@wagni_bot is a software supply chain threat activity cluster focused on impersonating cryptocurrency and DeFi brands through malicious package publishing in open-source ecosystems. The activity is associated with package names themed around prominent crypto platforms and tooling, including Binance, Jupiter, Orca, Pump.fun, Solana, Meteora, Polymarket, Hyperliquid, MetaMask, and OpenSea, and has included typosquatting of brand names such as MetaMask. The observed behavior indicates an ongoing expansion campaign centered on deceptive package naming intended to attract developers seeking SDKs or related dependencies for crypto and Web3 development workflows. High-confidence reporting supports characterization as a crypto-focused impersonation operation in package repositories, but the available information does not directly establish the operator’s origin, victim geography, downstream payload behavior, or broader intrusion lifecycle beyond initial access through malicious dependency acquisition. The dominant motivation is consistent with financially motivated crypto theft, although specific post-installation tradecraft is not available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.