RED-LILI is an active threat actor that has been identified by Checkmarx SCS research team. They have been publishing malicious packages on NPM and PyPi platforms, and have recently automated the process of creating NPM users for package publication. The Checkmarx team has detected around 1500 malicious packages associated with RED-LILI and has continuously disclosed their findings to the respective security teams.
Executive Summary
Red-LILI is an active threat actor distributing malicious packages on npm and PyPI platforms. They have automated the creation of NPM users to maintain a continuous presence, with over 1500 malicious packages identified by Checkmarx SCS. Their actions pose risks to software supply chains and development ecosystems.
Goals & Targeting
Red-LILI likely aims for economic gain through ad fraud or crypto-mining, with victims primarily in the tech sector, particularly open-source developers and companies using JavaScript and Python libraries. They exploit software development tools' trust to inject malicious code into packages used globally.
Enhanced Description
Red-LILI targets software package managers, specifically npm and PyPI, deploying malicious packages that compromise the software supply chain. This activity affects developers and companies relying on these platforms. The actor's automation of user creation suggests operational sophistication and a focus on persistence. Their actions include unauthorized access to package repositories and credential extraction, potentially targeting financial gain or disrupting supply chains.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Red-LILI has sustained activity over two years, with campaigns focusing on mass-monetization. Their adaptability in creating new packages complicates detection, requiring continuous monitoring of supply chains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in findings, with gaps in exact motivations and full infrastructure details.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics