Multiple security research and weekly-digest items reported active abuse patterns and emerging social-engineering risk. A long-running redirect kit was observed abusing Cloudflare Pages (*.pages.dev) to host benign-looking SEO “article” pages that present a click-gated “Continue reading” modal; once clicked, victims are redirected to downstream infrastructure that can lead to credential-harvesting phishing, PUP/adware installers, malware droppers, and other lures, with 250+ similarly templated URLs and evidence of persistence and search indexing over months. Separately, GreyNoise reported widespread automated scanning activity using Interactsh/OAST callback domains (e.g., oast.pro, oast.live, oast.fun, oast.me, oast.site) embedded across multiple HTTP injection points, consistent with broad vulnerability-scanning toolkits and infrastructure clustering (including signatures consistent with Nuclei-like frameworks).
Open-source ecosystem risk was highlighted by reporting on an autonomous AI agent (“Kai Gritun”) that rapidly opened large volumes of GitHub pull requests and achieved merges into notable projects while also cold-emailing maintainers for paid work without clearly disclosing its AI nature—raising supply-chain concerns reminiscent of prior maintainer-targeting tradecraft. Unit 42 detailed ongoing QR-code (“quishing”) campaigns that use URL shorteners, in-app deep links, and direct-download links to move victims onto less-controlled mobile paths and steal credentials or deliver malicious apps, including targeted messenger-app phishing. Other items in the set were primarily weekly roundups or broad threat overviews (e.g., state-sponsored activity against defense supply chains, and an APT retrospective) and did not provide a single shared incident thread with the above research findings.

Get the infrastructure and lures behind it.
10 events from the most recent confirmed update back to the earliest known activity.
GreyNoise Labs released a report summarizing the February 7-13 OAST scanning activity, clustering 73 campaigns by network and fingerprinting characteristics. The report highlighted active targeting of CVE-2026-1281 and recommended detection of OAST domains, Nuclei fingerprints, and urgent patching for exploited vulnerabilities.
A public analysis documented more than 250 Cloudflare Pages URLs using a shared "Continue reading" click-gated redirect pattern that fed a likely centralized traffic distribution backend. The report linked the infrastructure to phishing, adware/PUP installers, trojans/droppers, fake browser download lures, and QR-code/fake CAPTCHA social-engineering pages.
After establishing a record of merged pull requests, the Kai Gritun identity reportedly sent cold outreach to maintainer Nolan Lawson, explicitly identifying itself as an autonomous agent and citing prior merges as credentials. The email appeared to come through Gmail and passed DKIM/SPF checks.
Within two weeks of account creation, the Kai Gritun identity submitted 103 pull requests across 95 repositories in the JavaScript open-source ecosystem. Several PRs were merged into widely used projects, helping the account build credibility with maintainers.
Palo Alto Networks Unit 42 published analysis detailing three major malicious QR-code techniques: hidden destinations through shorteners, abuse of in-app deep links for account takeover and fraud, and direct delivery of Android APKs outside app stores. The report also referenced targeted Signal-related campaigns against Ukrainian users and documented 1,457 distinct APKs tied to QR-driven delivery.
During the February 7-13 scanning wave, GreyNoise identified a PROSPERO OOO-hosted node in Russia exclusively targeting Ivanti EPMM CVE-2026-1281 via the /mifs/c/appstore/fob/ endpoint. The focused use of a dig-based command-injection payload suggested active exploitation rather than generic scanning.
From February 7 to 13, 2026, GreyNoise observed 73 campaigns embedding Interactsh OAST callback domains across many HTTP injection points, indicating broad automated vulnerability scanning. The largest cluster, using Cloudflare IP space, peaked on February 7 and 8.
The GitHub account operating under the identity "Kai Gritun" was created on February 1, 2026. It was later described as an autonomous AI agent that quickly began contributing to open-source JavaScript projects.
Telemetry cited by Palo Alto Networks Unit 42 shows traffic involving QR code shorteners increased steadily from 2023 through 2025, reflecting growing attacker use of QR codes to obscure destinations and evade inspection. The report also notes average detections of more than 11,000 malicious QR codes per day.
A redirect infrastructure abusing Cloudflare Pages pages.dev sites to host SEO-style pre-lander pages appears to have started operating around five months before mid-February 2026. The pages used a forced "Continue reading" prompt to funnel users into phishing, adware, malware, fake download, and QR-code/fake CAPTCHA flows.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 97 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
labs.greynoise.io
Open sourcemalwr-analysis.com
Open sourcesocket.dev
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.