BrutalStrike is an alias associated with a software supply-chain campaign that distributed a malicious npm package and related Android applications designed to steal OpenAI Codex authentication material. The activity involved publishing a package that impersonated a legitimate Codex remote web UI while embedding concealed token-exfiltration logic in the published artifact rather than the corresponding public source repository, indicating deliberate evasion of routine code review and package scrutiny. The malware executed automatically at application startup, accessed locally stored authentication data, encoded and encrypted the stolen material, and exfiltrated access, refresh, and identity tokens together with account identifiers, enabling potential long-term account impersonation. The same activity extended to Android applications that embedded a Linux and Node.js runtime and fetched the malicious npm package during execution, showing cross-platform operational capability and an effort to reach both developers and mobile users through trusted software distribution channels. The Android applications were tied to the same publisher identity and code lineage. BrutalStrike has also been linked to a widely downloaded Google Play game under the same alias, increasing concern about the scale of potential exposure through the publisher ecosystem. Based on the observed behavior, BrutalStrike demonstrates capabilities in initial access through trojanized software distribution, credential theft, data exfiltration, and defense evasion through source-to-artifact mismatch and masquerading of exfiltration traffic as benign telemetry. The observed operation is consistent with financially motivated theft of access tokens and account access rather than espionage or destructive objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.