SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, July 16, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY AsyncAPI npm Supply Chain Compromise Distributes Malware | CRITICAL |
|
5 C2 IPs | 39 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by a severe supply-chain compromise of AsyncAPI npm packages distributing credential-stealing malware, alongside actively exploited zero-day vulnerabilities in Microsoft SharePoint and Progress ShareFile. Organizations must also contend with critical unpatched vulnerabilities, including a zero-interaction code execution flaw in the Cursor IDE and a newly released elevation of privilege PoC (LegacyHive) targeting the Windows User Profile Service. |
|
■ CRITICAL STORIES AsyncAPI npm Packages Infected with Credential-Stealing Malware Threat actors compromised multiple packages in the @asyncapi npm namespace to deliver a multi-stage botnet loader and info-stealing remote access trojan, weaponizing trusted CI/CD workflows. |
CISA Warns of Actively Exploited SharePoint Server Zero-Days CISA has added three SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, including two zero-days, urging immediate patching of internet-exposed on-premises instances. |
Unpatched Cursor IDE Vulnerability Allows Arbitrary Code Execution A critical flaw in the Cursor developer environment automatically executes a malicious git.exe binary placed in a repository's root directory upon opening, requiring no user interaction or confirmation. |
Researcher Releases LegacyHive Windows Zero-Day PoC Post-Patch Tuesday Security researcher Chaotic Eclipse released a proof-of-concept exploit targeting an arbitrary hive load elevation of privilege vulnerability in the Windows User Profile Service, bypassing recent Microsoft patches. |
|
■ CVEs IDENTIFIED CVE-2026-15718 Mozilla Firefox — Invalid pointer in JavaScript: WebAssembly component leading to code execution |
[CVE-TBD] Zoom Desktop Client & SDK for Windows — Unauthenticated account takeover |
[CVE-TBD] Cursor IDE — Arbitrary code execution via malicious git.exe in repository root |
[CVE-TBD] Progress ShareFile Storage Zones Controller — Zero-day vulnerability causing service disruption |
|
■ THREAT ACTORS bandcampro | Cybercriminal / Threat Actor |
Abused Google Gemini CLI as a hacking agent and botnet operator |
Chaotic Eclipse (Nightmare-Eclipse) | Security Researcher / Exploit Dev |
Released "LegacyHive" Windows User Profile Service zero-day PoC |
TuxBot v3 Operators | Botnet Operator |
Developed and deployed LLM-assisted IoT botnet framework |
|
|
|
■ ATT&CK TTPs | T1195.001 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malicious AsyncAPI npm packages published to deliver malware |
| T1204.001 | | User Execution: Malicious Link | OkoBot malware injecting phishing prompts into crypto wallet apps |
| T1204.002 | | User Execution: Malicious File | Cursor IDE executing malicious git.exe when opening a repository |
| T1068 | | Exploitation for Privilege Escalation | LegacyHive PoC exploiting Windows User Profile Service |
| T1102 | | Web Service | Google Gemini CLI abused as a C2 and hacking agent by "bandcampro" |
| T1036 | | Masquerading | CrashStealer malware posing as Apple's CrashReporter to steal credentials |
|
■ PATCH PRIORITY Microsoft — SharePoint Server: Actively exploited zero-day vulnerabilities — SecurityWeek |
Progress — ShareFile Storage Zones Controller: Zero-day vulnerability causing active disruption — SecurityWeek |
ServiceNow — AI Platform: Critical remote code execution (RCE) vulnerability — SecurityWeek |
Zoom — Desktop Client & SDK (Windows): Critical unauthenticated account takeover vulnerability — BleepingComputer |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately audit and update all dependencies on @asyncapi npm packages to remove compromised versions distributing credential-stealing malware. |
| 2 | [P1] Patch Microsoft SharePoint Server instances immediately to mitigate the three actively exploited zero-day vulnerabilities highlighted by CISA. |
| 3 | [P1] Apply security updates to Progress ShareFile Storage Zones Controller to resolve the active zero-day vulnerability causing service disruptions. |
| 4 | [P1] Apply Mozilla Firefox updates to address critical vulnerabilities, including CVE-2026-15718, for which public exploit code exists. |
| 5 | [P2] Avoid opening untrusted or unverified repositories in Cursor IDE on Windows until a patch is released for the git.exe execution vulnerability. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |