t-in-one is an npm supply-chain threat actor persona assessed with high confidence to be part of a single operator that also used the maintainer aliases mr.4nd3r50n and ce-rwb. The actor conducted a dependency-confusion and namespace-squatting campaign against internal-looking corporate package scopes, publishing malicious npm packages designed to impersonate private enterprise dependencies. The operation used spoofed package metadata and realistic package naming and versioning to increase the likelihood that developer workstations and build environments would resolve and install the attacker-controlled packages. The malicious packages executed through the npm postinstall lifecycle hook and launched a heavily obfuscated JavaScript stager. The stager used anti-analysis and defense-evasion measures including code obfuscation, control-flow flattening, dead-code injection, self-defending logic, CI/CD environment checks, and run-once cache markers to reduce repeated execution and detection. It then retrieved a platform-specific second-stage payload for Windows, macOS, or Linux and spawned it as a detached background process. Observed payload behavior was reconnaissance-focused by default. The malware profiled host and developer environments by collecting system information, hostnames, environment variables, installed-package context, and related developer or CI/CD context. The architecture was capable of supporting broader post-compromise activity, including credential theft, exfiltration, or backdoor deployment, although the observed campaign phase was configured primarily for reconnaissance. The t-in-one persona was used in a May 2026 wave that expanded the campaign into additional npm scopes, including packages impersonating a SberPay-related widget and other internal enterprise components. Attribution of t-in-one, mr.4nd3r50n, and ce-rwb to a single actor is supported by shared command-and-control infrastructure, identical package-generation patterns, correlated publishing behavior, and a common hardcoded authentication secret used in outbound requests. The activity is best characterized as a software supply-chain intrusion set focused on initial access into developer and build ecosystems through malicious package publication.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.