EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 23, 20263 min read

Security Briefing | June 23, 2026 - Malicious npm RAT, WhatsApp Phishing Campaign, Squidbleed Leaks Cleartext Credentials

Three malicious npm packages posing as PostCSS tools have delivered a Windows RAT to over 1,000 downloads combined. A WhatsApp-based phishing campaign is tricking users across multiple countries into installing legitimate remote access software. Meanwhile, a 29-year-old Squid proxy vulnerability called Squidbleed can leak cleartext credentials and session tokens.

By EACA Summit Content Team

Security Briefing | June 23, 2026 - Malicious npm RAT, WhatsApp Phishing Campaign, Squidbleed Leaks Cleartext Credentials

1. Malicious npm Packages Deliver Windows RAT via PostCSS Tools

Researchers identified three malicious npm packages posing as PostCSS tools that deliver a Windows remote access trojan (RAT). The packages were published by user 'aes-decode-runner-pro' and have been downloaded over 1,000 times combined.

Verified Facts

  • Three malicious npm packages identified: aes-decode-runner-pro (145 downloads), postcss-minify-selector (256 downloads), postcss-minify-selector-parser (615 downloads)
  • Packages deliver a Windows-based RAT
  • Published by npm user 'aes-decode-runner-pro' over the past month

Evidence

  • The Hacker News report
  • BleepingComputer report

Impact

Developers using npm packages should verify package integrity and monitor for suspicious updates. This supply chain attack could lead to credential theft and lateral movement.

Confidence Level: High

The Hacker News | BleepingComputer

2. WhatsApp VBScript Campaign Distributes ManageEngine RMM Tool

A smartphone displaying a blocked phishing attempt warning over a suspicious message claiming to offer a free prize, representing a WhatsApp-based phishing campaign.

An active campaign targets WhatsApp Desktop and Web users with fake business documents that execute VBScript files, leading to installation of legitimate ManageEngine RMM software. The campaign spans multiple countries including Malaysia, Brazil, India, and the UK.

Verified Facts

  • Campaign uses WhatsApp direct messages to distribute malicious VBScript files
  • Leads to installation of legitimate ManageEngine Remote Monitoring and Management (RMM) tool
  • Targets users in Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia
  • Discovered by Kaspersky

Evidence

  • The Hacker News report
  • BleepingComputer report

Impact Attackers gain remote access to victim machines via legitimate RMM software, enabling data theft, surveillance, or ransomware deployment. Defenders should monitor for unauthorized RMM installations.

Confidence Level: High

Sources The Hacker News | BleepingComputer

3. Decades-Old Squid Proxy Bug 'Squidbleed' Leaks Cleartext HTTP Requests

A heap over-read vulnerability in Squid proxy, dating back to a 1997 FTP-parsing change, can leak cleartext HTTP requests including credentials and session tokens. The flaw, named Squidbleed, affects default configurations and was disclosed by Calif.io.

Verified Facts

  • Heap over-read vulnerability in Squid web proxy
  • Can leak cleartext HTTP requests including credentials and session tokens
  • Bug originates from a 1997 FTP-parsing change
  • Affects default Squid configuration

Evidence

  • The Hacker News report
  • SecurityWeek report

Impact Organizations using Squid proxy should immediately patch or apply mitigations. Attackers with proxy access can steal sensitive data from other users' traffic.

Confidence Level: High

Sources The Hacker News | SecurityWeek

Also Noted

OpenAI has expanded its Daybreak initiative with a new model focused on vulnerability patching, signaling continued investment in AI-assisted defensive security tooling.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings