Tag: TaskWeaver

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
News

Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

Two previously undisclosed malware families, TaskWeaver and Djinn Stealer, have been delivered by an unidentified threat actor using a recently revealed maximum-severity security vulnerability in SimpleHelp. An unauthenticated attacker could use CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability affecting the OpenID Connect (OIDC) flow, to obtain a fully authenticated "Technician session by submitting a forged token containing arbitrary identity claims." According to an investigation by Blackpoint Cyber, TaskWeaver is a heavily disguised Node.js loader that uses an encrypted, reusable payload delivery channel instead of a predefined set of post-exploitation commands. It is sent as jquery.js and executed using node.exe. Djinn Stealer is a detected secon...