Threat Brief — 2026-09-18 — V8 flaw, npm stealer, Excel fix lands
Executive summary. A new Chromium V8 out-of-bounds memory access vulnerability (CVE-2026-0899) warrants attention for browser-update pipelines. A financially motivated actor has been distributing the PhantomRaven information stealer through npm, reportedly built with LLM assistance — the latest in a wave of package-registry supply-chain attacks. On the operational side, Microsoft has finally shipped a fix for the Excel 2016 copy-and-paste breakage introduced by September's KB5002914 security update.
Top items
- Chromium V8 out-of-bounds memory access (CVE-2026-0899). Microsoft's security update guide has published information for an out-of-bounds memory access flaw in the V8 JavaScript engine. Browser V8 flaws are frequently leveraged for remote code execution through crafted web content; no public exploit is indicated in the finding. (src: MSRC)
- PhantomRaven npm information stealer. A financially motivated threat actor has distributed a JavaScript-based infostealer via the npm package registry. Researchers assess that the malware was likely written using a large language model, lowering the development barrier for supply-chain malware. This adds to a growing pattern of registry-abuse campaigns. (src: The Hacker News)
- Microsoft fixes Excel 2016 copy-and-paste breakage from KB5002914. Microsoft has resolved a known issue that caused copy-and-paste failures for some Excel 2016 users after installing the September 2026 KB5002914 security update. This was first reported on 2026-09-10 as a patch-induced regression; the fix closes the loop on an operational issue affecting productivity suites. (src: BleepingComputer)
Themes
Package-registry supply-chain attacks persist. PhantomRaven continues a well-established pattern of threat actors abusing npm and similar registries to distribute malicious packages — now with the added concern that LLMs may be lowering the skill floor for producing functional malware.
AI-assisted offensive tooling is becoming routine. The PhantomRaven finding and several recently reported incidents reinforce that LLM-generated or LLM-assisted malware is no longer theoretical; it is appearing in the wild across multiple platforms and attack types.
