Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Red-Lili

Description

RED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platforms, and have recently automated the process of creating NPM users for package publication. The Checkmarx team has detected around 1500 malicious packages associated with RED-LILI and has continuously disclosed their findings to the respective security teams.

AI Analysis

· 1 week ago

Executive Summary

Red-LILI is an active threat actor distributing malicious packages on npm and PyPI platforms. They have automated the creation of NPM users to maintain a continuous presence, with over 1500 malicious packages identified by Checkmarx SCS. Their actions pose risks to software supply chains and development ecosystems.

Goals & Targeting

Red-LILI likely aims for economic gain through ad fraud or crypto-mining, with victims primarily in the tech sector, particularly open-source developers and companies using JavaScript and Python libraries. They exploit software development tools' trust to inject malicious code into packages used globally.

Enhanced Description

Red-LILI targets software package managers, specifically npm and PyPI, deploying malicious packages that compromise the software supply chain. This activity affects developers and companies relying on these platforms. The actor's automation of user creation suggests operational sophistication and a focus on persistence. Their actions include unauthorized access to package repositories and credential extraction, potentially targeting financial gain or disrupting supply chains.

Key Capabilities

  • Malicious package distribution
  • Automation of user creation on npm
  • Sophisticated operational security practices

MITRE ATT&CK Tactics

Exploitation for Collection

ATT&CK Techniques

T1595.001 - Supply Chain Compromise: Tampering with Binary or Script Build Process
T1086 - Use of CLI Tools for Configuration Credential Access

Software / Tooling

Custom malicious package creation tools
Scripts to automate npm user creation

Campaigns & Victims

Red-LILI has sustained activity over two years, with campaigns focusing on mass-monetization. Their adaptability in creating new packages complicates detection, requiring continuous monitoring of supply chains.

IOC Patterns

  • Spear-phishing via npm package updates
  • Unusual spikes in PyPI downloads
  • Bulk registration of npm accounts

Recommended Actions

  • Monitor npm and PyPI dependencies with automated tools
  • Implement strict vetting processes for new packages
  • Conduct regular software supply chain audits

Suggested Tags

APT
software-supply-chain
financial-gain
info-stealing

Confidence Assessment

Moderate confidence in findings, with gaps in exact motivations and full infrastructure details.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Supply Chain Attack
APT
software-supply-chain
financial-gain
info-stealing

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.