Daily Security Intel

Archives
Log in
Subscribe
July 16, 2026

[SecurityIntel] 16 Jul | AsyncAPI npm Supply Chain Compromise Distributes Malware

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, July 16, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

AsyncAPI npm Supply Chain Compromise Distributes Malware

CRITICAL

5

C2 IPs

39

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by a severe supply-chain compromise of AsyncAPI npm packages distributing credential-stealing malware, alongside actively exploited zero-day vulnerabilities in Microsoft SharePoint and Progress ShareFile. Organizations must also contend with critical unpatched vulnerabilities, including a zero-interaction code execution flaw in the Cursor IDE and a newly released elevation of privilege PoC (LegacyHive) targeting the Windows User Profile Service.

■ CRITICAL STORIES

CRITICAL#1

AsyncAPI npm Packages Infected with Credential-Stealing Malware

Threat actors compromised multiple packages in the @asyncapi npm namespace to deliver a multi-stage botnet loader and info-stealing remote access trojan, weaponizing trusted CI/CD workflows.

CRITICAL#2

CISA Warns of Actively Exploited SharePoint Server Zero-Days

CISA has added three SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, including two zero-days, urging immediate patching of internet-exposed on-premises instances.

HIGH#3

Unpatched Cursor IDE Vulnerability Allows Arbitrary Code Execution

A critical flaw in the Cursor developer environment automatically executes a malicious git.exe binary placed in a repository's root directory upon opening, requiring no user interaction or confirmation.

HIGH#4

Researcher Releases LegacyHive Windows Zero-Day PoC Post-Patch Tuesday

Security researcher Chaotic Eclipse released a proof-of-concept exploit targeting an arbitrary hive load elevation of privilege vulnerability in the Windows User Profile Service, bypassing recent Microsoft patches.

■ CVEs IDENTIFIED

CVE-2026-15718

Mozilla Firefox — Invalid pointer in JavaScript: WebAssembly component leading to code execution

Critical

[CVE-TBD]

Zoom Desktop Client & SDK for Windows — Unauthenticated account takeover

Critical

[CVE-TBD]

Cursor IDE — Arbitrary code execution via malicious git.exe in repository root

High

[CVE-TBD]

Progress ShareFile Storage Zones Controller — Zero-day vulnerability causing service disruption

Critical

■ THREAT ACTORS

bandcampro

Cybercriminal / Threat Actor

Abused Google Gemini CLI as a hacking agent and botnet operator

Chaotic Eclipse (Nightmare-Eclipse)

Security Researcher / Exploit Dev

Released "LegacyHive" Windows User Profile Service zero-day PoC

TuxBot v3 Operators

Botnet Operator

Developed and deployed LLM-assisted IoT botnet framework

■ ATT&CK TTPs

T1195.001
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | Malicious AsyncAPI npm packages published to deliver malware
T1204.001
User Execution: Malicious Link | OkoBot malware injecting phishing prompts into crypto wallet apps
T1204.002
User Execution: Malicious File | Cursor IDE executing malicious git.exe when opening a repository
T1068
Exploitation for Privilege Escalation | LegacyHive PoC exploiting Windows User Profile Service
T1102
Web Service | Google Gemini CLI abused as a C2 and hacking agent by "bandcampro"
T1036
Masquerading | CrashStealer malware posing as Apple's CrashReporter to steal credentials

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft — SharePoint Server: Actively exploited zero-day vulnerabilities — SecurityWeek

[P1 PATCH NOW]≤24h

Progress — ShareFile Storage Zones Controller: Zero-day vulnerability causing active disruption — SecurityWeek

[P1 PATCH NOW]≤24h

ServiceNow — AI Platform: Critical remote code execution (RCE) vulnerability — SecurityWeek

[P1 PATCH NOW]≤24h

Zoom — Desktop Client & SDK (Windows): Critical unauthenticated account takeover vulnerability — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately audit and update all dependencies on @asyncapi npm packages to remove compromised versions distributing credential-stealing malware.
2[P1] Patch Microsoft SharePoint Server instances immediately to mitigate the three actively exploited zero-day vulnerabilities highlighted by CISA.
3[P1] Apply security updates to Progress ShareFile Storage Zones Controller to resolve the active zero-day vulnerability causing service disruptions.
4[P1] Apply Mozilla Firefox updates to address critical vulnerabilities, including CVE-2026-15718, for which public exploit code exists.
5[P2] Avoid opening untrusted or unverified repositories in Cursor IDE on Windows until a patch is released for the git.exe execution vulnerability.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 17 Jul | ClickLock macOS Malware Kills Apps For Passwords Older → [SecurityIntel] 15 Jul | Record Microsoft Patch Tuesday Fixes Active Zero-Days
Powered by Buttondown, the easiest way to start and grow your newsletter.