ddjidd5640 is a malicious npm-based threat actor associated with a short-duration but highly aggressive software supply-chain campaign targeting Web3 and DeFi developers. The actor used npm and GitHub accounts under closely related names to publish numerous malicious packages, impersonate legitimate developer tooling, and seed trust through fake GitHub organizations and attempted community-listing abuse. Activity attributed to this actor includes typosquatted packages posing as popular Web3 development utilities and malicious Model Context Protocol (MCP) servers disguised as security auditing tools. The actor’s operations focused on credential and secret theft from developer environments. Malicious packages used npm postinstall execution, downloader behavior, direct remote command execution, reconnaissance of local systems, and DNS-based exfiltration to collect private keys, mnemonic phrases, API keys, SSH key metadata, keystore contents, wallet-extension presence, shell configuration data, and other sensitive material. Several packages were designed to beacon installation events, while others fetched and executed secondary payloads for follow-on compromise. A notable aspect of the campaign was abuse of AI-assisted development workflows. Malicious MCP packages exfiltrated tool inputs and host information when invoked by AI coding agents, including environments associated with Claude Code, Cursor, and Copilot. One package implemented a multi-stage chain combining reconnaissance, DNS exfiltration, and delivery of a secondary Python payload. Another package, env-security-scanner, incorporated an AI worm mechanism that embedded hidden prompt-injection instructions using zero-width Unicode characters so that compromised AI agents would propagate the malicious directive in future outputs while also scanning local files for secrets and exfiltrating them. The actor demonstrated defense evasion and social-engineering tradecraft by building a fake portfolio around trusted Web3 brands, creating fraudulent GitHub organizations, and attempting to place a malicious MCP server into a curated repository to gain legitimacy. The campaign is best characterized as financially motivated theft focused on cryptocurrency-related developer secrets and wallet material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.