Cybersecurity Threat Research ‘Weekly’ Recap. The recap highlights supply-chain abuse in npm ecosystems (ChainDrop/Shai-Hulud, keyv/cacheable compromises, and additional npm worm activity), alongside rising AI token jacking that steals API keys and drains AI credits while attackers increasingly weaponize AI and coding agents for pre-prompt execution. It also covers phishing and vishing extortion efforts (UNC6671, ScreenConnect lures, ARERA and pagoPA scams, FakeCaptcha infrastructure, and developer lures), targeted intrusions and malware such as APT37/NarwhalRAT and BINDCLOAK, and cloud/container abuse including fileless in-memory cryptojacking (Fileless XMRig) and direct-to-IP C2 that evades DNS monitoring. #ChainDrop #ShaiHulud #keyv #cacheable #UNC6671 #ScreenConnect #ARERA #pagoPA #FakeCaptcha #Xeno #BHAlert #RovoBlast #RAT37 #NarwhalRAT #BINDCLOAK #QuasarRAT #UltraVNC #Xctdoor #CRAT #XMRig #Nextjs #Sliver #FilelessXMRig
Supply Chain, Developer Ecosystems, and AI Tooling Abuse
- Self-propagating npm worms hit hundreds of packages, stole credentials, and spread via stolen tokens and GitHub Actions; ChainDrop / Shai-Hulud recap.
- Active npm compromise in keyv and cacheable namespaces used malicious preinstall hooks to steal cloud/CI secrets and republish infected packages; keyv/cacheable attack.
- Datadog reported another npm worm compromising popular packages and propagating through npm, GitHub, and cloud environments; npm worm analysis.
- AI token jacking is rising as attackers steal API keys and burn through AI credits using gray-market proxy services; token jacking report.
- Threat actors are increasingly weaponizing AI for malware development, credential theft, and exploit workflows; Talos AI abuse study.
- Trusted coding-agent projects can execute attacker code before the first prompt via MCP and PATH manipulation; pre-prompt execution paths.
- Elastic showed how to triage AI-generated bug bounty reports at scale with human-in-the-loop automation; HackerOne triage system.
Phishing, Vishing, and Social Engineering Campaigns
- UNC6671 continues extortion via vishing, AiTM theft, and SaaS exfiltration across multiple brands; UNC6671 activity.
- Fake update and app-store themed lures delivered ScreenConnect remote access payloads at scale; ScreenConnect phishing campaign.
- CERT-AGID disrupted phishing using ARERA refund lures to steal personal and financial data; ARERA phishing.
- Italy-themed fraud abused Polizia di Stato and pagoPA to trick users into paying fake fines; pagoPA scam.
- Fake CAPTCHA PDFs were used as traffic distribution infrastructure to route victims to malware and scam pages; FakeCaptcha operation.
- Fake AI/dev tools delivered a NodeJS infostealer through ClickFix and trojanized GitHub repos; developer lure campaign.
- Gaming forums and Discord were used to spread a Xeno Roblox stealer with broad account and wallet theft features; Xeno malware.
- Bahrain users were targeted with a fake BH Alert Android app that stole credentials and persisted via accessibility abuse; Octagon Android threat.
AI Platforms, SaaS, and Coding-Agent Risk
- RovoBlast showed a one-click attack against Atlassian Rovo that could leak data across connected SaaS tools; Atlassian Rovo flaw.
- Elastic observed macOS developer endpoints where coding agents, tunnels, and LaunchAgents enabled stealthy persistence and access; coding-agent tunnel findings.
- Sysdig demonstrated agentic vulnerability management to turn thousands of findings into one approved fix; agentic vuln management.
- Elastic benchmarked agentic SOC workflows to evaluate LLMs on real security tasks and tool use; agentic SOC benchmarking.
- Acronis focused on agent health and self-recovery for MSP visibility across RMM, backup, EDR, and remote access; MSP agent health.
Malware, RATs, and Targeted Intrusions
- APT37 resurfaced with NarwhalRAT in a new campaign; APT37 / NarwhalRAT.
- Xctdoor activity in Korea was linked to earlier CRAT cases and Lazarus-style tradecraft; Xctdoor analysis.
- Larva-24009 continued LNK phishing with PowerShell backdoors, QuasarRAT, and UltraVNC; Larva-24009 phishing.
- BINDCLOAK, a modular Windows backdoor, was used against Middle East government entities; BINDCLOAK report.
- A Russian-speaking access broker ran initial access sales and later used Sliver for targeted collection; access broker operation.
- July’s broader attack landscape featured RATs, stealers, and account-takeover campaigns across multiple regions; July cyberattacks roundup.
Cloud, Container, and Infrastructure Abuse
- Fileless XMRig cryptojacking hid in memory inside containerized Next.js apps with persistence and anti-removal defenses; cryptomining analysis.
- Nearly half of malware C2 observed by Unit 42 connected direct to IP, bypassing DNS visibility; direct-to-IP malware report.
- July attacks on water and wastewater systems highlighted exposed PLCs, HMIs, and weak remote access as key risks; water infrastructure review.
- July’s broader security briefing also tracked ransomware, tenant takeover abuse, and AI-focused breaches; July 2026 briefing.