CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

DAEMON Tools Lite

product · product:daemon-tools-lite

Coverage
1
first 2026-05-28 → last 2026-09-30
Latest activity
2026-05-28
Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector · regions: europe
Sources cited
7
6 hosts

Defender insights

What each entry about DAEMON Tools Lite tells a defender to do, newest first.

2026-05-28HIGHexploitedNx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries

Exposure · detection

Story timeline

  1. 2026-05-28Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
    deep-dive
ATT&CK techniques (3 across 3 tactics)

3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessSupply Chain Compromise: Compromise Software Supply Chain
  • Credential AccessUnsecured Credentials: Credentials In Files
  • ExfiltrationExfiltration Over Web Service

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Exfiltration TA0010

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-05-28/nx-console-tanstack-daemon-tools-supply-chain-cascade-lands · ATT&CK page ↗

Entries about DAEMON Tools Lite (1)

2026-05-28 · view entry permalink →

HIGHCVE-2026-48027 +2exploitedupdatedNATOB1

Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries

Background. The CISA KEV adds on 2026-05-27 close a chain of disclosures across the preceding three weeks that share a single operational pattern: trusted developer-tooling-publishing pipelines (a maintainer's machine, a vendor build server, a popular VS Code marketplace listing) used to push malicious code to downstream consumers at scale (CISA KEV catalog, 2026-05-27; Nx postmortem, 2026-05-21; GHSA-c9j4-9m59-847w, 2026-05-18; GHSA-g7cv-rxg3-hmpx, 2026-05-11; Disc Soft Limited, 2026-05-06; Kaspersky, 2026-05-05; Help Net Security, 2026-05-21). The TanStack compromise was carried out via Mini Shai-Hulud, TeamPCP's self-replicating worm that steals CI/CD credentials and uses them to publish infected versions of more packages (Help Net Security, 2026-05-21). Three of the chain's CVEs were added to CISA KEV on the same day (2026-05-27), confirming in-the-wild exploitation (CISA KEV catalog, 2026-05-27), and GitHub's CISO Alexis Wales named the malicious Nx Console extension as the vector for the theft of about 3,800 of GitHub's internal repositories (Help Net Security, 2026-05-21).

The TanStack → Nx Console pivot: CVE-2026-45321 and CVE-2026-48027.

The chain begins on 2026-05-11 with GHSA-g7cv-rxg3-hmpx (CVE-2026-45321): 84 malicious versions across 42 @tanstack/* npm packages were published with a credential-stealing payload (Nx postmortem, 2026-05-21). On a Nx contributor's machine the payload read locally stored credentials and exfiltrated them, including the contributor's GitHub CLI OAuth token. The Nx postmortem names @tanstack/zod-adapter@1.166.15 as the malicious dependency resolved on that machine (Nx postmortem, 2026-05-21). Seven days later, the attacker published Nx Console v18.95.0 as a legitimate Nx core contributor (Nx postmortem, 2026-05-21), tracked as CVE-2026-48027 (CISA KEV catalog, 2026-05-27). The malicious version was live on the Visual Studio Marketplace from 12:30 to 12:48 UTC on 2026-05-18 and on Open VSX from 12:33 to 13:09 UTC (GHSA-c9j4-9m59-847w, 2026-05-18). Nx Console is a VS Code extension with 2.2 million installs (Help Net Security, 2026-05-21). The payload ran on extension activation in VS Code or a fork such as Cursor and harvested Vault tokens, npm tokens, AWS metadata-service, Secrets Manager, SSM and Web Identity credentials, GitHub tokens, the contents of an active 1Password op CLI session, SSH private keys, .env files and GCP and Docker credentials (Nx postmortem, 2026-05-21). The advisory describes it as an obfuscated payload that the extension fetched, and says the harvested data was exfiltrated over HTTPS, the GitHub API and DNS (GHSA-c9j4-9m59-847w, 2026-05-18).

The advisory says the leaked credentials "allowed the attacker to run workflows on our GitHub repository as a contributor" (GHSA-c9j4-9m59-847w, 2026-05-18). The postmortem names the gap that let this become a release: until the incident any core contributor could publish a new Nx Console version without a second human's approval, with no required-reviewer rule and no environment gate (Nx postmortem, 2026-05-21). A stolen developer credential therefore turned into a downstream publish without secondary review.

CVE-2026-8398: DAEMON Tools Lite signed-build trojanisation.

CVE-2026-8398 covers a separate but parallel compromise of Disc Soft Limited's build environment. DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, circulating since 2026-04-08, contained trojanised DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe binaries signed with a valid AVB Disc Soft digital signature, which contact a command-and-control server at every system start (Kaspersky, 2026-05-05). Disc Soft says it found "unauthorized interference within our infrastructure" and that certain installation packages "were impacted within our build environment and were released in a compromised state". It released the clean version 12.6 on 2026-05-05 (Disc Soft Limited, 2026-05-06). Kaspersky detected several thousand attempts to install additional payloads through infected installations during the roughly four-week distribution window (Kaspersky, 2026-05-05). Safe version: 12.6 or later. CISA added the CVE to KEV on 2026-05-27 (CISA KEV catalog, 2026-05-27).

Downstream impact: what GitHub and Grafana Labs publicly confirmed.

GitHub CISO Alexis Wales named the malicious Nx Console v18.95.0 extension, installed by a GitHub employee, as the vector for GitHub's breach in which about 3,800 private repositories were exfiltrated (Help Net Security, 2026-05-21). Grafana Labs' CISO Joe McManus traced Grafana's separate GitHub breach to "a TanStack npm supply chain attack via the Mini Shai-Hulud campaign", not to Nx Console, so both breaches trace back to the TanStack compromise by different routes (Help Net Security, 2026-05-21). The malicious version was live for less than an hour (about 18 minutes on the Visual Studio Marketplace and 36 on Open VSX) (GHSA-c9j4-9m59-847w, 2026-05-18); the postmortem's summary gives about 11 minutes for the Marketplace, counted from the maintainers' first alert (Nx postmortem, 2026-05-21), and one install by a GitHub employee was enough for the attackers to reach GitHub's private repositories (Help Net Security, 2026-05-21).

Detection and hardening: what to push to operators today.

Hardening: enforce an organisational policy controls list for VS Code / Cursor / Windsurf extensions (the malicious upload passed the Visual Studio Marketplace's automated signing, manifest and malware checks (Nx postmortem, 2026-05-21)); pin npm dependencies with lockfile + --ignore-scripts for CI/CD builds; require human approval for any package that adds or modifies postinstall / preinstall / install scripts; rotate every CI/CD secret, npm token, GitHub PAT, and AWS access key accessible from any host that ran an affected Nx Console version between 2026-05-18 12:30 and 13:09 UTC. Treat any host that installed Nx Console 18.95.0, or had Nx Console installed with auto-update enabled in VS Code or a fork such as Cursor during that window, as potentially compromised (Nx postmortem, 2026-05-21).

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

CISA KEV catalog 2026-05-27
Correctionrun 2026-09-30T0639Z-auditsourcesbodyevidencesourcing_noteclassificationtechniquestagssummaryentitiesaffected_products

CISA's Known Exploited Vulnerabilities catalog marks both CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) as used in known ransomware campaigns (CISA KEV catalog, 2026-05-27). The attackers who stole Grafana Labs' codebase through the TanStack compromise demanded payment not to release or sell it, and Grafana did not pay (Help Net Security, 2026-05-21). Credentials exposed through either compromise are best handled on the assumption that an extortion group holds them.

The Nx postmortem does not describe token scopes, a tag push or hosted-runner publish secrets. It says any core contributor could publish without a second approval (Nx postmortem, 2026-05-21). The harvested credentials are Vault, npm, AWS service, GitHub, 1Password op session, SSH, .env, GCP and Docker secrets (Nx postmortem, 2026-05-21). GitHub named Nx Console only for its own breach, while Grafana Labs traced its breach to the TanStack npm attack (Help Net Security, 2026-05-21). The DAEMON Tools trojanised builds circulated for about four weeks, from 2026-04-08 until the clean 12.6 release on 2026-05-05 (Kaspersky, 2026-05-05; Disc Soft Limited, 2026-05-06).

vulnerability28 May 05:00Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Deep dive1

Source distribution

  • github.com2 (29%)
  • blog.daemon-tools.cc1 (14%)
  • cisa.gov1 (14%)
  • helpnetsecurity.com1 (14%)
  • kaspersky.com1 (14%)
  • nx.dev1 (14%)