SimpleHelp flaw exploited to spread malware across managed systems

Blackpoint Cyber has described an intrusion that began with exploitation of a recently disclosed authentication bypass in the SimpleHelp remote management tool. The attacker used the compromised control plane to transfer files and execute malware across managed systems, deploying two previously undocumented components: TaskWeaver, an obfuscated Node.js loader, and Djinn Stealer, a cross-platform credential stealer. According to Blackpoint, Djinn targets credentials and tokens tied to cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH and cryptocurrency wallets. CISA added CVE-2026-48558 to its Known Exploited Vulnerabilities catalogue on 29 June.

What this means for your organisation

Remote management tooling is built to reach every machine with high privileges, and a breach of the control plane gives the attacker that same reach. If you use a managed service provider, you inherit their exposure. Because the stealer targets tokens for cloud services and code repositories, the consequences do not stop at the individual machine.

Berigo recommends

  • Confirm with your service provider that their SimpleHelp installation is patched, and ask for the answer in writing.
  • Run a compromise assessment of machines managed through SimpleHelp, not merely an update.
  • Rotate tokens and keys for cloud platforms, code repositories and package registries if there is any doubt.
  • Write notification duties and patching deadlines for remote management tooling into your supplier agreements.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch