Djinn Stealer is a cross-platform information-stealing malware family targeting Windows, macOS, and Linux. Identified by Blackpoint Cyber’s Adversary Pursuit Group, it is delivered as a second-stage JavaScript payload by the TaskWeaver Node.js loader. Its observed deployment followed exploitation of CVE-2026-48558, an OpenID Connect authentication bypass in SimpleHelp remote monitoring and management software. An unidentified threat actor obtained an authenticated technician session on an internet-facing SimpleHelp server and abused its native file-transfer and remote-execution capabilities to deploy the malware to managed endpoints.
Djinn Stealer uses operating-system-specific collection rules to enumerate user directories and recursively harvest credentials, session tokens, configuration files, and sensitive development artifacts. Targets include cloud platforms, identity services, source-control tools, package registries, build systems, infrastructure tooling, SSH and PGP keys, browser data, database clients, shell histories, and cryptocurrency wallets and keystores. It also collects authentication, session, project, and Model Context Protocol configuration data associated with Claude, Gemini, Codex, Cline, OpenCode, and Kilo. On Linux, it examines running-process arguments and environment variables for exposed credentials and other secrets. Its collection scope emphasizes developer and administrative workstations, including systems reachable through compromised managed-service-provider infrastructure.
The malware excludes selected high-volume directories, deduplicates collected files, and applies file-size and file-count limits. It packages stolen data into a gzip-compressed PAX tar archive, encrypts the archive with AES-256-GCM, protects the encryption key using RSA-2048, and exfiltrates the encrypted data over HTTP to attacker-controlled infrastructure. Djinn Stealer shares TaskWeaver’s obfuscation framework and embedded RSA public key. Theft of developer, cloud, package-registry, and AI-assistant credentials can expose connected repositories, infrastructure, and downstream services beyond the infected endpoint.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The disclosure of CVE-2026-48558 affecting the SimpleHelp RMM tool provides a good example of why this category often receives additional scrutiny... Blackpoint’s Adversary Pursuit Group (APG) recently investigated an intrusion that began with the threat actor exploiting CVE-2026-48558. The threat actor obtained an authenticated technician session on an internet-facing SimpleHelp server and used the access to deploy two previously undocumented malware samples, which the APG has named TaskWeaver and Djinn Stealer. | The threat actor obtained an authenticated technician session on an internet-facing SimpleHelp server and used the access to deploy two previously undocumented malware samples, which the APG has named TaskWeaver and Djinn Stealer.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server
SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician.
Some agents keep access tokens or refresh tokens locally... A stolen access token may let an attacker use an account until it expires, and a refresh token can sometimes extend that window, enabling paid API abuse or resale of working access.
Djinn Stealer is designed to harvest a wide range of sensitive data from developer and administrative workstations. Its targets include cloud provider credentials, AI coding assistant tokens, Git repositories, SSH keys, Docker configurations, cryptocurrency wallets, and CI/CD secrets.
Djinn Stealer "harvests credentials and configuration data for cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets."
It beacons to a command-and-control server using a hybrid encryption scheme to hide its traffic... The encrypted archive is exfiltrated to the C2 server via plain HTTP.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An infostealer family documented targeting MCP configuration paths. It is cited as prior evidence of malware collecting AI-tooling configurations, rather than as a subject of the credential census.
Previously undocumented stealer malware deployed after exploitation of an internet-facing SimpleHelp server.
Cross-platform information stealer that uses a rules-based collection engine to harvest credentials and configuration data from cloud platforms, source-control services, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets. It archives and encrypts collected data before exfiltrating it over its C2 channel.
macOS-focused information stealer associated with harvesting data from multiple AI coding agents, including Claude, Codex, Gemini, Cline, OpenCode, and Kilo.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.