- [2026.06.24]dbkiss
Legitimate open-source database admin tool (DBKiss 1.11) with the most discreet W0rm supply-chain injection in the corpus. The backdoor hides inside a define() block and fires pre-auth at PHP parse time — before the application even starts.
- [2026.06.24]MySQL-interface
Standalone web-based MySQL administration tool carrying a W0rm supply-chain backdoor. Pre-auth RCE via GET parameter fires before any panel authentication. Hardcoded panel credentials (tryag_vb/102030). A lightweight phpMyAdmin alternative poisoned by its own redistributor.
- [2026.06.24]symlink.php
cPanel privilege escalation tool using symlink traversal across account boundaries — also carrying a W0rm supply-chain injection with pre-auth RCE that fires before any of the tool's own cookie-based authentication.
- [2026.06.24]unzipper
Legitimate archive extraction utility poisoned with W0rm supply-chain injection. Pre-auth RCE on every request, dynamic C2 email via MD5-of-Pastebin, and a dedupe mechanism that reports each compromised install exactly once.