TerminalFix hid payloads in PNG pixels

Ullrich points to SANS researcher Didier Stevens’s analysis of PNG files associated with TerminalFix. Stevens found valid images with payload bytes encoded in pixel data, rather than appended after the file or stored in metadata. A file-type check alone would not expose that content.

For defenders, the useful investigation is the execution chain: what fetched the image, which process decoded it, what ran next, and where that process connected. The PNG is evidence to preserve, but the surrounding behavior explains the intrusion.

The npm package waited until it was used

Ullrich also highlights Checkmarx Zero’s finding that malicious indexed-btree imitates the legitimate sorted-btree package. Checkmarx found no install hook. Its loader sits in a library method and runs only under a specific call condition, so blocking install scripts would miss this path.

Checkmarx reports host fingerprinting, exfiltration, and a second stage directed through an Ethereum testnet contract. Those are the researcher’s findings; the report does not establish how many organizations executed the package. Search manifests and lockfiles for the package, then investigate runtime use and outbound activity before drawing an impact conclusion.

Pi-hole’s management settings need a boundary

The third link in the episode is a Pi-hole FTL advisory. It describes a path from access to the web or API configuration interface to file read and code execution through advanced webserver options. The advisory says an authenticated session or no-password mode is a precondition.

Review who can reach and change the management interface, remove no-password access, and check affected versions against the project’s current fixed release. This is an administrative exposure question, not evidence that every Pi-hole instance is remotely exploitable.

Threat Field Notes assessment

Ullrich’s three topics are separate cases, not one campaign. Their shared lesson is to test what happens after a familiar wrapper is trusted: what an image decoder reconstructs, what package code executes during use, and what an administrator can change.

Three checks to make this week

  1. 1

    Trace suspicious image execution chains. For TerminalFix investigations, correlate the initial user action with image retrieval, decoding activity, child processes, and outbound connections. Retain the original PNG when collecting evidence.

  2. 2

    Search dependency records for the named package. Look for indexed-btree in manifests, lockfiles, build logs, and software inventories. If found, investigate runtime use and outbound activity; package installation alone does not prove the loader ran.

  3. 3

    Review Pi-hole management exposure. Check installed FTL versions against the current advisory, update affected instances, remove no-password access, and limit who can reach and change the management interface.

How this brief was prepared

Johannes B. Ullrich hosts the 22 September SANS Stormcast episode. Threat Field Notes used its episode description to identify the main topics and checked the linked SANS analysis, Checkmarx research, and Pi-hole advisory. This is an original defender synthesis based on those materials, not a transcript or a claim that we independently observed the attacks.