Also known as: network, software application, tracked as, is a contrast, The Wedding Curse, a botnet, Cryptowall, root access, Smoke loader
A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with credential theft, cryptomining capabilities, privilege escalation via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The threat actor 'sukob' operates a sophisticated npm supply chain attack targeting Linux developer systems and CI/CD environments. The actor uses typosquatting to distribute malicious packages, harvest credentials, hijack maintainer accounts, and create long-term persistence through systemd and SUID exploitation. The campaign leverages Tor-based infrastructure for command-and-control communication, making it highly anonymous and resilient.
Goals & Targeting
'sukob' likely seeks to disrupt software development processes and gain长期 access to target environments. The targeting of Linux developer systems and CI/CD pipelines suggests a focus on sectors with high dependency on these technologies, such as technology companies, research institutions, and DevOps-heavy organizations. By compromising trusted npm packages, 'sukob' aims to create persistent footholds in victim networks while maintaining operational anonymity through Tor infrastructure.
Enhanced Description
The 'sukob' threat actor exploits the npm ecosystem by distributing a typosquatting package named 'crypto-javascri', which mimics the legitimate 'crypto-js' library. Once installed, this malicious package harvests sensitive credentials from infected systems, including those for npm and GitHub accounts. The attacker then takes over maintainer identities to republish trojanized packages under trusted names, creating a self-propagating threat within the supply chain. The payload includes a weaponized Arti Tor client that facilitatescredential theft, cryptomining, privilege escalation, and persistence mechanisms such as SUID exploitation and systemd-based services. The actor's targeting focus on Linux developer environments underscores their intent to disrupt software development pipelines and create long-term risks in the supply chain. The use of Tor-based C2 infrastructure highlights 'sukob's operational sophistication and efforts to maintain anonymity. This attack vector is particularly concerning for organizations reliant on open-source libraries and continuous integration systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
'sukob' campaign exhibits a worm-like propagation model, leveraging compromised maintainer accounts to distribute malicious packages further. The use of Tor infrastructure indicates a focus on long-term operational resilience and匿名ity. Targeted sectors include Linux developers, CI/CD environments, and open-source software maintainers. Notable past operations include the widespread compromise of npm packages, creating significant supply chain risks for numerous organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in 'sukob's identification as a sophisticated npm supply chain threat actor, based on the detailed functionality and attack vector analysis. However, specific campaign timestamps, exact toolset versions,and explicit correlations to known APT groups remain unclear.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
44
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics