ChainDrop npm Worm, N-central in KEV & $130M Wallet Theft (08/04/2026)

August 4, 2026
ChainDrop npm Worm, N-central in KEV & $130M Wallet Theft (08/04/2026)
Key Intel / TL;DR
  • ChainDrop compromised at least 868 npm packages across 1,381 versions, reaching roughly 2 billion monthly downloads, after attackers took the Keyv maintainer's GitHub account.
  • The worm runs during npm install, steals cloud and build pipeline credentials, and plants hooks in Claude Code and VS Code so it survives a package rollback.
  • CISA added the N-able N-central authentication bypass to its Known Exploited Vulnerabilities catalog after confirmed customer compromises.
  • Coldcard losses passed $130 million, and a phishing campaign now targets worried owners with a fake security audit that installs ScreenConnect.
  • Device code phishing rose 1,500% in 2026 and the Greatness phishing-as-a-service kit added it, putting the technique in reach of low-skill operators.

Today’s stories are about the things inside your perimeter that were installed on purpose. A worm rode into build pipelines through packages your developers already depended on, then wrote itself into their editors so removing the package does not remove the problem. Attackers reached managed endpoints through the remote management tool your team uses to fix things, and CISA made the federal deadline three days. The Coldcard owners who read last week’s news are now getting phished with an offer to audit their wallet.

Top 5 Critical Security Alerts

1. ChainDrop Turns 868 npm Packages Into a Worm

Attackers compromised the GitHub account of the Keyv maintainer and used it to seed a self-propagating payload. Aikido researchers counted at least 868 compromised packages across 1,381 versions, including Keyv, Cacheable, flat-cache, and file-entry-cache, together drawing roughly 2 billion downloads a month. Anyone running npm install against an affected version executed setup.mjs before the install finished. It harvests GitHub tokens, npm tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and Stripe, Slack, and Azure credentials, then infects packages belonging to any maintainer whose machine it lands on. Deliveroo, Picsart, Qlik, and ServiceTitan had associated packages caught in it. BleepingComputer

Operator Note: It plants hooks in Claude Code and VS Code, so rolling back the package leaves the persistence in the developer’s editor. Treat an affected build host as compromised: rotate every reachable token, rebuild from clean backups, and check the editor config, not just the lockfile.

2. CISA Puts N-able N-central on the KEV List

CISA added the N-able N-central authentication bypass to its Known Exploited Vulnerabilities catalog after reports of active exploitation and confirmed customer compromises. Sophos reports that successful exploitation ends in the attacker deploying their own remote monitoring and management tooling on the systems the server manages. The Hacker News

Operator Note: This is the flaw we covered Monday, now with federal agencies given three days to fix it. If you are an MSP or you buy from one, the question to ask today is what ran on your endpoints between the first incomplete patch and the second one.

3. Coldcard Losses Pass $130 Million, and Now the Phishing Starts

Blockchain monitoring firms put total losses from the Coldcard firmware flaw above $130 million, up from the $88.6 million reported over the weekend. Separately, a phishing campaign is trading on owner anxiety about the disclosure, offering a security audit of the wallet and installing ScreenConnect remote access software instead. TechCrunch

Operator Note: The second wave of any public breach is the help. Attackers know exactly who is worried and what they are worried about, and a vendor that just disclosed a flaw is the easiest brand in the world to impersonate that week.

4. Device Code Phishing Is Up 1,500% and Now Sold as a Service

Device code phishing rose 1,500% in 2026 while vishing doubled, according to research covered by Dark Reading, and the techniques share a property that explains the growth: they sidestep entrenched controls and leave less evidence behind. The commercial Greatness phishing-as-a-service kit added device code support, which abuses the legitimate OAuth 2.0 device authorization flow to capture tokens after the victim approves a real Microsoft prompt. Dark Reading

Operator Note: Blocking the device code flow in Conditional Access takes about ten minutes and removes the whole technique for accounts that never legitimately need it. Almost nobody in your organization does.

5. A Long-Running Campaign Is Installing ScreenConnect Everywhere

Researchers detailed a multi-wave campaign using Adobe and Zoom update lures, business document reviews, and fake system maintenance utilities to deliver ScreenConnect for persistent remote access. Dark Reading’s coverage of the related Smoke#Screen activity describes rotating payloads and varied social engineering pretexts against the same goal. The Hacker News

Operator Note: Legitimate remote management software is signed, allowlisted, and invisible to most detection stacks, which is exactly why they keep choosing it. Inventory which remote access tools are approved in your environment and alert on every other one by name.

Additional Security Alerts

Threat Intelligence

  • XCSSET returns through Xcode projects: A new variant targets macOS developers via compromised Xcode projects, continuing a pattern of going after the build environment rather than the product. BleepingComputer
  • WhatsApp accounts hijacked through Linked Devices: A scam abuses the legitimate linked devices feature to attach an attacker’s session to the victim’s account. Infosecurity Magazine
  • Cloud and SaaS are now the top targets: Attacker focus has shifted to cloud and SaaS environments over on-premises infrastructure. Infosecurity Magazine

Cloud & Network Security

  • TP-Link patches Omada zero-touch provisioning flaws: The bugs allow attackers to breach networks through the provisioning process, which runs before anyone has configured anything. BleepingComputer
  • A critical cPanel flaw reaches database root: Hosting customers could run SQL as the database root user, crossing the tenant boundary on shared infrastructure. The Hacker News

Emerging Security Technologies

  • OpenAI and Anthropic agents ran against real targets in cyber tests: Both companies’ agents were pointed at real people and systems during controlled testing, and the results are being published. BleepingComputer
  • Guardrail bypass is not a specialist skill: The Register reports that getting around model safety controls is within reach of low-skill attackers, which matters more for volume than for capability. The Register
  • AI notetakers are a live surveillance path: Researchers showed AI meeting assistants being used to listen in on government and corporate video calls. Dark Reading

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)