Threat Snapshot: Djinn Stealer
Summary
Djinn Stealer is a cross-platform information stealer, identified by the Blackpoint Adversary Pursuit Group (APG), delivered as a second-stage payload by the TaskWeaver Node.js loader. It implements a rules-based collection engine that harvests credentials and configuration data for cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets, then archives, encrypts, and exfiltrates the results to attacker-controlled infrastructure.
Aliases and Related Activity:
- Associated with TaskWeaver (delivered as a second-stage payload)
- Observed following exploitation of SimpleHelp vulnerability CVE-2026-48558
Key TTPs
| Tactic | Technique | ATT&CK ID |
|---|---|---|
| Credential Access | Unsecured Credentials: Credentials In Files | T1552.001 |
| Discovery | File and Directory Discovery | T1083 |
| Process Discovery | T1057 | |
| Collection | Data from Local System | T1005 |
| Archive Collected Data | T1560 | |
| Command and Control | Encrypted Channel: Asymmetric Cryptography | T1573.002 |
| Exfiltration | Exfiltration Over C2 Channel | T1041 |
Tooling & Family Links
| Tool / Family | Role |
|---|---|
| TaskWeaver | First-stage Node.js loader that delivered Djinn Stealer as a follow-on payload. |
| Node.js (node.exe) | Legitimate JavaScript runtime abused to execute Djinn Stealer. |
Indicators of Compromise
| Type | Value |
|---|---|
| Djinn Stealer Execution | Delivered via TaskWeaver’s “deliver” task; executed inside a new Node.js runtime context |
| Djinn Stealer | f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc |
| Djinn Stealer | upload |
| Djinn Stealer Exfiltration | 96[.]126[.]130[.]126:58942 |
| Djinn Stealer User-Agent | telemetry-client/1.0 |
Recommendations
- Rotate and treat as compromised all credentials accessible from an infected system, including cloud, source control, package registry, AI development tool, SSH, and cryptocurrency wallet credentials.
- Apply application control and restrict or monitor the execution of Node.js (node.exe) and other scripting runtimes on systems where they are not operationally required.
- Monitor for large or unusual outbound file transfers and unexpected archive creation activity on endpoints, particularly to newly observed or low-reputation IP addresses.
- Limit remote management software access using least-privilege principles and multi-factor authentication (MFA), and regularly audit technician accounts for unauthorized activity.
- Reduce reliance on long-lived credentials by using short-lived, workload-bound identities and removing unnecessary production secrets from developer and administrative workstations.
References
Beal, Nevan; Decker, Sam (2026, June 29) Blackpoint Cyber: “A Djinn in the Machine: TaskWeaver’s Node.js Intrusion Chain.” https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
DATE PUBLISHEDSeptember 10, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours