A human-operated intrusion exploited CVE-2026-39987, a pre-authentication remote-code-execution flaw in Marimo's terminal WebSocket endpoint, to obtain an interactive shell without credentials. The operator reportedly spent about four hours creating eight custom Python scripts and then conducted a nine-hour session with more than 850 interactive commands, using no identifiable public offensive tooling. Although the attacker viewed an LLM prompt-injection bait file, Sysdig's tripwire did not trigger, supporting the assessment that the operation was directed by a human rather than an autonomous AI agent.
The prepared chain harvested cloud credentials from the host environment and Redis, queried AWS Secrets Manager for an SSH private key, wrote the key to /tmp/bastion_key, and used it to access an internet-exposed bastion host within eight seconds. Additional scripts configured a Netcat relay on 45.79.187.72:4444 and attempted reverse-shell access; failed EC2 Instance Connect enumeration followed by SendSSHPublicKey for placeholder instance ID i-0000000000000000 created a distinctive automation fingerprint. Marimo releases through 0.20.4 are affected; version 0.23.0 remediates the vulnerability, which was also added to CISA's Known Exploited Vulnerabilities catalog.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Sysdig's Threat Research Team published a technical write-up documenting the CVE-2026-39987 exploitation activity, the custom toolkit, and the attempted AWS and SSH operations.
CVE-2026-39987 was listed in CISA's Known Exploited Vulnerabilities catalog. CISA set a federal remediation deadline of May 7, 2026, though the source does not state when the catalog addition occurred.
At approximately 18:56 UTC, background automation received denied responses for DescribeInstances, DescribeKeyPairs, and DescribeInstanceInformation, then submitted a blocked SendSSHPublicKey request for placeholder instance ID i-0000000000000000. Sysdig identified this denied-enumeration-to-placeholder sequence as a behavioral fingerprint of the operator's automation.
After compromising the Marimo host, the operator harvested credentials from the process environment and Redis backend, replayed them against AWS, and retrieved an SSH private key from AWS Secrets Manager. The prepared chain enabled access to an internet-reachable bastion host within eight seconds of launch.
A human operator exploited CVE-2026-39987, a pre-authentication RCE flaw in Marimo's terminal WebSocket endpoint, to obtain an interactive shell as the Marimo process user without credentials. The operator subsequently issued more than 850 interactive commands during a nine-hour session.
The operator spent roughly four hours developing and debugging eight custom Python scripts, then stored them on the compromised host for later execution. The scripts included AWS Secrets Manager retrieval, SSH-key handling, reverse-shell, and relay/listener automation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.