Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: network, software application, tracked as, is a contrast, The Wedding Curse, a botnet, Cryptowall, root access, Smoke loader

Description

A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with credential theft, cryptomining capabilities, privilege escalation via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model.

Goals & Targeting

Targeted Sectors

Financial services
Government
Mining
Construction
Energy
Education
Manufacturing
Critical infrastructure

Targeted Countries / Regions

US
RU
CN
JP
KP

AI Analysis

· 1 week ago

Executive Summary

The threat actor 'sukob' operates a sophisticated npm supply chain attack targeting Linux developer systems and CI/CD environments. The actor uses typosquatting to distribute malicious packages, harvest credentials, hijack maintainer accounts, and create long-term persistence through systemd and SUID exploitation. The campaign leverages Tor-based infrastructure for command-and-control communication, making it highly anonymous and resilient.

Goals & Targeting

'sukob' likely seeks to disrupt software development processes and gain长期 access to target environments. The targeting of Linux developer systems and CI/CD pipelines suggests a focus on sectors with high dependency on these technologies, such as technology companies, research institutions, and DevOps-heavy organizations. By compromising trusted npm packages, 'sukob' aims to create persistent footholds in victim networks while maintaining operational anonymity through Tor infrastructure.

Enhanced Description

The 'sukob' threat actor exploits the npm ecosystem by distributing a typosquatting package named 'crypto-javascri', which mimics the legitimate 'crypto-js' library. Once installed, this malicious package harvests sensitive credentials from infected systems, including those for npm and GitHub accounts. The attacker then takes over maintainer identities to republish trojanized packages under trusted names, creating a self-propagating threat within the supply chain. The payload includes a weaponized Arti Tor client that facilitatescredential theft, cryptomining, privilege escalation, and persistence mechanisms such as SUID exploitation and systemd-based services. The actor's targeting focus on Linux developer environments underscores their intent to disrupt software development pipelines and create long-term risks in the supply chain. The use of Tor-based C2 infrastructure highlights 'sukob's operational sophistication and efforts to maintain anonymity. This attack vector is particularly concerning for organizations reliant on open-source libraries and continuous integration systems.

Key Capabilities

  • Typosquatting npm packages
  • Credential harvesting via malware
  • Maintainer account hijacking
  • Automated package republishing under trusted identities
  • Arti Tor client weaponization for C2 communication
  • SUID exploitation for privilege escalation
  • Systemd-based persistence mechanisms
  • Crypto-mining capabilities

MITRE ATT&CK Tactics

Credential Access
Defense Evasion
Persistence
Exfiltration

ATT&CK Techniques

T1059.003 (Command-line interface manipulation)
T1207 (Valid Accounts)
T1566.001 (Phishing)
T1058 (Password reuse)
T1543 (Windows registry persistence)

Software / Tooling

Arti Tor client
CustomLinux malware

Campaigns & Victims

'sukob' campaign exhibits a worm-like propagation model, leveraging compromised maintainer accounts to distribute malicious packages further. The use of Tor infrastructure indicates a focus on long-term operational resilience and匿名ity. Targeted sectors include Linux developers, CI/CD environments, and open-source software maintainers. Notable past operations include the widespread compromise of npm packages, creating significant supply chain risks for numerous organizations.

IOC Patterns

  • Spear-phishing with typosquatting npm packages
  • C2 communication via Tor infrastructure
  • Unusual activity in npm package repositories
  • Systemd services added without proper authentication
  • Abnormal credential theft patterns in system logs

Recommended Actions

  • Implement rigorous supply chain security measures for npm packages.
  • Monitor for unauthorized package updates or new versions of trusted libraries.
  • Enable multi-factor authentication for npm and GitHub accounts.
  • Harden CI/CD pipelines against supply chain compromises.
  • Educate users about npm package risks and typosquatting threats.
  • Conduct regular audits of system services, particularly systemd entries.
  • Monitor network traffic for Tor-based C2 communication patterns.

Suggested Tags

APT
Supply Chain攻击
Linux威胁
npm生态系统
持续集成风险

Confidence Assessment

High confidence in 'sukob's identification as a sophisticated npm supply chain threat actor, based on the detailed functionality and attack vector analysis. However, specific campaign timestamps, exact toolset versions,and explicit correlations to known APT groups remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 3 URL 8 SHA-256 Hash 9

References

  1. www.malwarebytes.com — Cited by web research for: network
  2. threats.kaspersky.com — Cited by web research for: Cryptowall
  3. www.trendmicro.com — Cited by web research for: Payload
  4. www.cloudsek.com — Cited by web research for: GitHub
  5. panther.com — Cited by web research for: npm packages

Intel Summary

0

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Supply Chain Attack
Data Exfiltration
APT
Supply Chain攻击
Linux威胁
npm生态系统
持续集成风险

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.