mr4nd3r50n is an npm-focused supply-chain threat actor assessed with high confidence to have operated multiple maintainer personas, including mr.4nd3r50n, ce-rwb, and t-in-one, as part of a coordinated malicious package campaign in May 2026. The actor abused dependency confusion and namespace squatting to impersonate internal corporate packages across multiple organizational scopes, using realistic package metadata, spoofed enterprise development references, and manipulated versioning to increase the likelihood that malicious packages would be resolved and installed in developer and CI/CD environments. The actor’s packages executed through the npm postinstall lifecycle hook and used heavily obfuscated JavaScript stagers with anti-analysis features such as string encoding, control-flow flattening, dead-code injection, and self-defending logic. The stagers performed environment checks, including CI-aware execution gating and Node.js version checks, then retrieved platform-specific second-stage payloads for Windows, macOS, and Linux and launched them as detached background processes. The malware also used cache-based run-once logic to reduce repeated execution and lower detection risk. Observed payload behavior was primarily reconnaissance-oriented. The second stage collected host and environment information, including system details, hostnames, environment variables, installed-package context, and developer-environment context. The architecture was designed to support broader post-compromise activity, and the operator’s tooling was capable of being adapted for credential theft, data exfiltration, or backdoor deployment. The campaign therefore demonstrates initial access, defense evasion, persistence-adjacent execution through package lifecycle abuse, and post-exploitation reconnaissance within software development ecosystems. The actor targeted internal-looking package namespaces spanning multiple organizations, including lures associated with software platforms, data science, payments, travel testing, chat tooling, and e-commerce payment functionality. One impersonated package directly spoofed a SberPay-related widget, indicating targeting of enterprise development workflows connected to financial services. The campaign included pre-staged releases before the main publication bursts, suggesting preparation and operational planning rather than opportunistic abuse. Attribution available at high confidence links the three maintainer aliases to a single operator based on shared command-and-control infrastructure, identical hardcoded authentication material, matching package-generation patterns, and tightly correlated publishing activity. No high-confidence state attribution is established from the available facts. The dominant motivation is currently best assessed as espionage-oriented reconnaissance against developer and build environments rather than immediate monetization, because the observed payloads were configured for information gathering by default.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.