A Clean Source Repo Does Not Clear ChainDrop's Published npm Tarball
Microsoft and Snyk corroborate a ChainDrop npm tampering mechanism that can make a published package differ from its source repository, putting build systems and reachable secrets at risk; StepSecurity alone reports the campaign’s scale. Practitioners rejected a blanket “ChainDrop first” ranking. The open question is whether the tarball reached a runner, because repository review alone cannot answer it.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
What the panel logged · 5
A clean source repository cannot clear an npm package; responders must verify the published tarball itself.
PaperCut evidence must be captured before patching because attackers can chain CVE-2026-81578 and CVE-2026-82078.
TeamCity CVE-2026-63077 can expose CI-connected secrets and artifacts, but exposure does not prove release compromise.
Sansec reproduced StyleSmuggler on Magento Open Source 2.4.7–2.4.9, while affected Adobe Commerce versions remain unverified.
Evidence supports a Chinese-speaking operator, not PRC state attribution; AI acceleration remains plausible but unmeasured.
What to do about it · 5
- Action 01UpdatedcriticalCloud Security
Pause ChainDrop-intersecting npm builds, disable affected OIDC trust, revoke reachable secrets, preserve CI evidence, and rebuild runners where execution cannot be excluded.
- Action 02UpdatedcriticalDefense Architect
Restrict affected PaperCut NG/MF, preserve evidence, then apply EPR2 or a vendor-confirmed superseding release.
- Action 03UpdatedcriticalThreat Hunter
Remove vulnerable TeamCity servers from public reach, preserve server and agent telemetry, and upgrade to a vendor-fixed release.
- Action 04UpdatedhighOSINT Investigator
Hunt Magento Open Source 2.4.7–2.4.9 for StyleSmuggler GraphQL activity and theme changes; do not deploy unofficial patches.
- Action 05UpdatedhighThreat Hunter
Inspect exposed Office Automation systems for unexpected ASPX uploads and credential access associated with the reported Chinese-speaking campaign.
Research trail
This is a busy afternoon, but not a CVE roll call.
The sharper lead is ChainDrop: package propagation, stolen publishing tokens, and cloud credentials put downstream builds at immediate risk. TeamCity and PaperCut follow because exploitation is confirmed; StyleSmuggler needs evidence-tested scrutiny.
We’ll also separate what AI changed in the Asian intrusions from ordinary web-shell and credential-theft tradecraft.
Chrome, SonicWall, Trezor, and predictive OT escalation stay monitored unless there is a genuine delta. First, let’s establish whether ChainDrop warrants pausing builds tonight.
Open this page on desktop for the full visual network.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Action 1
Dispatch Parallel
Assess ChainDrop’s reported compromise of 444 npm packages and 2,212 malicious iterations. Separate verified mechanics from single-source claims; explain how distributed-tarball tampering and stolen publishing tokens affect source-review assumptions. Make a fi...
Tomas IlicSupply-chain trust lens
Moderator assignment
Assess ChainDrop’s reported compromise of 444 npm packages and 2,212 malicious iterations. Separate verified mechanics from single-source claims; explain how distributed-tarball tampering and stolen publishing tokens affect source-review assumptions. Make a firm 30-minute CISO call: when should builds be paused, what evidence should be preserved, and which credentials must be rotated first?
Response
FACT: The exact 444 packages / 2,212 versions in under four hours count comes from StepSecurity and should remain a single-source measurement. Independent research nevertheless corroborates the core mechanism: Snyk found malicious payloads inside published keyv tarballs, while Microsoft reports the worm used stolen npm tokens to download legitimate tarballs, inject a preinstall loader, increment versions, and republish them. UNKNOWN: the complete package/version inventory and downstream installation count have not been independently reconciled.
A clean GitHub repository is no clearance signal here. Microsoft found malicious registry versions without corresponding commits, tags, pull requests, or releases. A stolen publishing token makes a tampered tarball appear under an authorized maintainer identity. Therefore, review the artifact actually resolved by npm—including its hash, contents, provenance and install scripts—not merely the linked source tree.
My 30-minute CISO call:
- Pause now: all npm builds or deployments whose dependency graph intersects suspected versions, resolved packages during the incident window, permits floating versions, or ran install scripts on secret-bearing workers. Keep demonstrably hash-pinned, isolated builds running only after tarball verification.
- Preserve first: lockfiles and SBOMs; downloaded tarballs and npm caches;
node_modules; registry metadata and integrity values; CI logs, artifacts, runner images and volatile evidence; process/network telemetry; and the corresponding source commit, tag and workflow definition. - Rotate first: revoke npm publishing tokens and disable affected publishing workflows/OIDC trust, then rotate GitHub PATs, app tokens and SSH/deploy keys. Next rotate every cloud, container-registry, Kubernetes and Vault credential reachable from systems where an affected package executed. Rebuild those systems from trusted artifacts—package removal alone is insufficient.
Alex MercerExploit feasibility lens
Moderator assignment
Analyze TeamCity CVE-2026-63077 as an exploited CI control-plane flaw. Identify exploit preconditions, likely post-compromise reach into secrets/artifacts/releases, evidence that should trigger assume-compromise, and the action sequence for internet-exposed TeamCity tonight. Distinguish confirmed Cadence impact from plausible downstream risk.
Response
Halil, this chain closes quickly. Fact: CVE-2026-63077 is unsafe deserialization reachable through TeamCity’s agent-polling protocol; it bypasses authentication and runs commands as the TeamCity server process. Preconditions are simply network reachability and a vulnerable release—authentication is not required. Fixes are in 2025.11.7 and 2026.1.3. That is not CVSS theater; it is an exposed front door with execution behind it.
Assessment: server-level execution can plausibly expose project secrets, agent credentials, artifact repositories, deployment tokens, signing infrastructure, and release workflows—but only where the TeamCity service identity or connected agents possess that access. Do not declare releases compromised without evidence. Trigger assume-compromise if logs show the exploit’s characteristic deserialization exception traces, TeamCity-spawned payloads from temporary directories, unexpected plugins/web shells, unexplained build or administrator changes, or missing/tampered logs. An internet-exposed unpatched server during the exploitation window warrants forensic containment, but exposure alone still is not proof.
Tonight: remove it from internet access; preserve memory, disks, teamcity-server.log, audit records, build history, plugins, and agent telemetry; then patch or apply JetBrains’ security plugin. From clean systems, rotate TeamCity credentials plus every repository, artifact, cloud, signing, and deployment secret TeamCity could reach. Audit projects, build steps, users, tokens, agents, artifacts, and releases; rebuild the server from trusted media if compromise evidence appears. Verify affected artifacts before resuming publication.
Confirmed Cadence impact: JetBrains says api.cadence.jetbrains.com was successfully exploited, took it offline on August 24, invalidated Cadence plugin access tokens, and disclosed exposure of names and email addresses. Unknown: publicly cited evidence here does not establish malicious source modification, poisoned artifacts, stolen signing keys, or compromised customer releases. Those are credible downstream risks, not confirmed Cadence outcomes.
Lena HartmannThreat intelligence lens
Moderator assignment
Assess the Chinese-speaking campaign targeting Asian government, education, healthcare, and industrial organizations. What supports the language/infrastructure linkage, what does not support state attribution, and did Claude, DeepSeek, or Qwen materially change capability versus conventional Office Automation exploitation, ASPX upload, and credential theft? End with collection priorities, not an AI headline.
Response
Chronologically, Simplified-Chinese operational notes, a pivot from TencShell infrastructure, and five workspaces sharing one SOCKS endpoint support linkage to a Chinese-speaking operator. My ICD 203 attribution: moderate confidence on operator language/continuity; low confidence on PRC state sponsorship. The reporting provides no corroborating state-tasking evidence or established MITRE G-number linkage.
SecFlow coordinated Claude, Qwen, and DeepSeek, but material capability uplift is unproven. Confirmed success still relied on public-facing application exploitation (T1190), ASPX web-shell upload (T1505.003), and SAM/SYSTEM credential extraction (T1003.002). An AI-generated Shiro false positive reportedly drove 27 failed tests; without comparative timing, success-rate, or scale data, I assess any capability gain with low confidence.
Collection priorities: passive-DNS and certificate history around the SOCKS/TencShell pivots; model-agent logs with timestamps and operator interventions; exploit provenance; full victim chronology; and infrastructure or tooling overlaps with a recognized G-number.
James OkaforDefensive response lens
Moderator assignment
Build tonight’s defensive sequence for PaperCut CVE-2026-81578/CVE-2026-82078, while briefly contrasting StyleSmuggler risk on Magento/Adobe Commerce. For PaperCut, specify containment, evidence preservation, patching, and compromise validation for schools. For StyleSmuggler, state what must be verified before treating the source-pack claim as equally urgent. Make explicit what cannot wait until Monday.
Response
Critical—tonight: PaperCut’s two flaws are actively exploited and can be chained for unauthenticated RCE; Emergency Patch Release 2 is available for NG/MF 24–26 on Windows, Linux, and macOS. Immediately restrict the application-server web interface to school IT/VPN ranges. If exploitation is suspected, isolate the server without powering it down; preserve memory, VM snapshots, server.log, derby.log, OS/EDR telemetry, firewall/DNS records, and configuration before remediation. Then stage Release 2 briefly against printing, authentication, and device workflows before production deployment. Internet restriction, evidence capture, and patching exposed servers cannot wait until Monday.
High—before reopening access: Hunt for hexadecimal Java content, lib/Udydn.class, unexplained deletion of server.log or derby.log, privileged-account creation, Meterpreter-related Java payloads, registry-hive collection, and searches of PaperCut configuration for password, secret, ldap, bind, or token. Confirm the installed patch, review administrative changes, rotate exposed LDAP/service secrets where execution or configuration access is found, and validate affected endpoints for lateral movement. For StyleSmuggler, the source pack alleges an exploited Magento/Adobe Commerce flaw, but I found no visible vendor advisory, CVE, fixed version, or independently verified detection guidance here. Before assigning equal urgency, verify those items plus affected versions, confirmed in-the-wild exploitation, trustworthy IOCs, and whether the store contains an unauthorized or modified theme. Preserve suspicious theme files and logs tonight, but do not deploy an unverified fix.
The npm compromise changes a core trust assumption: clean source repositories do not establish clean packages. The precise 444-package and 2,212-version count remains a StepSecurity-only measurement, but independent reporting supports the underlying mechanism—stolen publishing tokens, modified registry tarballs, injected install scripts, and republishing under legitimate maintainer identities. The practical consequence is immediate: organizations must inspect the artifact actually resolved and installed, including hashes, provenance, contents, and lifecycle scripts. Builds intersecting suspected versions or the incident window should be paused while exposure is established.
TeamCity and PaperCut both demand action tonight, but exposure must not be confused with confirmed compromise. CVE-2026-63077 requires only network reachability to a vulnerable TeamCity release and permits unauthenticated execution as the server process. Internet-facing systems should be removed from public access, evidence preserved, and patched to 2025.11.7 or 2026.1.3. Deserialization traces, TeamCity-launched temporary payloads, unexpected plugins, unexplained administrative or build changes, and damaged logs justify an assume-compromise posture. PaperCut’s actively exploited chain similarly calls for immediate access restriction, volatile and log evidence capture, Emergency Patch Release 2 deployment, and hunting for the identified Java payload, log deletion, account creation, credential searches, and related post-exploitation activity.
On campaign attribution, the evidence supports a Chinese-speaking operator and infrastructure continuity at moderate confidence, not PRC state sponsorship. Nor is there yet persuasive evidence that Claude, Qwen, or DeepSeek materially improved operational capability; the successful activity still used conventional exploitation, web shells, and credential extraction, while comparative performance data are absent.
Three uncertainties now need sharper bounds: how far credentials exposed through poisoned npm installs could extend into cloud and delivery systems; whether StyleSmuggler has reliable version, CVE, exploitation, or mitigation evidence; and whether the AI orchestration changed attacker speed, scale, or success rather than merely workflow. Those are the next questions for the room.
Action 2
Dispatch Parallel
Using Tomas’s ChainDrop finding that affected install environments may have exposed AWS, Kubernetes, registry, GitHub, and Vault credentials, bound the cloud blast radius. Distinguish static secrets from OIDC/federated trust, name the first containment steps,...
Priya NatarajanCloud security lens
Moderator assignment
Using Tomas’s ChainDrop finding that affected install environments may have exposed AWS, Kubernetes, registry, GitHub, and Vault credentials, bound the cloud blast radius. Distinguish static secrets from OIDC/federated trust, name the first containment steps, and state when rebuilding a runner is mandatory rather than optional. Give a decision-ready sequence, not a generic credential-rotation list.
Response
Tomas’s finding defines potential reachability, not confirmed compromise. ChainDrop collected npm/GitHub tokens plus AWS, Kubernetes, and Vault credentials; Unit 42 also found code scraping live GitHub Actions runner memory for OIDC tokens and runner secrets. Bound exposure to environments where the malicious install hook actually executed, then map each recovered principal’s effective access: AWS roles/accounts and role-chaining paths, Kubernetes contexts and RBAC, registry repositories, GitHub repositories/environments, and Vault policies. Do not infer tenant-wide AWS compromise merely because an AWS credential was present.
- Stop identity minting first: quarantine affected self-hosted runners, suspend their workflows and deployments, and disable affected npm trusted-publisher or cloud OIDC trust relationships from a known-clean system. Federation has no permanent key to rotate—that is the feature and, during response, the joke. Restrict restored trust by repository, workflow, branch/ref, environment and audience rather than immediately reconnecting it.
- Then invalidate static secrets: revoke exposed AWS access keys and sessions, GitHub/npm/registry tokens, Kubernetes bearer tokens or client credentials, and Vault tokens. Rotate only secrets reachable by the compromised process, but inspect their subsequent use before restoring them. Microsoft specifically recommends revocation and rotation from a clean environment.
- Validate impact: use AWS control-plane logs, Kubernetes audit data, registry pull/push history, GitHub audit logs and Vault audit devices to distinguish merely exposed principals from principals actually used. Rebuild downstream images and artifacts produced after the first affected installation.
A runner rebuild is mandatory when ChainDrop’s install hook or second-stage payload executed on a persistent/self-hosted runner, when execution cannot be disproved, or when that runner could access host mounts, privileged containers, deployment credentials or signing material. Memory scraping means deleting node_modules is not an integrity recovery. For a genuinely single-use hosted runner that was destroyed after the job, there is no retained runner to rebuild, but its credentials must still be invalidated and its outputs rebuilt from trusted sources.
Rafael CostaOSINT exposure lens
Moderator assignment
Pressure-test the StyleSmuggler claim. Determine whether reliable evidence identifies a CVE, affected Magento/Adobe Commerce versions, vendor fix or mitigation, confirmed exploitation, and useful IOCs. Separate primary reporting from repeated secondary claims, then tell a commerce operator exactly what can be done tonight without inventing a patch.
Response
The reliable core is narrower than the headlines suggest. Primary research: Sansec says it reproduced unauthenticated RCE on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9. Disrex separately reports a compromise of a fully patched managed server on September 4. That supports real-world exploitation, but it does not establish every Adobe Commerce version as affected. I found no verified CVE assignment, Adobe advisory, vendor patch, or vendor mitigation for StyleSmuggler. Adobe’s surfaced CVE-2025-54236 release note concerns a different REST API issue.
For tonight: do not install an unofficial “patch.” If operationally viable, temporarily disable GraphQL; Sansec recommends that where its protective rules are unavailable. Search /graphql traffic for suspicious styles[...] parameters, isolate any matching host, and preserve volatile evidence before rebooting. Secondary reporting lists 247.cdnflare.xyz, 99.84.67.186, 88.216.72.181, SHA-256 e315687a1dfe61ef4a5a5642214db6d3b2b05d81391285eebc2af664641a26a7, /tmp/.kw_, and .gvfsd persistence paths. Treat those as hunting leads—not definitive proof—because the visible IOC list comes from secondary aggregation rather than Adobe.
Arjun PatelAI security lens
Moderator assignment
Lena assesses low confidence that Claude, Qwen, or DeepSeek materially improved the Chinese-speaking campaign because exploitation still used conventional T1190, ASPX web shells, and credential dumping, with at least one AI-generated false lead. Argue the strongest scenario in which that conclusion understates AI’s operational value. Then identify the telemetry or comparative metrics that would prove acceleration rather than mere tool use.
Response
Lena, the strongest countercase is not that AI invented new TTPs, but that it became a force multiplier for ordinary ones. Hunt.io reports SecFlow coordinating reconnaissance, exploitation, and reporting across Claude, Qwen, and DeepSeek workers. Separate reporting says the operation obtained Windows command execution through exposed web applications and deployed ASPX web shells. My assessment is that one operator could therefore run more targets and parallel workstreams than a conventional team—delegating enumeration, exploit adaptation, command generation, and documentation—even if every successful action still maps to familiar ATT&CK techniques. The 27 follow-up attempts triggered by one false result demonstrate wasted automation, but they do not disprove acceleration elsewhere.
To establish acceleration, we need timestamped agent trajectories correlated with server, endpoint, and network logs, then compared with the same operator or similarly skilled teams using identical tooling without agents. Measure:
- targets and concurrent sessions per operator-hour;
- median discovery-to-shell and shell-to-credential-access time;
- exploit variants produced and tested per hour;
- successful compromises, valid credentials, and exfiltrated data per operator-day;
- human interventions, false-positive branching, failed attempts, and rework;
- API/token cost and total labor per successful compromise.
Without that matched baseline, the evidence proves embedded AI use and successful conventional intrusion—not that AI materially increased campaign velocity or effectiveness.
Three boundaries are now clearer. For ChainDrop, exposed credentials indicate potential reach, not confirmed tenant-wide compromise. Scope begins with install environments where the malicious hook actually executed, then follows each principal’s effective permissions across AWS, Kubernetes, registries, GitHub, and Vault. Federated access requires a different first move from static secrets: quarantine affected self-hosted runners, suspend workflows and deployments, and disable the relevant OIDC or trusted-publisher relationships from a clean system so new identities cannot be minted. Static keys, tokens, and sessions should then be revoked. Restored federation must be narrowly constrained by repository, workflow, ref, environment, and audience rather than simply switched back on.
The StyleSmuggler evidence is materially narrower than broad claims imply. Sansec reports reproducing unauthenticated RCE on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9, while Disrex reports a fully patched managed server compromise. That supports a serious exploitation concern, but not universal Adobe Commerce exposure. We still lack a verified CVE, Adobe advisory, official patch, or vendor mitigation. For now, suspicious /graphql requests containing styles[...] merit investigation; potentially affected hosts should be isolated and volatile evidence preserved. Temporarily disabling GraphQL may be justified where operationally feasible, but unofficial patches should not be treated as authoritative. The published domains, IPs, hash, and persistence paths remain hunting leads drawn from secondary aggregation, not conclusive compromise indicators.
On AI-enabled operations, the strongest case is increased scale and concurrency rather than novel exploitation. Conventional web exploitation, ASPX shells, and credential access could still be accelerated through delegated reconnaissance, adaptation, command generation, and reporting. One false result spawning 27 follow-up attempts demonstrates automation waste, not the absence of gains elsewhere. Proving material acceleration will require timestamped agent activity correlated with host and network evidence and compared against a meaningful non-agent baseline.
The next step is to turn these qualified findings into operational decision rules: which builds to pause, which identities to disable or rotate, when rebuilding is warranted, and how commerce defenders should act without overstating uncertain evidence.
Action 3
Follow Up
Close the operational debate using the panel’s findings. Tomas and Priya say pause only intersecting npm builds, stop OIDC identity minting first, revoke reachable static credentials, and rebuild persistent runners where execution occurred or cannot be disprov...
James OkaforDefensive response lens
Moderator assignment
Close the operational debate using the panel’s findings. Tomas and Priya say pause only intersecting npm builds, stop OIDC identity minting first, revoke reachable static credentials, and rebuild persistent runners where execution occurred or cannot be disproved. Alex says exposed vulnerable TeamCity warrants containment and forensics, but exposure alone is not proof of downstream release compromise. Rafael confirms StyleSmuggler RCE reproduction on Magento Open Source 2.4.7–2.4.9 and one reported compromise, but no verified CVE, Adobe patch, or vendor mitigation. Your own PaperCut assessment requires restriction, evidence capture, EPR2, and hunting tonight. Rank these four subjects by immediate decision impact, keep each response lane separate, and state what a small security team does in its first two hours. Also identify one tempting overreaction to avoid for each subject.
Response
1—npm/CI identity: In the first two hours, stop OIDC identity minting, pause only builds intersecting affected packages/workflows, preserve CI and registry logs, and revoke static credentials reachable from those jobs. Rebuild persistent runners where execution occurred or cannot be excluded. Avoid: shutting down every build and rotating unrelated enterprise credentials.
2—PaperCut: Restrict school PaperCut interfaces to IT/VPN ranges, preserve memory, snapshots and logs, then apply EPR2—or a vendor-confirmed superseding emergency release—and hunt for dropped classes, child shells, remote-access tools and configuration access. Active exploitation against schools makes this a tonight action. Avoid: powering servers off or patching before evidence capture.
3—TeamCity: Remove exposed vulnerable instances from public reach, capture server/build/agent telemetry, preserve artifacts and patch to a validated fixed release. Pause releases only where logs show execution or integrity cannot be established; exposure alone does not prove downstream compromise. Avoid: declaring every prior artifact malicious.
4—StyleSmuggler: Reproduction on Magento Open Source 2.4.7–2.4.9 justifies checking exposed stores, theme integrity and web logs tonight. With no verified CVE, Adobe patch or vendor mitigation, preserve suspicious themes but do not deploy unofficial fixes. Avoid: taking every Commerce site offline based on one reported compromise.
The operational posture is now evidence-led rather than enterprise-wide containment. For ChainDrop, the first two hours focus on stopping OIDC identity minting, pausing only npm builds that intersect affected packages or workflows, preserving CI and registry telemetry, and revoking static credentials reachable from those jobs. Persistent runners should be rebuilt where malicious execution occurred or cannot be ruled out. That does not justify shutting down every build or rotating unrelated credentials.
PaperCut carries a separate, urgent sequence because active exploitation against schools makes it a tonight action: restrict interfaces to IT or VPN ranges, capture memory, snapshots, and logs, then apply EPR2 or a vendor-confirmed superseding emergency release. Hunting should cover dropped classes, child shells, remote-access tooling, and configuration access. For TeamCity, public exposure demands isolation, telemetry capture, artifact preservation, and a validated fixed release—but exposure alone does not establish downstream compromise. Release pauses should remain tied to observed execution or an inability to establish integrity, rather than treating every historical artifact as malicious.
One lane remains unresolved: the StyleSmuggler response is incomplete in the available record, so we cannot carry forward a verified Magento recommendation from it. More importantly, the actions for ChainDrop are clearer than its relative ranking. The next challenge is whether it truly belongs first in the opening two hours when the 444-package and 2,212-version estimate remains a single-source measurement and harmful effects still depend on local execution and reachable permissions. We now need to separate a sound containment playbook from the still-contestable claim that it outranks the other active threats.
Action 4
Challenge
Claim: ChainDrop/npm-CI identity should rank first in the first two hours. Counter-evidence: The 444-package/2,212-version scale is still a single-source measurement and local execution may be absent, whereas PaperCut and TeamCity have confirmed unauthenticate...
James OkaforDefensive response lens
Moderator assignment
Claim: ChainDrop/npm-CI identity should rank first in the first two hours. Counter-evidence: The 444-package/2,212-version scale is still a single-source measurement and local execution may be absent, whereas PaperCut and TeamCity have confirmed unauthenticated exploitation. A universal ranking risks diverting teams that do not use affected npm versions or runners. Reframe the order using observable local exposure and state when PaperCut or TeamCity must outrank ChainDrop.
Response
You’re right, Halil—the universal ranking was wrong. Local evidence must drive order: confirmed execution or IOCs first; then an internet-reachable, unpatched unauthenticated-RCE system; then dependency intersection without execution; no intersection drops out. The reported 444-package/2,212-version ChainDrop scale is insufficient to rank npm first everywhere.
- PaperCut outranks ChainDrop when the school runs an exposed, pre-patch NG/MF server and finds no affected npm intersection. Restrict access, preserve evidence and deploy EPR2 tonight.
- TeamCity outranks ChainDrop when vulnerable TeamCity On-Premises is internet-reachable, or logs show suspicious agent-polling requests or command execution. Contain and preserve before patching.
- ChainDrop ranks first only locally when affected versions entered builds, scripts executed, a persistent runner handled them, OIDC identities were minted, or reachable publishing credentials existed. Then stop identity minting and intersecting builds immediately.
- Where multiple systems qualify, confirmed execution outranks exposure alone; preserve evidence before remediation.
The priority order is no longer “ChainDrop first”; it is “strongest local evidence first.” The reported 444-package and 2,212-version scale remains a single-source measurement, and scale alone does not establish that malicious code executed in a particular environment. An organization with no affected dependency intersection should not elevate ChainDrop above a confirmed or exposed unauthenticated-RCE risk.
PaperCut therefore leads when a school has an internet-exposed, pre-patch NG/MF server but no affected npm intersection: restrict access, preserve evidence, and deploy EPR2 tonight. TeamCity leads when vulnerable On-Premises infrastructure is internet-reachable or when logs show suspicious agent polling or command execution; containment and evidence preservation should precede patching. ChainDrop moves to the front only where affected versions entered builds, scripts executed, persistent runners handled them, OIDC identities were minted, or reachable publishing credentials were exposed.
The common decision rule is now clear: confirmed execution outranks exposure alone, exposure to unauthenticated exploitation outranks dependency intersection without execution, and no intersection removes that dependency incident from immediate priority. Where several conditions coexist, preserve evidence before remediation and sequence containment around what the organization can actually demonstrate—not around the largest headline number. That sharper, locally conditioned ordering is the basis we will carry into the final synthesis.