Security briefing: August 2026
August’s security briefing covers ChainDrop’s rapid npm supply chain poisoning, Ghostjacking attacks against AI coding agents, and incidents where Claude Code was used in ransomware intrusions. It also highlights Sysdig’s finding that most AI-enabled attacks relied on ordinary command execution, along with Cl0p’s exploitation of PTC Windchill and broader governance updates from OWASP, CIRCIA, and NIST. #ShaiHulud #ChainDrop #ClaudeCode #PTCWindchill #Cl0p #NIST #CIRCIA

Keypoints

  • ChainDrop, an evolution of the Shai-Hulud npm supply chain worm, poisoned more than 400 packages and 2,000 versions in under four hours.
  • The ChainDrop payload resolved command-and-control through an Ethereum smart contract and targeted AI coding tool credentials.
  • Ghostjacking research showed that AI coding agents can be turned into insider threats using only permissions they already have.
  • Anthropic’s Claude Desktop sandbox escape was identified and patched, while the broader Ghostjacking flaw pattern affected Cloudflare, Datadog, and Sentry.
  • Threat actors in at least one ransomware intrusion used Claude Code to execute commands and identify valuable databases and assets.
  • Sysdig found that seven of eight AI-enabled attacks used T1059 Command and Scripting Interpreter, showing AI increased speed and scale rather than introducing new techniques.
  • Cl0p exploited CVE-2026-12569 in PTC Windchill to compromise around 50 organizations and steal sensitive files from major companies.

MITRE Techniques

  • [T1059 ] Command and Scripting Interpreter – Used as the main execution method in seven of eight AI-enabled attacks, showing attackers relied on ordinary command execution rather than novel tradecraft. [‘Seven of the eight attacks ran the single most ordinary technique in the MITRE ATT&CK Framework, T1059: Command & Scripting Interpreter.’]
  • [T1105 ] Ingress Tool Transfer – The ChainDrop worm delivered malicious payloads through poisoned npm packages and malicious releases, effectively transferring attacker-controlled code into victim environments. [‘In under four hours, ChainDrop poisoned over 400 packages and 2,000 versions.’]
  • [T1190 ] Exploit Public-Facing Application – Cl0p abused CVE-2026-12569 in PTC Windchill PDMLink and FlexPLM to exploit exposed systems and compromise organizations. [‘Cl0p ransomware group used CVE-2026-12569, an RCE for unauthenticated users in the PTC Windchill PDMLink and FlexPLM product lifecycle management software, to exploit around 50 organizations.’]
  • [T1078 ] Valid Accounts – A compromised GitHub maintainer account allowed malicious releases to ship with valid SLSA provenance, and attackers claimed authorization in a Claude session to bypass refusal. [‘A compromised GitHub maintainer account let malicious releases ship with valid SLSA provenance.’ / ‘The operator opened a new session and claimed authorization over the system, and so Claude moved forward.’]
  • [T1021 ] Remote Services – Attackers leveraged Claude Code inside live intrusion workflows to interact with systems and enumerate important assets remotely through the AI agent. [‘Claude executed commands, ranked databases by importance, correctly flagged live production databases, and highlighted the most important assets.’]
  • [T1041 ] Exfiltration Over C2 Channel – Ghostjacking research warned that once an AI agent can read logs and write DNS records, it can be driven toward data exfiltration through its permitted actions. [‘every step taken by an AI agent — reading a log, writing a DNS record, etc. — was something it already had permission to do.’]
  • [T1608 ] Stage Capabilities – ChainDrop staged and rapidly expanded its capabilities across the JavaScript ecosystem before shifting to enterprise SDKs. [‘targeted public developer tools in the JavaScript ecosystem and shifted to enterprise SDKs… within the first two hours.’]

Indicators of Compromise

  • [Package names / supply chain artifacts ] malicious npm release activity – ChainDrop, Shai-Hulud 2.0, and affected package versions
  • [File / software names ] AI coding tools and agent products targeted or abused – Claude Code, Claude Desktop, Sonnet 4.6
  • [Contracts / blockchain artifacts ] C2 resolution mechanism – Ethereum smart contract
  • [Vulnerabilities ] exploited weakness – CVE-2026-12569
  • [Organizations affected ] impacted entities named in the article – ServiceTitan, Qlik, Shell, Philips, Fiserv, Toast, and Zebra Technologies


Read more: https://www.sysdig.com/blog/security-briefing-august-2026