Daily Security Intel

Archives
Log in
Subscribe
August 5, 2026

[SecurityIntel] 05 Aug | ChainDrop Self-Propagating NPM Supply Chain Worm

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, August 05, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

ChainDrop Self-Propagating NPM Supply Chain Worm

CRITICAL

5

C2 IPs

43

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

The primary threat today is the massive "ChainDrop" self-propagating npm supply chain worm, which has compromised over 1,300 packages to steal developer credentials and plant malicious hooks. Additionally, TP-Link has patched 15 critical vulnerabilities in its Omada Zero-Touch Provisioning (ZTP) ecosystem that allow for remote code execution and complete network takeover. Organizations must also defend against sophisticated "ClickFix" campaigns delivering RATs and Greatness PhaaS campaigns leveraging OAuth device code phishing to bypass MFA.

■ CRITICAL STORIES

HIGH#1

ChainDrop Worm Poisons Over 1,300 NPM Packages

A highly virulent, self-propagating credential-stealing worm has infected the Node Package Manager (npm) registry, injecting malicious hooks into developer environments (such as VS Code and Claude Code) and automatically republishing updates to spread.

CRITICAL#2

TP-Link Patches 15 Omada ZTP Vulnerabilities

Flaws in TP-Link's Omada Zero-Touch Provisioning (ZTP) mechanism can be chained to achieve unauthenticated remote code execution (RCE) and full network takeover, exposing enterprise network infrastructure.

HIGH#3

DOUBLECUP Loader Leverages ClickFix Lures and Cached PNGs

A new Russian loader-as-a-service uses social engineering "ClickFix" prompts to store malware-laced PNGs in browser caches, delivering CountLoader and the new DeviceManager RAT.

INFO#4

Google Deletes Malicious AI Agent Workflows from ADK

Researchers demonstrated that a public GitHub issue could manipulate a triage AI agent into triggering a privileged code-fixing agent, highlighting the emerging threat of AI agent prompt injection and privilege escalation.

■ CVEs IDENTIFIED

[CVE-TBD-1]

TP-Link Omada ZTP — Remote Code Execution (RCE) and full network takeover via chained vulnerabilities

Critical

[CVE-TBD-2]

cPanel — Privilege escalation allowing authenticated hosting customers to run SQL as database root

Critical

[CVE-TBD-3]

N-able N-central — Unspecified vulnerability leading to customer compromises, added to CISA KEV

High

[CVE-TBD-4]

Node Package Manager (npm) Keyv Package — Supply chain compromise via self-propagating credential-stealing worm (ChainDrop)

High

■ THREAT ACTORS

ChainDrop Actor

Cybercrime / Supply Chain Threat

Distributed self-propagating worm across 1,300+ npm packages to harvest developer credentials

Greatness PhaaS

Phishing-as-a-Service Operator

Expanded operations to include Adversary-in-the-Middle (AiTM) and OAuth 2.0 Device Code phishing targeting Microsoft 365

DOUBLECUP

Loader-as-a-Service (LaaS) / Cybercrime

Used ClickFix lures and cached PNGs to deliver CountLoader and DeviceManager RAT

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Malicious Software Update | ChainDrop worm automatically republishing malicious updates to over 1,300 npm packages
T1566.002
Phishing: Spearphishing Link | Greatness PhaaS utilizing RingCentral lures and ClickFix campaigns using fake Adobe/Zoom updates
T1539
Steal Web Session Cookie | Greatness PhaaS employing Adversary-in-the-Middle (AiTM) attacks to bypass MFA and steal session tokens
T1528
Steal Application Access Token | Greatness PhaaS abusing OAuth 2.0 Device Authorization Grant for device code phishing
T1059.006
Command and Scripting Interpreter: Python | Malicious manipulation of Google ADK Python workflows via GitHub issues
T1021.001
Remote Services: Remote Desktop Protocol | Fake updates installing ScreenConnect for persistent remote access

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

TP-Link Omada ZTP — Chained vulnerabilities allow unauthenticated RCE and full network takeover — [BC/SW]

[P1 PATCH NOW]≤24h

cPanel — Flaw allows authenticated hosting customers to run SQL as database root — [THN]

[P1 PATCH NOW]≤24h

N-able N-central — High-severity flaw actively exploited in the wild and added to CISA KEV — [THN]

[P2 PATCH NOW]≤72h

Node Package Manager (npm) Keyv — Self-propagating ChainDrop worm stealing credentials and injecting hooks — [MSFT/THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately audit and lock down npm dependencies to block [email protected] and related ChainDrop-infected packages, scanning development environments for unauthorized VS Code hooks.
2[P1] Apply the latest firmware updates for TP-Link Omada network devices to remediate the 15 ZTP vulnerabilities [CVE-TBD-1] that allow remote code execution.
3[P1] Apply the security patches released by cPanel to address the database root SQL execution vulnerability [CVE-TBD-2] on all hosted servers.
4[P1] Identify and patch all instances of N-able N-central [CVE-TBD-3] in accordance with CISA's KEV catalog directive to prevent active exploitation.
5[P2] Implement strict OAuth application consent policies and monitor for anomalous device code flow requests to mitigate Greatness PhaaS device-code phishing.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws Older → [SecurityIntel] 04 Aug | Midnight Blizzard Hijacks Hotel Wi-Fi Networks Globally
Powered by Buttondown, the easiest way to start and grow your newsletter.