MUT-1244 is a developer-focused threat actor associated with open-source software supply-chain attacks targeting the cybersecurity community. The actor has been linked to malicious packages and fake proof-of-concept repositories designed to compromise researchers, bug hunters, and red teamers who test newly disclosed vulnerabilities or install seemingly useful development dependencies. Activity attributed to MUT-1244 includes the ChocoPoC campaign, which embedded a data-stealing remote access trojan in fraudulent Python proof-of-concept repositories themed around recently disclosed CVEs. In these operations, the visible exploit code appeared benign while malicious functionality was hidden in dependency chains, causing infection when victims installed requirements and executed the proof-of-concept. ChocoPoC provided remote shell and arbitrary Python execution, collected host and process information, and stole browser data including saved credentials, cookies, autofill data, and browsing history, along with local files, shell history, notes, and databases. The malware also used dead-drop style command retrieval and traffic-masking techniques to reduce detection. Separate activity attributed to MUT-1244 involved malicious npm packages targeting cybersecurity practitioners for data theft and cryptocurrency mining through dependent packages. Across reporting, the actor is characterized by abuse of trusted developer ecosystems such as package repositories and code-hosting platforms, use of staged payload delivery through dependencies, and efforts to evade casual review and sandbox analysis by delaying or context-gating execution. The actor’s targeting pattern indicates a strong focus on compromising technically privileged users whose environments may contain SSH keys, cloud credentials, browser secrets, and access to internal tooling. This creates elevated downstream risk of supply-chain compromise affecting security tooling and related frameworks. No high-confidence country attribution is available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign using fake proof-of-concept repositories to steal SSH keys and cloud credentials from red teamers and security researchers.
Attributed activity cluster distributing malicious npm packages (often disguised as PoC code or a kernel patch) targeting the cybersecurity community, enabling data theft and cryptocurrency mining via a dependent package, and leveraging legitimate services (e.g., Dropbox) for exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.