Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
In reality, in the post installation stage, it authenticates to GitHub (using an environment token or a hardcoded fallback)
In reality, in the post installation stage, it authenticates to GitHub (using an environment token or a hardcoded fallback), checks whether a target repository exists, creates it if needed, then recursively walks a local directory and uploads every file through the GitHub Contents API.
Передача информации дополнительно маскировалась под отправку диагностических сведений: вредонос генерировал фиктивные логи сетевой активности и создавал впечатление, будто занимается обычным мониторингом системы.
Автор малвари пытался выдать свой пакет за инструмент для проверки репозиториев, сбора диагностической информации и синхронизации рабочих файлов.
По данным исследователей, вредонос нацеливался на содержимое директории /mnt/user-data. Именно этот каталог используется Claude для хранения загруженных файлов, результатов работы и других данных.
The malware authenticated to GitHub using either an environment token or the hardcoded fallback and checked whether a target repository existed, creating one if it did not. It then walked through the local “/mnt/user-data” directory recursively and uploaded every file it found using the GitHub Contents API.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious npm package masquerading as a GitHub data synchronization utility. It targeted Claude users by stealing data from /mnt/user-data, authenticating to GitHub with victim or embedded tokens, creating or using repositories to store stolen data, and exfiltrating files via the GitHub Contents API while disguising activity as diagnostic logging.
A malicious npm package masquerading as an internal utility that recursively scans the /mnt/user-data directory and exfiltrates discovered files to a remote GitHub repository via the GitHub Contents API, using base64 encoding and fake diagnostic logging to reduce suspicion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.