TaskWeaver is a heavily obfuscated, modular Node.js malware loader first observed following exploitation of CVE-2026-48558, a critical authentication-bypass vulnerability in SimpleHelp remote monitoring and management deployments using vulnerable OpenID Connect configurations. An unidentified threat actor used a forged technician session to abuse SimpleHelp’s native file-transfer and remote-execution capabilities, mass-deploying TaskWeaver to managed endpoints. The loader masquerades as a benign JavaScript library and is executed by the legitimate Node.js runtime.
TaskWeaver fingerprints compromised hosts, including operating-system and process-related information, and transmits encrypted beacon data to command-and-control infrastructure. It employs layered obfuscation and runtime reconstruction of Node.js module-loading functionality to impede static analysis. Its observed payload-delivery capability retrieves, decrypts, and executes operator-provided JavaScript with full Node.js runtime access, enabling reusable deployment of arbitrary follow-on payloads rather than a fixed command set. In the observed operation, TaskWeaver delivered Djinn Stealer, a cross-platform information stealer focused on cloud, developer, infrastructure, browser, SSH, package-registry, cryptocurrency-wallet, and AI-development-assistant data. The campaign creates particular risk for managed service providers and other organizations operating centralized remote-management infrastructure, where a compromised technician session can provide broad access to downstream systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The disclosure of CVE-2026-48558 affecting the SimpleHelp RMM tool provides a good example of why this category often receives additional scrutiny... Blackpoint’s Adversary Pursuit Group (APG) recently investigated an intrusion that began with the threat actor exploiting CVE-2026-48558. The threat actor obtained an authenticated technician session on an internet-facing SimpleHelp server and used the access to deploy two previously undocumented malware samples, which the APG has named TaskWeaver and Djinn Stealer. | The threat actor obtained an authenticated technician session on an internet-facing SimpleHelp server and used the access to deploy two previously undocumented malware samples, which the APG has named TaskWeaver and Djinn Stealer.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker exploited the flaw, tracked as CVE-2026-48558, to obtain a trusted technician session on an internet-facing SimpleHelp server
SimpleHelp failed to check the cryptographic signature of identity tokens in its OpenID Connect login, letting an unauthenticated attacker forge a token and sign in as a technician.
TaskWeaver was a modular Node.js loader designed to fingerprint the compromised system, establish encrypted communications with attacker-controlled infrastructure, and retrieve and execute additional JavaScript payloads with full access to the Node.js runtime. | TaskWeaver sent the beacon as an HTTPS POST request with a text/plain body.
mass-deploy an obfuscated file disguised as the jQuery library, jquery.js, fetched from a temporary Cloudflare address
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously undocumented malware sample deployed after exploitation of an internet-facing SimpleHelp server.
Node.js-based first-stage loader that delivers Djinn Stealer through its "deliver" task, executing the payload in a new Node.js runtime context.
Node.js loader deployed following exploitation of a SimpleHelp authentication-bypass flaw to deliver Djinn Stealer.
Previously unreported malware family deployed after exploitation of the SimpleHelp authentication bypass on compromised RMM deployments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.