800 Malicious npm Packages & a GitHub Issue That Reached CI (08/07/2026)
- › Nearly 800 malicious npm packages went up under machine-generated names, delivering a cross-platform remote access trojan and infostealer to Windows, Mac, and Linux.
- › N-able confirmed attackers turned N-central admin access into a route into customer networks, and shipped a second hotfix.
- › A GitHub issue opened by an account with no repository privileges executed code on the continuous integration runners behind Anthropic's and Google's own coding-agent repositories.
- › Malware in a signed-in Windows session can use the victim's Windows Hello for Business key to authenticate to Entra ID and establish longer-term access.
- › An 18-year-old Linux SCTP flaw lets a local user gain root and escape a container.
Three of today’s five stories are about the machinery that builds and manages your software rather than the software itself. Attackers published nearly 800 packages under generated names, opened a GitHub issue that ran code on the continuous integration runners of the companies who make coding agents, and turned a remote management console into a path into customer networks. None of it required a product vulnerability in the thing being protected.
Top 5 Critical Security Alerts
1. Nearly 800 Malicious npm Packages Go Up at Once
A cluster of close to 800 packages was published to the npm registry delivering cross-platform malware to Windows, Mac, and Linux. The names appear machine-generated, squatting on plausible-looking strings rather than typo variants of specific popular packages. The payload combines a remote access trojan with an infostealer. The Hacker News
Operator Note: This is the third npm campaign in a week, after ChainDrop and the Alibaba-targeted cluster. Generated names defeat the mental check developers actually run, which is whether a name looks like the package they meant to type. Pin your dependencies and require review for any new direct dependency.
2. N-able Confirms Attackers Reached Customer Networks
N-able confirmed that attackers turned administrative access on N-central servers into a route downstream into customer networks, and shipped a second hotfix. Customers are being told to patch again. The Register
Operator Note: Four days ago this was an authentication bypass with a KEV listing. Today it is a confirmed downstream compromise with a second patch. If you consume managed services, the question for your provider is no longer whether they patched but what they found when they looked.
3. A GitHub Issue Reached the Coding Agents’ Own CI Secrets
Novee Security found that a GitHub issue opened by an account with no repository privileges was enough to execute code on the continuous integration runners behind Anthropic’s and Google’s coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. The Hacker News
Operator Note: An issue is untrusted input from a stranger, and a coding agent wired into continuous integration treats it as work to do. If you have given an agent repository access, find out today what triggers it and what credentials the runner holds.
4. Windows Hello Keys Become a Persistence Mechanism
Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key to authenticate to Microsoft Entra ID, then establish longer-term access. The Hacker News
Operator Note: This is the same shape as the Unit 42 passkey work we covered Monday. A credential bound to hardware still answers to whatever code is running as the signed-in user, so endpoint compromise remains the event that ends the conversation.
5. An 18-Year-Old Linux Flaw Gives Root and a Container Escape
A flaw in the Linux SCTP implementation, present for 18 years, allows a local user to gain root and escape a container. The Hacker News
Operator Note: Container escapes reprice every multi-tenant assumption in your environment. If you run untrusted or semi-trusted workloads on shared kernels, this belongs in this week’s patch cycle rather than next month’s.
Additional Security Alerts
Threat Intelligence
- A former NSA chief says water controllers do not belong online: The remarks follow the suspected Iranian campaign against US water utilities, which we covered in exposed PLCs. The Register
- Microsoft 365 phishing goes after payroll and finance mail: An adversary-in-the-middle campaign takes over accounts specifically to find the people who move money. The Hacker News
- Ransomware climbed again in July: Finance, technology, and healthcare took the heaviest targeting after a quieter second quarter. Infosecurity Magazine
Security Breaches & Incidents
- Framework notifies all customers of a breach: Attackers accessed names, email addresses, phone numbers, and physical addresses. TechCrunch
- Levi Strauss loses corporate data through three employees: The company says attackers used social engineering against three staff to reach data on their machines. BleepingComputer
- North Carolina Ports confirms operational disruption: The port authority acknowledged the cyberattack is affecting operations. BleepingComputer
Vulnerabilities
- NatJack hijacks TCP sessions through NAT tables: The technique also enables DNS spoofing by manipulating network address translation state. The Hacker News
- A WordPress pre-auth flaw reaches PHP execution: The cross-site scripting bug requires no authentication and can lead to code execution. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.