SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, August 05, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY ChainDrop Self-Propagating NPM Supply Chain Worm | CRITICAL |
|
5 C2 IPs | 43 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR The primary threat today is the massive "ChainDrop" self-propagating npm supply chain worm, which has compromised over 1,300 packages to steal developer credentials and plant malicious hooks. Additionally, TP-Link has patched 15 critical vulnerabilities in its Omada Zero-Touch Provisioning (ZTP) ecosystem that allow for remote code execution and complete network takeover. Organizations must also defend against sophisticated "ClickFix" campaigns delivering RATs and Greatness PhaaS campaigns leveraging OAuth device code phishing to bypass MFA. |
|
■ CRITICAL STORIES ChainDrop Worm Poisons Over 1,300 NPM Packages A highly virulent, self-propagating credential-stealing worm has infected the Node Package Manager (npm) registry, injecting malicious hooks into developer environments (such as VS Code and Claude Code) and automatically republishing updates to spread. |
TP-Link Patches 15 Omada ZTP Vulnerabilities Flaws in TP-Link's Omada Zero-Touch Provisioning (ZTP) mechanism can be chained to achieve unauthenticated remote code execution (RCE) and full network takeover, exposing enterprise network infrastructure. |
DOUBLECUP Loader Leverages ClickFix Lures and Cached PNGs A new Russian loader-as-a-service uses social engineering "ClickFix" prompts to store malware-laced PNGs in browser caches, delivering CountLoader and the new DeviceManager RAT. |
Google Deletes Malicious AI Agent Workflows from ADK Researchers demonstrated that a public GitHub issue could manipulate a triage AI agent into triggering a privileged code-fixing agent, highlighting the emerging threat of AI agent prompt injection and privilege escalation. |
|
■ CVEs IDENTIFIED [CVE-TBD-1] TP-Link Omada ZTP — Remote Code Execution (RCE) and full network takeover via chained vulnerabilities |
[CVE-TBD-2] cPanel — Privilege escalation allowing authenticated hosting customers to run SQL as database root |
[CVE-TBD-3] N-able N-central — Unspecified vulnerability leading to customer compromises, added to CISA KEV |
[CVE-TBD-4] Node Package Manager (npm) Keyv Package — Supply chain compromise via self-propagating credential-stealing worm (ChainDrop) |
|
■ THREAT ACTORS ChainDrop Actor | Cybercrime / Supply Chain Threat |
Distributed self-propagating worm across 1,300+ npm packages to harvest developer credentials |
Greatness PhaaS | Phishing-as-a-Service Operator |
Expanded operations to include Adversary-in-the-Middle (AiTM) and OAuth 2.0 Device Code phishing targeting Microsoft 365 |
DOUBLECUP | Loader-as-a-Service (LaaS) / Cybercrime |
Used ClickFix lures and cached PNGs to deliver CountLoader and DeviceManager RAT |
|
|
|
■ ATT&CK TTPs | T1195.002 | | Supply Chain Compromise: Malicious Software Update | ChainDrop worm automatically republishing malicious updates to over 1,300 npm packages |
| T1566.002 | | Phishing: Spearphishing Link | Greatness PhaaS utilizing RingCentral lures and ClickFix campaigns using fake Adobe/Zoom updates |
| T1539 | | Steal Web Session Cookie | Greatness PhaaS employing Adversary-in-the-Middle (AiTM) attacks to bypass MFA and steal session tokens |
| T1528 | | Steal Application Access Token | Greatness PhaaS abusing OAuth 2.0 Device Authorization Grant for device code phishing |
| T1059.006 | | Command and Scripting Interpreter: Python | Malicious manipulation of Google ADK Python workflows via GitHub issues |
| T1021.001 | | Remote Services: Remote Desktop Protocol | Fake updates installing ScreenConnect for persistent remote access |
|
■ PATCH PRIORITY TP-Link Omada ZTP — Chained vulnerabilities allow unauthenticated RCE and full network takeover — [BC/SW] |
cPanel — Flaw allows authenticated hosting customers to run SQL as database root — [THN] |
N-able N-central — High-severity flaw actively exploited in the wild and added to CISA KEV — [THN] |
Node Package Manager (npm) Keyv — Self-propagating ChainDrop worm stealing credentials and injecting hooks — [MSFT/THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately audit and lock down npm dependencies to block [email protected] and related ChainDrop-infected packages, scanning development environments for unauthorized VS Code hooks. |
| 2 | [P1] Apply the latest firmware updates for TP-Link Omada network devices to remediate the 15 ZTP vulnerabilities [CVE-TBD-1] that allow remote code execution. |
| 3 | [P1] Apply the security patches released by cPanel to address the database root SQL execution vulnerability [CVE-TBD-2] on all hosted servers. |
| 4 | [P1] Identify and patch all instances of N-able N-central [CVE-TBD-3] in accordance with CISA's KEV catalog directive to prevent active exploitation. |
| 5 | [P2] Implement strict OAuth application consent policies and monitor for anomalous device code flow requests to mitigate Greatness PhaaS device-code phishing. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |