Threat Snapshot: Djinn Stealer

Threat Type Infostealer
Platform Cross-platform
First Observed June 21, 2026
Confidence High

Summary

Djinn Stealer is a cross-platform information stealer, identified by the Blackpoint Adversary Pursuit Group (APG), delivered as a second-stage payload by the TaskWeaver Node.js loader. It implements a rules-based collection engine that harvests credentials and configuration data for cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets, then archives, encrypts, and exfiltrates the results to attacker-controlled infrastructure.

Aliases and Related Activity:

  • Associated with TaskWeaver (delivered as a second-stage payload)
  • Observed following exploitation of SimpleHelp vulnerability CVE-2026-48558

Key TTPs

Tactic Technique ATT&CK ID
Credential Access Unsecured Credentials: Credentials In Files T1552.001
Discovery File and Directory Discovery T1083
Process Discovery T1057
Collection Data from Local System T1005
Archive Collected Data T1560
Command and Control Encrypted Channel: Asymmetric Cryptography T1573.002
Exfiltration Exfiltration Over C2 Channel T1041
Tool / Family Role
TaskWeaver First-stage Node.js loader that delivered Djinn Stealer as a follow-on payload.
Node.js (node.exe) Legitimate JavaScript runtime abused to execute Djinn Stealer.

Indicators of Compromise

Type Value
Djinn Stealer Execution Delivered via TaskWeaver’s “deliver” task; executed inside a new Node.js runtime context
Djinn Stealer f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc
Djinn Stealer upload
Djinn Stealer Exfiltration 96[.]126[.]130[.]126:58942
Djinn Stealer User-Agent telemetry-client/1.0

Recommendations

  • Rotate and treat as compromised all credentials accessible from an infected system, including cloud, source control, package registry, AI development tool, SSH, and cryptocurrency wallet credentials.
  • Apply application control and restrict or monitor the execution of Node.js (node.exe) and other scripting runtimes on systems where they are not operationally required.
  • Monitor for large or unusual outbound file transfers and unexpected archive creation activity on endpoints, particularly to newly observed or low-reputation IP addresses.
  • Limit remote management software access using least-privilege principles and multi-factor authentication (MFA), and regularly audit technician accounts for unauthorized activity.
  • Reduce reliance on long-lived credentials by using short-lived, workload-bound identities and removing unnecessary production secrets from developer and administrative workstations.

References

Beal, Nevan; Decker, Sam (2026, June 29) Blackpoint Cyber: “A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain.” https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/

DATE PUBLISHEDSeptember 10, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY