Namastex is a software supply chain threat cluster associated with malicious npm packages and malware behavior overlapping earlier CanisterWorm activity and TeamPCP-linked operations. The activity centers on trojanized packages that execute during installation, harvest sensitive data from developer workstations, exfiltrate the collected information to attacker-controlled services, and attempt worm-like propagation by abusing software package publishing access. Observed malware attributed to this cluster targets developer and build environments, searching for secrets and artifacts including npm configuration, SSH material, cloud credentials, environment files, shell history, Git credentials, Kubernetes and Docker configuration, browser data, and cryptocurrency wallet data. It also includes logic to extract npm tokens, enumerate packages the victim is authorized to publish, inject malicious post-install hooks into packages, and republish packages to spread the compromise further. Some payloads additionally include persistence or propagation steps aimed at Python packaging workflows. The cluster is notable for post-compromise automation designed to turn a single infected developer system into a broader supply chain intrusion point. Its tradecraft combines credential theft, secret collection, exfiltration, and propagation across package ecosystems, creating risk to downstream users of compromised open-source packages. Publicly discussed activity tied to Namastex has involved malicious packages associated with the @automagik/genie and pgserve package lines, with suspicious related activity also observed under the @fairwords and @openwebconcept namespaces. High-confidence reporting supports malware lineage overlap or direct code reuse with CanisterWorm-style operations, but does not conclusively establish a nation-state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.