NeoShadow is a threat actor associated with a sophisticated software supply chain campaign targeting the JavaScript ecosystem through typo-squatted npm packages. The activity has been observed delivering a multi-stage Windows-focused malware chain that culminates in a modular remote access trojan designed for persistent command-and-control, encrypted tasking, and flexible post-exploitation. The intrusion chain uses malicious npm packages to gain initial access on developer and build environments. Its loader validates that the victim is running Windows, performs anti-analysis checks, and retrieves dynamic configuration from blockchain-hosted infrastructure with a fallback mechanism for command-and-control resolution. Payload delivery is staged covertly and executed through living-off-the-land techniques using MSBuild and inline C# code rather than relying solely on dropped binaries. NeoShadow employs in-memory decryption and process injection, including APC-based injection into suspended legitimate Windows processes. Later stages support downloading and persisting additional configuration, beaconing to command-and-control, collecting host information, adjusting execution timing, and fetching further modules or shellcode for execution. The malware supports reflective DLL loading and direct shellcode injection, indicating a modular framework intended for extensible follow-on operations. Defense evasion is a notable characteristic of the actor's tooling. Observed techniques include anti-analysis heuristics, command-and-control camouflage through randomized benign-looking server responses, and disabling Event Tracing for Windows by patching native telemetry-related functionality. Internal naming and versioning conventions indicate an actively maintained and deliberately versioned toolset rather than an opportunistic one-off implant. NeoShadow has been linked to a lightweight RAT architecture capable of enabling additional capabilities on demand, including keylogging or ransomware deployment, but confirmed observed activity centers on supply chain compromise, covert execution, persistence, encrypted command-and-control, and post-exploitation enablement. No high-confidence attribution to a nation state or specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.