Attackers are actively exploiting CVE-2026-48558, a critical OIDC authentication bypass in the SimpleHelp remote monitoring and management platform, to gain technician-level access to internet-facing servers without valid credentials. Investigators found the intrusions used the trusted RMM channel to deploy TaskWeaver, a heavily obfuscated JavaScript/Node.js loader that established encrypted communications with attacker infrastructure and fetched a second-stage payload known as Djinn Stealer. Blackpoint Cyber said its disclosure of active exploitation prompted CISA to add the flaw to the Known Exploited Vulnerabilities catalog.
Once deployed, Djinn Stealer harvested high-value secrets from Windows, macOS, and Linux systems, including cloud credentials, SSH keys, API keys, service account credentials, browser data, source-control and package-registry tokens, cryptocurrency wallets, and credentials tied to AI development tools. Researchers said the malware encrypted stolen data with AES-256-GCM and protected the encryption key with RSA-2048 before exfiltration, while the campaign appeared to rely on opportunistic scanning for exposed vulnerable SimpleHelp instances rather than tightly targeted victim selection. The activity raises particular concern for MSPs and enterprises because a compromise of trusted RMM infrastructure can extend quickly into cloud, CI/CD, and software supply chain environments.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Following Blackpoint's disclosure of active exploitation, CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities catalog. The move underscored the need for affected organizations, especially MSPs, to patch, investigate, and rotate potentially exposed credentials.
Blackpoint Cyber publicly reported its investigation into the intrusion chain involving SimpleHelp exploitation, TaskWeaver, and Djinn Stealer. The disclosure highlighted the risk that compromise of trusted RMM infrastructure could extend into enterprise, cloud, CI/CD, and software supply chain environments.
TaskWeaver retrieved and deployed Djinn Stealer, a cross-platform information stealer affecting Windows, macOS, and Linux systems. The malware targeted cloud credentials, SSH keys, API and service account credentials, package registry and source control tokens, browser data, cryptocurrency wallets, and AI development tool secrets, encrypting stolen data before exfiltration.
After obtaining access through the vulnerable SimpleHelp platform, the attacker deployed an obfuscated Node.js/JavaScript loader tracked as TaskWeaver. The loader established encrypted communications with attacker infrastructure and served as a reusable second-stage delivery mechanism.
A recent intrusion campaign used CVE-2026-48558, a critical SimpleHelp OIDC authentication bypass, to gain technician-level access on Internet-facing remote monitoring and management servers without valid credentials. Researchers said the activity appeared to involve opportunistic scanning for vulnerable exposed instances.
SimpleHelp fixed the critical CVE-2026-48558 OpenID Connect authentication bypass on 2026-06-09, releasing versions 5.5.16 and 6.0 RC2. The flaw allowed unauthenticated attackers to forge identity tokens and create privileged Technician accounts, with possible MFA bypass in some configurations.
SimpleHelp published a security notice saying servers running 5.5.15 and earlier may be vulnerable under certain conditions and urged customers to update immediately. The company provided fixed releases 5.5.16 and 6.0 RC2, along with installation guidance and package hashes, while saying fuller disclosure details would follow later.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcethreataft.com
Open sourceblackpointcyber.com
Open sourcedarkreading.com
Open sourcethreataft.com
Open sourcesimple-help.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.