cms is a label for a Windows-focused package-supply-chain intrusion cluster associated with the broader Solana FakeFix operation. The cluster used malicious npm packages themed around CMS-related tooling to compromise developer and user systems, particularly on Windows. Its operators relied on install-time execution to launch PowerShell-based loaders, install the Deno runtime, retrieve remote JavaScript or executable payloads, and establish persistence on infected hosts. The cluster’s observed behavior indicates a multi-stage malware delivery workflow oriented toward post-compromise control. Initial package installation triggered downloader activity, after which second-stage payloads were fetched repeatedly and executed. Persistence was established through Windows autorun mechanisms, enabling continued access and recurring payload retrieval. The operation also collected host registration telemetry from compromised systems, suggesting victim tracking and infrastructure management. This cluster is part of a broader malicious ecosystem that also targeted Solana developers through typosquatted and impersonating packages designed to steal wallet material, cloud credentials, SSH keys, environment secrets, and other sensitive data. Across the wider operation, exfiltration to Telegram-based command-and-control channels, remote command execution, and credential theft were documented. The CMS-themed subset is best characterized as a Windows loader and persistence cluster within that larger financially motivated supply-chain campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.