Weekly review

ThreatNoir Afternoon Brief — August 4

2026-08-04Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — August 4, 2026

The threat landscape on August 4, 2026, presents multiple critical risks spanning supply chain attacks on foundational npm packages, privilege escalation vulnerabilities in hosting control panels, decades-old infrastructure exposure, and sophisticated malware delivery campaigns. Organizations face urgent remediation priorities across development, hosting, and data center environments.

Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

An active supply chain compromise is affecting widely used npm packages in the keyv and cacheable namespaces, with at least ten packages published on August 4, 2026, containing malicious preinstall hooks. The affected packages collectively account for tens of millions of weekly downloads, and new trojanized versions continue appearing in real time. Source: Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack

The compromise exploits the maintainer account (Jaredwray) and delivers malicious code through a setup.mjs preinstall hook that downloads a standalone Bun runtime and executes an obfuscated second stage payload. The malware harvests cloud and CI credentials including AWS, GCP, and Azure keys, HashiCorp Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC tokens, and npm tokens. The payload then republishes trojanized versions of other packages using stolen npm credentials, enabling self-propagation across the ecosystem.

The malware exfiltrates stolen credentials to threat actor GitHub repositories and over DNS, while planting autostart hooks in .claude and .vscode directories to compromise developers who clone affected repositories. Affected packages include keyv@6.0.0, cacheable@2.5.1, cacheable-request@13.0.20, flat-cache@6.1.24, and multiple @cacheable scoped packages. Organizations should rotate all credentials reachable from compromised hosts, revoke npm and GitHub tokens, and audit for unexpected package versions and repositories created on August 4, 2026.

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has released a security patch addressing a critical vulnerability tracked as CVE-2026-58048 (CVSS 9.4) that allows authenticated hosting customers to execute SQL commands in the database's root context. The flaw enables privilege escalation across the boundary between individual cPanel accounts and the server's administrative database identity. Source: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

The targeted security release patches this database vulnerability alongside two additional routes for account boundary bypass (CVE-2026-58047). Hosting providers and customers running affected cPanel versions should prioritize patching to prevent unauthorized database access and potential lateral movement within shared hosting environments.

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Over 24,000 internet-accessible server-management interfaces are disclosing authentication hashes before login, exposing thousands of data centers to potential compromise. The vulnerability stems from a decades-old flaw in BMC (Baseboard Management Controller) systems. Source: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

The flaw, tracked as CVE-2013-4786, demonstrates the persistent risk posed by legacy infrastructure components that remain unpatched despite years of public disclosure. Organizations operating data centers should conduct immediate inventory of internet-exposed IPMI and BMC interfaces and implement network segmentation to restrict access to these critical management systems.

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service operation codenamed DOUBLECUP is leveraging ClickFix social engineering lures to stage malware-laden PNG images in victims' browser caches, ultimately delivering the CountLoader malware and a previously undocumented remote access trojan called DeviceManager. Source: DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

The attack chain begins with ClickFix lures that trick users into clicking malicious links, which stage steganographic PNG images in the browser cache. The first stage payload retrieves the hidden content from these cached images and executes the second stage, establishing persistence and delivering full remote access capabilities. The infrastructure associated with this campaign includes IP address 213.139.77.109. Organizations should educate users on ClickFix tactics and monitor for suspicious PNG files in browser cache directories.

The afternoon's threat intelligence reveals a convergence of attack vectors targeting development pipelines, hosting infrastructure, legacy data center systems, and end-user endpoints. Immediate action is required across supply chain security, patch management, and infrastructure hardening initiatives.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
Malware3
  • DeviceManager
    Previously undocumented remote access trojan delivered via DOUBLECUP; uses EtherHiding for C2 resolution
  • CountLoader
    Malware payload delivered by DOUBLECUP with variants for Windows and macOS
  • DOUBLECUP
    Russian loader-as-a-service distributing CountLoader and DeviceManager RAT
IP Address1
  • 213.139.77.109
    Open directory hosting DOUBLECUP license panel testing files