Active Splunk Exploit and npm Supply Chain Campaign

Active Splunk Exploit and npm Supply Chain Campaign

•

Episode description

Active Splunk Exploit and npm Supply Chain Campaign

CISA has confirmed active exploitation of a critical Splunk Enterprise vulnerability, with a patch deadline of 22 June 2026 for US federal agencies. UK organisations face the same threat but lack a legal mandate. Separately, over 140 npm packages in the mastra ecosystem were compromised through account takeover, pushing typosquatted dependencies that harvest credentials on installation. A second npm attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating SSH keys and cloud credentials via DNS. A third attack targeted PyPI’s Microsoft DurableTask client through a stolen GitHub account. The Okendo Reviews widget, used by over 18,000 e-commerce brands, was also found to contain malicious JavaScript in May 2026. These attacks share a common thread: patient exploitation of trust frameworks in developer tooling and monitoring platforms. Mauven provides actionable steps for UK businesses to verify patch status, audit dependency chains, review DNS monitoring capability, and confirm e-commerce widget remediation before the weekend.

Chapters

  • Intro Mauven introduces two active threats requiring immediate attention: a CISA advisory on exploited enterprise software and a coordinated developer ecosystem compromise campaign. Response capability drops over weekends, making Friday advisories particularly dangerous.
  • npm Supply Chain Surge Microsoft Threat Intelligence confirmed compromise of over 140 npm packages via account takeover, pushing typosquatted dayjs dependency. A second attack exploited a lapsed maintainer email domain to compromise node-ipc, exfiltrating credentials via DNS. A third targeted PyPI’s DurableTask client. Okendo Reviews widget injected with malicious JavaScript in May 2026 affected 18,000 e-commerce brands.
  • CTA Listener call to action: follow the show and share with colleagues who need threat intelligence.
  • Splunk Enterprise Under Active Exploit CISA added Splunk Enterprise vulnerability to KEV catalogue with 22 June 2026 patch deadline for US agencies. UK organisations lack legal mandate but face identical risk. Compromised monitoring platforms allow attackers to suppress alerts and manipulate log data from a trusted internal position.
  • ICO Leadership Change John Edwards resigned as Information Commissioner. Leadership transition creates institutional uncertainty around enforcement priorities, though legal obligations remain unchanged.
  • What To Do Before Monday Immediate actions: verify Splunk patch status, audit recent npm and PyPI package updates, confirm Okendo widget remediation if present in May 2026, and implement or plan outbound DNS monitoring to close exfiltration blind spots.
  • Outro Attackers exploit trust in packages, monitoring tools, and institutional frameworks. They are patient, sophisticated, and aware that Friday advisories are often deferred. Do not give them the weekend.

Links

No transcript available for this episode.