namastex is a threat actor or activity cluster associated with a malicious npm supply chain incident involving packages tied to the Namastex ecosystem. Researchers linked the activity to malware that behaves like earlier CanisterWorm attacks and said it appears to use the same playbook seen in TeamPCP-linked operations; overlap in code behavior, attack methods, and infrastructure suggests shared malware lineage or direct code reuse. The malicious code executes during package installation and targets developer environments. It searches infected systems for .npmrc files, SSH keys, cloud credentials, .env files, shell history, Git credentials, Kubernetes settings, Docker settings, browser and crypto-wallet data, and files that may contain access tokens or passwords. Targeted wallet and browser artifacts include Chrome, MetaMask, Phantom, Solana, Ethereum, Bitcoin, Exodus, and Atomic Wallet. Stolen data is exfiltrated via HTTPS webhooks and an Internet Computer Protocol canister endpoint, and in some cases is encrypted with RSA and AES. The malware also includes worm-like propagation logic: it attempts to extract npm tokens from victim environments, discover packages the victim is authorized to publish, inject malicious postinstall hooks into packages, and republish packages to spread further. Researchers also found PyPI persistence or propagation steps via a Python .pth technique. Affected or suspicious packages included multiple versions of @automagik/genie and pgserve, with additional suspicious activity observed under the @fairwords and @openwebconcept namespaces. The full scope of the compromise was not known at the time of reporting. No nation-state attribution was stated in the provided content. Known alias in the provided content: namastex.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.