Security advisories

Findings from our own investigations, published with the indicators other defenders need to act on them.

Published

LH-2026-004 · Published 2026-09-08 · TLP:CLEAR
A Recruiter-Supplied "MVP" Repository Carried a Node.js Backdoor

A cold approach on LinkedIn asked the reporter to review a startup’s “tokenized real estate” MVP before a meeting. Reading the source rather than running it found fourteen lines that POST the machine’s entire process.env to a base64-hidden endpoint and then compile the HTTP response as JavaScript with require passed in. The function is absent from module.exports and self-invokes at module load, so it fires from npm start alone — which is exactly what the repository’s README tells the reader to do. Two findings of independent interest: the endpoint is not new, having been named in at least 21 malicious-npm-package advisories since 2026-04-16, and GitLab’s own API shows the namespace was created hours before the approach while the single commit inside it is dated three and a half weeks earlier, so the commit date is fabricated. Includes the execution trace, twelve concealment signals, a behavioural YARA rule, a pre-install triage script, and an account of the one step in our own analysis that went further than the plan allowed.

LH-2026-003 · Published 2026-08-06 · TLP:CLEAR
A Retracted Finding Survived Its Own Correction in the File AI Assistants Read

A defect in our own publishing, reported against ourselves. We withdrew a finding and published a correction ninety minutes later — and the correction reached the advisory page and stopped there. llms.txt and a published STIX 2.1 bundle kept asserting the retracted claim, and a keyword sweep missed them because the behaviour had been written out without the word we searched for. Includes the enumeration of surfaces a correction has to reach.

LH-2026-002 · Published 2026-08-06 · TLP:CLEAR
A Live Phishing Page Went Undetected by Browser Safe-Browsing for Nearly Eight Hours

Measured, not asserted: a credential-harvesting page that five commercial engines classified as phishing or malicious was rated clean by the Google Safe Browsing engine row on the VirusTotal URL report — the feed behind the Chrome, Firefox and Safari interstitial — so nobody who clicked saw a browser warning. Includes the full timestamped record, the fair counterpoint on false positives, and what defenders should assume instead. Every observation is reproducible against public URLs.

LH-2026-001 · Published 2026-08-06 · Updated 2026-08-12 · TLP:CLEAR
Credential-Phishing Campaign Distributed From a Compromised AirDroid (Sand Studio) Mailbox

Mail sent from a vendor's own business-development mailbox passed SPF, DKIM and DMARC under a p=reject policy, with no external hop in the Received: chain. The operator replied in-thread seven minutes after being challenged. The payload is a two-stage adversary-in-the-middle kit — a Microsoft-branded gate on an abused domain handing the victim's address to a Cloudflare-fronted domain registered seven days earlier, now behind a Turnstile gate. Full IOCs, hunting guidance, disclosure timeline, and a published correction withdrawing one of our own v1.0 findings. Updated 2026-08-12 — vendor response received, advisory concluded: Sand Studio reports that initial access came from a phishing mail to one of its own employees, that unauthorised access was limited to that single Google Workspace mailbox, and that it notified every identified recipient. After we declined to accept mail from the affected tenant as disclosure, the vendor published a security notice on its own domain on 2026-08-12 — a surface the compromised mailbox does not control — which resolved the provenance question the advisory had raised. Our incident response is closed; no finding or indicator was changed at any point.

How to read these

Each advisory separates what we observed from what we inferred, states a confidence level per finding, and carries a section titled What we did not find. Where we could not establish something, we say so rather than rounding up.

Note on indicators

Indicator blocks may reference infrastructure that was live at time of publication. Treat every URL and domain in an advisory as hostile. Do not visit them from a workstation, and do not authenticate against them under any circumstances.

Machine-readable feeds

Indicators are published alongside each advisory in CSV and STIX 2.1 for direct ingestion:

AdvisoryCSVSTIX 2.1
LH-2026-004 lh-2026-004-iocs.csv lh-2026-004.stix.json
LH-2026-001 lh-2026-001-iocs.csv lh-2026-001.stix.json

Reporting to us

To report a security issue in a Lifted Holdings product or service, see the vulnerability disclosure policy or email will@liftedholdings.com.