// Flax Typhoon
Flax Typhoon, FortiBleed, and npm Malware: A Convergent Storm Hitting Infrastructure
By NeoShield AI Threat Desk · Published 2026-10-09 · 4 min read
#Flax Typhoon#FortiGate#npm supply chain#BIND#Apache Struts#credential theft#RAT#CISA KEV
October 9, 2026 brings a dangerous convergence of nation-state infrastructure attacks, active VPN lockouts, and a poisoned software supply chain — here is what defenders must prioritize today.
The FBI's disruption of Flax Typhoon operations is significant but should not be read as a resolution. The seizure of seven domains tied to the Chinese state-sponsored group's MicroScan and FishHub tooling removes specific command-and-control infrastructure, but the actors behind it remain active and capable of rebuilding. Organizations in energy, water, telecommunications, and manufacturing — the traditional targets of Flax Typhoon — should treat this as a window to hunt for existing footholds rather than a moment to stand down. Review outbound DNS and network telemetry for any historical connections to the seized domains, and audit privileged accounts and lateral movement paths that may have been established before the disruption.
Running parallel to the nation-state threat is the FortiBleed campaign actively targeting exposed FortiGate firewalls and SSL VPN gateways. Attackers are not just exploiting these devices — they are locking out legitimate administrators, a tactic designed to delay incident response and extend dwell time. If your organization has internet-facing FortiGate appliances, this is a patch-now situation. Verify that management interfaces are not exposed to the public internet, enforce multi-factor authentication on all VPN and administrative access, and review administrator account activity logs for any unauthorized changes or new accounts created in recent weeks. If you cannot patch immediately, restrict management plane access to trusted IP ranges as an interim control.
Two entries on CISA's Known Exploited Vulnerabilities catalog deserve attention precisely because of their age. CVE-2015-5477, a data processing error in ISC BIND, and CVE-2016-3081, a command injection vulnerability in Apache Struts, are both over a decade old. Their presence on the KEV list in 2026 is a reminder that legacy systems and unpatched internet-facing applications remain a reliable entry point for attackers. If your environment still runs affected versions of BIND or Apache Struts, those systems should be treated as compromised until proven otherwise. Inventory your DNS infrastructure and any Java-based web applications immediately.
The software supply chain threats dominate the developer-facing side of today's briefing. The tensorlake npm package, version 0.5.144, was compromised to deliver a credential-stealing worm named Shai-Hulud with persistence mechanisms and remote code execution capabilities. Separately, eight additional malicious npm packages have been downloaded nearly 41,000 times since August 2023, delivering the Overlord RAT and associated stealer malware. The scale and duration of these campaigns confirm that the npm ecosystem is under sustained, organized attack. Any organization with Node.js or JavaScript development pipelines must act.
Defensive priorities for today:
- Audit all npm dependencies in your CI/CD pipelines and developer workstations for tensorlake at version 0.5.144 and the eight newly identified malicious packages; remove and rotate any credentials accessible from affected systems immediately.
- Enable software composition analysis tools in your build pipelines to flag newly published or recently modified packages before they reach production.
- Lock npm package versions using lockfiles and consider mirroring approved packages through a private registry to reduce exposure to upstream compromise.
- Patch or isolate FortiGate appliances affected by FortiBleed; disable public-facing management interfaces and audit all administrator accounts for unauthorized additions.
- Search historical DNS and proxy logs for connections to Flax Typhoon infrastructure; escalate any hits to your incident response team regardless of how old the connection appears.
- Inventory BIND and Apache Struts deployments and apply available patches or compensating controls; treat any internet-exposed instance running vulnerable versions as a priority remediation.
- For developer endpoints that may have executed compromised npm packages, initiate credential rotation for all secrets stored in environment variables, configuration files, browser stores, and SSH key rings.
The thread connecting all of today's items is attacker patience. Flax Typhoon built persistent infrastructure over years. The npm campaign ran for over a year before broad detection. FortiBleed attackers are deliberately slowing defender response by locking out admins. The defensive answer to patience is visibility — continuous asset inventory, dependency monitoring, and behavioral detection that does not rely solely on known-bad signatures.
This briefing is informational and does not replace official vendor advisories, CISA guidance, or your organization's incident response procedures.
Related articles
Credential Harvesters, Critical Patches, and Supply Chain Traps: October 8 Threat Briefing
Today's threat landscape is dominated by credential theft campaigns, critical unpatched vulnerabilities in enterprise…
MCPAI Protocols, Stolen CPR Data, and Critical Atlassian Flaws: October 7 Threat Briefing
From exposed MCP servers and a massive Danish identity breach to exploited WordPress plugins and a critical Atlassian file-access…
NetScalerNetScaler SAML Zero-Day, Zammad Session Flaws, and the Week's Quiet Leverage Points
CVE-2026-88779 is actively knocking SAML authentication offline across Citrix NetScaler deployments while two Zammad…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.