ce-rwb is a maintainer alias used in a malicious npm software supply-chain campaign that abused dependency confusion and namespace squatting to impersonate internal corporate packages. High-confidence attribution links ce-rwb with the aliases mr.4nd3r50n and t-in-one as personas operated by the same actor. The campaign published malicious packages across multiple organizational scopes in late May 2026, using spoofed package metadata and realistic enterprise-themed repository information to make the packages appear legitimate. The malicious packages executed through the npm postinstall lifecycle hook and launched a heavily obfuscated JavaScript stager employing anti-analysis and anti-tampering techniques such as string encoding, control-flow flattening, dead-code injection, and self-defending logic. The stager retrieved platform-specific second-stage payloads for Windows, macOS, and Linux, wrote them to temporary storage, and spawned them as detached background processes. The malware also used cache-based run-once logic to reduce repeated execution and checked for CI/CD-related environment variables to evade monitored build environments. Observed payload behavior was reconnaissance-focused by default. The malware collected host and environment information, including system details, hostnames, environment variables, installed-package context, and developer-environment context. The architecture was assessed as capable of supporting follow-on actions such as credential theft, data exfiltration, or backdoor deployment, although the documented campaign phase was configured primarily for reconnaissance. Within the linked cluster, the ce-rwb persona published a smaller subset of the malicious packages across scopes associated with data science, payments, travel testing, and similarly themed internal namespaces. One impersonated package directly mimicked a SberPay-related payment widget, indicating targeting of enterprise development ecosystems and internal package consumers. The actor used inflated and sometimes realistic versioning to win dependency resolution while blending into expected release histories. This activity is best characterized as a software supply-chain intrusion focused on initial access into developer and CI/CD environments, followed by reconnaissance and preparation for potential deeper compromise. No high-confidence state attribution is established from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.