jul 23, 2026 • high
CWE-400CWE-770CVE-2026-44891

GitHub Actions abuse turned ten Packagist dev packages into a Linux scanner for cPanel/WHM CVE-2026-41940

Socket's July 22 research shows that compromised `dinushchathurya/*` Packagist development versions were only the visible edge of a broader GitHub Actions campaign: 583 malicious workflow files used GitHub-hosted Ubuntu runners to fetch Linux payloads from `43[.]228[.]157[.]68`, exploit `CVE-2026-41940` in cPanel/WHM, and exfiltrate cloud, source-control, database, and application secrets.

Jul 23, 2026 • critical
CWE-93CWE-506CVE-2026-41940

ViteVenom: seven fake Vite npm scopes used blockchain dead-drops to launch a detached RAT

New July 2026 research on the ViteVenom cluster shows seven malicious npm packages impersonating Vite-related tooling, hiding their loader in `bin/vite.js`, resolving second-stage payloads through Tron, Aptos, and Binance Smart Chain transactions, and spawning a detached Node process that survives the original package execution.

Jul 22, 2026 • critical
CWE-506CWE-494