Djinn Stealer is a previously undocumented cross-platform information stealer used in attacks that exploit CVE-2026-48558 in SimpleHelp remote monitoring and management software. In observed intrusions, attackers abused the authentication bypass to obtain technician-level access to exposed SimpleHelp servers and then used the trusted RMM channel to deploy a Node.js loader, TaskWeaver, which delivered Djinn Stealer to managed endpoints. The malware has been observed targeting Windows, macOS, and Linux systems, with particular risk to managed service providers and enterprise environments where a compromised RMM server can provide broad downstream access.
Djinn Stealer is designed to harvest high-value secrets from developer and administrative workstations in a single collection pass. Its targeting includes cloud and identity-platform credentials, source-control and developer artifacts, package-registry and build-tool authentication material, infrastructure and secrets-management configurations, browser data, shell history, SSH material, database client configurations, PGP data, cryptocurrency wallets, and tokens or configuration data associated with AI development assistants and Model Context Protocol integrations. On Linux, it also attempts to extract secrets from running processes by reading process command-line arguments and environment data.
The malware uses OS-specific collection logic to traverse user directories, apply hard-coded collection rules, and avoid noisy or low-value content such as caches, logs, and temporary data. Reported behavior includes deduplication and limits on file size or file count to reduce suspicion during collection. Stolen material is packaged into an archive, compressed, encrypted with AES-256-GCM, and the symmetric key is protected with an embedded RSA-2048 public key before exfiltration. Djinn Stealer has also been linked to TaskWeaver through shared obfuscation characteristics and encryption material.
The campaign associated with Djinn Stealer has not been publicly attributed to a specific threat actor. Its operational focus on cloud access, software development ecosystems, package registries, infrastructure tooling, and AI-assistant credentials indicates an emphasis on credential theft and follow-on access that can extend beyond the initially compromised endpoint into broader enterprise, customer, and software supply-chain environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Blackpoint Cyber found that an attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server. In affected configurations, SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician. | The recovered payload, Djinn Stealer, was a cross-platform infostealer for Windows, macOS and Linux.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server
SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician.
Djinn Stealer ... swept a machine for cloud and infrastructure keys, source code and SSH credentials, cryptocurrency wallets and package-registry tokens ... reaching for the tokens behind AI coding assistants.
Djinn is designed to harvest ... Browser data and session tokens
Djinn Stealer is designed to harvest a wide range of sensitive data from developer and administrative workstations. Its targets include cloud provider credentials, AI coding assistant tokens, Git repositories, SSH keys, Docker configurations, cryptocurrency wallets, and CI/CD secrets.
Blackpoint said it swept a machine for cloud and infrastructure keys, source code and SSH credentials
Djinn Stealer is designed to harvest credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets.
On Linux, it reads /proc/<pid>/cmdline and /proc/<pid>/environ virtual files to extract secrets like API keys, credentials, and session tokens from running processes.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously unreported stealer malware deployed following exploitation of the SimpleHelp authentication bypass, likely for credential theft and post-compromise access enablement.
A previously undiscovered stealer malware sample identified during attacks exploiting the SimpleHelp vulnerability CVE-2026-48558.
A previously undocumented cross-platform infostealer for Windows, macOS, and Linux that harvests cloud and infrastructure keys, source code, SSH credentials, cryptocurrency wallets, package-registry tokens, and tokens used by AI coding assistants, enabling broader compromise including potential supply-chain abuse.
A novel cross-platform infostealer for Windows, macOS, and Linux that traverses directories using OS-specific rules and steals sensitive files. It targets cloud-service credentials, developer environment secrets, package registry credentials, AI tool data, cryptocurrency wallets, browser and shell history, database client files, PGP data, and SSH configurations. It deduplicates files, excludes caches/logs/temp files, limits transfer size, archives data into gzip-compressed PAX tar format, encrypts it, and exfiltrates it over plain HTTP.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.