The latest Security Affairs malware research roundup (Round 118) is a snapshot of where the threat landscape actually sits in 2026: attackers are abandoning noisy exploit delivery in favor of living-off-the-user and living-off-the-ecosystem techniques. Four stories from this round deserve immediate attention from defenders:
- ClingSTUN — a Linux unauthorized-access mechanism that abuses public STUN infrastructure (the same Session Traversal Utilities for NAT services that power legitimate VoIP and WebRTC) for covert command-and-control, blending C2 traffic into normal-looking UDP/3478 flows.
- UAC-0277's ClickFix campaign — compromised websites serving fake CAPTCHA/verification pages that trick users into pasting malicious commands into the Windows Run dialog, delivering the LUNEXSTEALER infostealer.
- MALFEX — a malicious npm package whose
postinstallhook executed hostile payloads for fourteen months without triggering a single registry advisory, a brutal reminder that dependency trust is still an unmonitored blind spot in most pipelines. - PoeLLM ("Canto incognito") — malware abusing LLM-adjacent infrastructure, continuing the trend of attackers riding AI tooling adoption.
None of these rely on a patchable CVE. They exploit trust: trust in public infrastructure, trust in what a website tells a user to type, and trust in the package registry. That's precisely why signature-only defenses keep missing them — and why behavioral detection is the focus of this post.
Technical Analysis
UAC-0277 ClickFix → LUNEXSTEALER (Windows)
Attack chain: The actor compromises legitimate websites and injects overlay pages mimicking CAPTCHA or "Verify you are human" checks. The page instructs the victim to press Win+R, paste (via clipboard hijack — the page pre-populates the clipboard with a malicious one-liner), and hit Enter. The pasted command is typically a PowerShell or mshta.exe invocation that retrieves a second-stage payload, culminating in LUNEXSTEALER deployment — an infostealer harvesting browser credentials, cookies/session tokens, cryptocurrency wallets, and system fingerprints.
Key defensive observation: this technique produces a highly distinctive process lineage. Legitimate software almost never results in explorer.exe (the Run dialog's parent) spawning powershell.exe, pwsh.exe, mshta.exe, or curl.exe with remote-fetch arguments. That lineage is the detection pivot.
Affected platforms: Windows 10/11 and Server editions — anything with a Run dialog and PowerShell. Exploitation status: confirmed active in the wild via compromised-site injection; no CVE, no KEV entry — this is a social-engineering TTP, not a vulnerability.
ClingSTUN (Linux C2 via Public STUN)
Attack chain: After gaining initial unauthorized access to Linux hosts, the implant establishes command-and-control by abusing public STUN servers (UDP/TCP 3478, TLS 5349). Because STUN is a legitimate, widely deployed NAT-traversal protocol, egress to well-known STUN endpoints rarely trips egress filters or raises analyst eyebrows. The attacker tunnels tasking and exfil inside STUN-shaped traffic.
Key defensive observation: on servers, almost nothing legitimate talks to STUN. STUN is a client-side protocol — desktops running WebRTC/VoIP apps use it; web servers, database hosts, and containers do not. A server-side process with no WebRTC/VoIP role initiating outbound 3478/5349 connections is a high-fidelity anomaly.
MALFEX (npm Supply-Chain, postinstall Hook)
Attack chain: A typosquatted/malicious npm package ships a postinstall script in package.json. The moment a developer or CI runner executes npm install, the hook runs arbitrary code — no user interaction beyond the install itself. Fourteen months without an advisory means the package likely used environment gating (detonating only in CI/production-like environments) and staged payload retrieval to evade static scanning.
Key defensive observation: node/npm spawning shells, network fetchers (curl, wget, powershell), or credential-file access during install is anomalous for the overwhelming majority of packages. Lockfile integrity and --ignore-scripts are your primary controls.
PoeLLM / "Canto incognito"
Details are still emerging, but the pattern matches a growing class of malware piggybacking on LLM-tooling adoption — abusing AI API endpoints, developer-side tooling, or poisoned model-adjacent packages for persistence and exfil. The defensive lesson: apply the same egress monitoring and process-lineage scrutiny to AI developer tooling that you (should) apply to npm.
Detection & Response
Sigma Rules
---
title: ClickFix Run Dialog Script Execution - LUNEXSTEALER Delivery
description: Detects explorer.exe (Run dialog) spawning script interpreters or fetch tools with remote-retrieval arguments, consistent with UAC-0277 ClickFix social engineering delivering LUNEXSTEALER.
references:
- https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
- https://attack.mitre.org/techniques/T1204/002/
- https://attack.mitre.org/techniques/T1059/001/
author: Security Arsenal
id: 3f9c1a72-8b44-4e21-9d5a-2c7e6f0a1b93
status: experimental
date: 2026/04/10
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\explorer.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\curl.exe'
- '\wscript.exe'
- '\cscript.exe'
selection_cmdline:
CommandLine|contains:
- 'http://'
- 'https://'
- 'Invoke-Expression'
- 'iex '
- 'Invoke-WebRequest'
- 'iwr '
- 'DownloadString'
- 'FromBase64String'
- ' -enc '
- ' -e '
condition: all of selection_*
falsepositives:
- Rare; administrators pasting commands into Run dialog is atypical in managed environments
level: high
---
title: npm or node Spawning Shell or Network Fetcher During Install
description: Detects npm/node processes spawning shells or network retrieval utilities, consistent with malicious postinstall hooks such as MALFEX.
references:
- https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
- https://attack.mitre.org/techniques/T1195/002/
author: Security Arsenal
id: 7b2e4d61-1a9f-4c38-b502-9e3d8c7f2a46
status: experimental
date: 2026/04/10
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.cmd'
- '\npm.exe'
- '\npx.cmd'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\cmd.exe'
- '\curl.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
- '\wscript.exe'
condition: all of selection_*
falsepositives:
- A small number of legitimate packages with native build steps (node-gyp); baseline per pipeline and allowlist known-good packages
level: high
---
title: Server Process Initiating Outbound STUN Connection
description: Detects processes on Linux servers initiating connections to STUN ports (3478/5349), consistent with ClingSTUN abusing public STUN infrastructure for C2. Tune to exclude legitimate WebRTC/VoIP workloads.
references:
- https://securityaffairs.com/200775/breaking-news/security-affairs-malware-newsletter-round-118.html
- https://attack.mitre.org/techniques/T1071/001/
- https://attack.mitre.org/techniques/T1572/
author: Security Arsenal
id: c5a8f309-6d21-4b74-a1e8-4f2b9d0c3e57
status: experimental
date: 2026/04/10
logsource:
category: network_connection
product: linux
detection:
selection_port:
DestinationPort:
- 3478
- 5349
filter_known_rtc:
Image|endswith:
- '/chrome'
- '/firefox'
- '/zoom'
- '/asterisk'
- '/freepbx'
- '/teams'
condition: selection_port and not filter_known_rtc
falsepositives:
- Legitimate VoIP/WebRTC services (Asterisk, FreeSWITCH, coturn); exclude known RTC infrastructure by host group
level: medium
KQL (Microsoft Sentinel / Defender)
// Hunt 1: ClickFix lineage - Run dialog (explorer) spawning script/fetch tools
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName =~ "explorer.exe"
| where FileName in~ ("powershell.exe","pwsh.exe","mshta.exe","curl.exe","wscript.exe","cscript.exe")
| where ProcessCommandLine has_any ("http://","https://","iex","Invoke-WebRequest","iwr ","DownloadString","FromBase64String"," -enc")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, SHA256
| order by TimeGenerated desc;
// Hunt 2: npm/node spawning shells or fetchers (MALFEX-style postinstall abuse)
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("node.exe","npm.cmd","npm.exe","npx.cmd")
| where FileName in~ ("powershell.exe","cmd.exe","curl.exe","certutil.exe","bitsadmin.exe","wscript.exe","bash.exe","sh.exe")
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, FolderPath
| order by TimeGenerated desc;
// Hunt 3: Linux hosts with outbound STUN (3478/5349) from non-RTC processes (ClingSTUN) - via Syslog/CEF ingestion
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationPort in (3478, 5349)
| where DeviceAction !in ("deny","blocked")
| summarize ConnectionCount = count(), DistinctDestinations = dcount(DestinationIP), Destinations = make_set(DestinationIP, 20) by SourceHostName, SourceIP, DestinationPort, bin(TimeGenerated, 1d)
| order by ConnectionCount desc;
// Hunt 4: Defender network events to STUN ports from server-class devices
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemotePort in (3478, 5349)
| where ActionType == "ConnectionSuccess"
| where InitiatingProcessFileName !in~ ("chrome.exe","firefox.exe","msedge.exe","Teams.exe","Zoom.exe")
| summarize Connections = count(), RemoteIPs = make_set(RemoteIP, 20) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, bin(TimeGenerated, 1d)
| order by Connections desc;
Velociraptor VQL
-- Hunt: ClickFix-style execution lineage and postinstall abuse artifacts
-- Part A: Processes whose parent is explorer with script/fetch tooling and remote URLs
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime,
get_member(field='Exe') AS ProcessPath
FROM pslist()
WHERE CommandLine =~ '(?i)(https?://|FromBase64String|DownloadString|Invoke-Expression|iex | -enc)'
AND Name =~ '(?i)(powershell|pwsh|mshta|curl|wscript|cscript)'
-- Part B: npm/node parents spawning shells (MALFEX-style postinstall)
SELECT Pid, Ppid, Name, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(powershell|cmd|curl|certutil|sh|bash)'
AND Ppid IN (
SELECT Pid FROM pslist()
WHERE Name =~ '(?i)(node|npm|npx)'
)
-- Part C: npm lifecycle scripts present in recently modified node_modules (triage artifact)
SELECT FullPath, Mtime, Size
FROM glob(globs='C:\Users\*\**\node_modules\**\package.json')
WHERE Mtime > timestamp(epoch=win32time_to_unix(now() - 12096000000000))
Remediation / Hardening Scripts
# ClickFix / LUNEXSTEALER hardening + verification (run elevated)
# 1) Audit RunMRU for evidence of pasted commands (ClickFix artifacts live here)
Get-ChildItem 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' -ErrorAction SilentlyContinue |
ForEach-Object { $_.Property } | ForEach-Object {
$v = (Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU').$_
if ($v -match 'http|iex|Invoke|certutil|bitsadmin|mshta') {
Write-Warning "Suspicious RunMRU entry: $_ = $v"
}
}
# 2) Enforce PowerShell Constrained Language + Script Block Logging on endpoints
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name EnableScriptBlockLogging -Value 1 -Force
New-Item 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription' -Force | Out-Null
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription' -Name EnableTranscripting -Value 1 -Force
# 3) Disable mshta via WDAC/AppLocker is ideal; at minimum enable audit of mshta execution
auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable
# 4) Verify no unauthorized outbound STUN from Windows hosts (defense-in-depth)
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
Where-Object { $_.RemotePort -in 3478,5349 } |
Select-Object LocalAddress,RemoteAddress,RemotePort,OwningProcess,
@{N='Process';E={(Get-Process -Id $_.OwningProcess).ProcessName}}
#!/bin/bash
# ClingSTUN / MALFEX hardening for Linux servers and build runners
# 1) Identify current outbound STUN connections from non-RTC processes
ss -uapn | awk '$5 ~ /:(3478|5349)$/ {print}'
# 2) Egress-filter STUN on server VLANs (keep only on designated RTC hosts)
# iptables -A OUTPUT -p udp --dport 3478 -j LOG --log-prefix "STUN-EGRESS: "
# iptables -A OUTPUT -p udp --dport 3478 -j DROP
# iptables -A OUTPUT -p tcp --dport 3478:5349 -j DROP
# 3) Alert historically: search auth/syslog for repeated STUN destinations
grep -Ei '3478|5349' /var/log/syslog* 2>/dev/null | tail -50
# 4) npm supply-chain hardening: disable lifecycle scripts globally on CI/dev hosts
npm config set ignore-scripts true --location=global
echo 'ignore-scripts=true' > ~/.npmrc
# 5) Audit installed trees for postinstall hooks (MALFEX-style)
find . -name package.json -path '*node_modules*' -mtime -60 2>/dev/null | \
xargs grep -l '"postinstall"' 2>/dev/null
# 6) Verify lockfile integrity before installs in CI
npm ci --ignore-scripts --audit --audit-level=high
Remediation
UAC-0277 ClickFix / LUNEXSTEALER:
- User intervention control: There is no patch — the "vulnerability" is the user. Update security awareness training this quarter with the ClickFix pattern: no legitimate website will ever ask a user to press Win+R and paste a command. This single message kills the technique.
- Technical controls: Deploy AppLocker/WDAC rules blocking
mshta.exefor standard users; enforce PowerShell Constrained Language Mode via WDAC; enable Script Block Logging and forward Event ID 4104 to your SIEM. - Web filtering: Block newly registered domains and uncategorized sites at the proxy for the initial lure; the compromised-site overlay stage depends on injected JS on legitimate sites, so script-level protections (browser isolation for uncategorized sites) are the effective compensating control.
- If executed: Assume credential and session-token theft. Revoke all active sessions for the affected identity (Entra ID / IdP), force password resets, rotate API keys accessible from the host, and reimage — LUNEXSTEALER-class stealers are frequently followed by hands-on intrusions.
ClingSTUN:
- Add UDP/TCP 3478 and 5349 to your egress deny list for all server VLANs; permit only designated RTC infrastructure.
- Hunt historically (30–90 days) for any server-sourced STUN connections — C2 via public infrastructure leaves no malicious domain to pivot on, so volume and periodicity (beacon-like regularity to a fixed STUN endpoint) are your analytical pivots.
- For hosts showing suspicious STUN egress: isolate, capture memory, and triage persistence (
cron, systemd units,ld.so.preload, SSH authorized_keys) before remediation.
MALFEX / npm supply chain:
- Set
ignore-scripts=truein.npmrcacross developer workstations and CI runners; re-enable per-package only via an allowlist for packages that genuinely need native builds. - Use
npm ci(notnpm install) in CI, pin exact versions, and commit lockfiles. Diff lockfile changes in PR review — a surprisepostinstalladdition is a red flag. - Scan lockfiles against advisories continuously; MALFEX's 14-month advisory gap proves that advisory-only detection is insufficient — pair it with behavioral install-time monitoring (the Sigma/KQL above) and egress restrictions on build runners.
- If a malicious package was installed: treat the runner/dev host as compromised. Rotate all secrets present in the environment (CI variables,
.npmrctokens, SSH keys, cloud credentials) — postinstall hooks inherit the install user's full environment.
PoeLLM:
- Inventory AI/LLM tooling in your environment (many orgs cannot answer this today), apply egress allowlisting for model API endpoints, and monitor developer tooling for the same process-lineage anomalies described above.
Related Resources
Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.