v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Saturday · 22 August 2026 End-of-day synthesis 4 watches · 1 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

The story of the day — A day light on new disclosures narrowed to a single story: a BADBOX-linked group turned automotive Android head-unit firmware into a residential proxy botnet.

After two ingest passes, today's queue stayed short: GHSA's evening batch and CISA's KEV catalog both repeated yesterday's late-breaking items — the JSONata/Xinference/Phalcon/GeoTools RCE cluster and the Zimbra KEV add are already covered on the 2026-08-21 page — so nothing from either feed qualified as new today.

The one genuine story is Kaspersky Securelist's writeup attributing an automotive supply-chain attack to MoYu Group, the actor behind the BADBOX botnet: a legitimate DoFun firmware system app (TWCore) is repurposed as the dropper for a JarService loader that pulls a module called zhima, enrolling Android car head units — hardware that ships with its own SIM — into a residential-proxy botnet used for ad fraud and traffic laundering. It's the same TTP shape as BADBOX and BADBOX 2.0: a trusted OTA/update channel turned into the malware delivery path, this time on automotive infotainment rather than budget Android TV boxes.

→ Operational priority for the night if you evaluate aftermarket or OEM Android head units for fleet or product use, pull the current BADBOX indicator set and flag unexplained outbound proxy-style traffic or unexpected TWCore network activity as a compromise signal.

12:00 ET · Forenoon Watch

Android car head-unit firmware hijacked by MoYu/BADBOX-linked proxy botnet malware

Kaspersky's Securelist writeup attributes this to the MoYu Group — the actor behind the BADBOX botnet — abusing a legitimate DoFun firmware system app (TWCore) as the dropper for a JarService loader that pulls a module called zhima and enrolls the head unit in a residential-proxy botnet used for ad fraud and traffic laundering. It's the same TTP shape as BADBOX and BADBOX 2.0: a trusted OTA/update channel repurposed as the malware delivery path, this time on automotive infotainment hardware that ships with its own SIM for connectivity. If you're evaluating aftermarket or OEM Android head units, treat unexplained outbound proxy-style traffic or unexpected TWCore network activity as an IOC and pull the current BADBOX indicator set.