Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-11 and was added to the RWP archive on 2026-09-07.

IT Intelligence · IT

Early August was npm worms, ClickFix on Mac, and N-central measured in hours

Week of 4–11 August 2026. ChainDrop self-propagated in npm. macOS ClickFix grew a fingerprint gate. Storm-1175 was on N-central before most MSPs finished reading the advisory.

RWP Ventures · 2026-09-07 · event 2026-08-11 · 2 min read · priority 8.3

Executive summary

FACT: The first full week of August stacked three different supply-and-access stories. ChainDrop (4 August): npm worm with postinstall, treated by Microsoft and Unit 42 as self-propagating supply chain — sibling of Shai-Hulud, not a merge. macOS ClickFix (5 August): look-alike domains, fingerprinting so scanners saw a blank page, MacSync/AMOS. DeadLock (10 August): Rust encryptor, Polygon contract plus HTML chat, 80+ leak-site names by July in Microsoft's telling. Overlay: CVE-2026-18577 on N-central hit KEV; Microsoft had Storm-1175 (StormEncryptor) using it within hours, AnyDesk/SimpleHelp, LSASS. CISA also rushed Langflow and related KEVs on a three-day clock in early-August recaps.

ASSESSMENT: Developers, Mac users, and MSPs were three separate queues. The connecting tissue was trusted install paths (npm, “CAPTCHA,” RMM).

The week in one assessment

If your software factory, your endpoints, and your MSP console are three teams, this week punished that org chart.

1. Most important development

N-central 18577 + Storm-1175 speed. An RMM auth bypass with hours-to-ransomware is worse than another npm headline.

2. Active exploitation

CONFIRMED 18577 KEV.

REPORTED Storm-1175 exploitation hours after disclosure.

CONFIRMED as research/reporting: ChainDrop, ClickFix, DeadLock Microsoft notes.

3. Threat actor / campaign activity

Storm-1175/Medusa line. DeadLock as a new-ish RaaS with on-chain negotiation. ClickFix operators are crimeware, not a named APT in the Microsoft Mac note.

4. Vulnerabilities to prioritize

N-central. Langflow if CISA listed it that week. npm ignore-scripts in CI. Browser updates for ClickFix landing pages will not save a user who pastes Terminal commands.

5. Identity / cloud / enterprise

RMM admin takeover is domain-wide identity. DeadLock's HTML negotiation desk is a process problem for IR, not a CVE.

6. Ransomware / criminal activity

StormEncryptor via RMM. DeadLock leak-site volume. Do not call DeadLock ICS malware.

7. Defensive priorities

  1. N-central patch + internet exposure.
  2. npm lockfiles / ignore-scripts.
  3. Mac users: ClickFix tabletop (never paste from a CAPTCHA).
  4. DeadLock: backups and identity, not a Polygon-specific control.

8. What changed from last week

npm worm + Mac ClickFix arrived; RMM KEV became a timed Medusa story. Patch Tuesday had not yet shipped (11 August).

9. What we are watching next

August Patch Tuesday / Lazarus AFD.sys. More N-central CVEs.

10. RWP assessment

Confidence: High on the three Microsoft threads and the KEV. This week is the prologue to the 18 August and September RMM weeks.

Historical intelligence backfill of the week ending 11 August 2026; added 7 September 2026.

Sources

  1. Microsoft — ChainDrop npm worm (4 August 2026)
  2. Microsoft — macOS ClickFix fingerprint gate (5 August 2026)
  3. Microsoft — DeadLock ransomware Polygon/HTML chat (10 August 2026)
  4. Telefónica Tech — Storm-1175 on N-central CVE-2026-18577
  5. CISA KEV — N-able N-central CVE-2026-18577