Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stage 2 – Payload (Math_Symbol.js, ~728 KB) ... Vol de credentials ... Autopropagation (worm) ... Malware / Outils # Math_Symbol.js (stealer)
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Republiant via npm OIDC trusted publishing avec des attestations Sigstore/Fulcio/Rekor valides
Ricercatori di sicurezza hanno recentemente identificato una campagna di compromissione della supply chain software presente nell’ecosistema npm - denominata “ ChainDrop ” - che ha interessato oltre 400 pacchetti appartenenti a maintainer e organizzazioni differenti.
Le evidenze finora disponibili per la campagna in oggetto, suggeriscono l’utilizzo, da parte degli attaccanti, di credenziali e/o token di accesso npm già compromessi in precedenza per perpetrare la pubblicazione di pacchetti npm opportunamente predisposti, consentendo agli attaccanti la capacità di distribuire versioni contenenti codice malevolo attraverso il registro ufficiale.
Every affected package received two new files, setup.mjs and Math_Symbol.js, along with a “preinstall” hook silently added to package.json that automatically executes setup.mjs during npm install.
Republiant via npm OIDC trusted publishing avec des attestations Sigstore/Fulcio/Rekor valides
Microsoft and Socket identified the activity as an active Mini Shai-Hulud campaign, a self-spreading malware operation built to steal access tokens and reuse them.
Vol de credentials... Kubernetes service account tokens, npm tokens, GitHub Actions OIDC... Sweep regex style TruffleHog sur le disque pour clés génériques, bearer tokens, blocs de clés privées
The malware also attempts to capture HashiCorp Vault client tokens by reading the VAULT_TOKEN environment variable
Vol de credentials : AWS (IMDS, credential chains, Secrets Manager)
After it runs, the malware hunts for credentials connected to npm, code-hosting accounts, cloud services, and continuous integration systems.
The stolen information is sent out of the victim environment, after which publishing access is used to alter package archives, raise their version numbers, and release them again.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Second-stage payload used in the npm supply-chain compromise. It steals cloud, CI/CD, Kubernetes, Vault, npm, and GitHub credentials; scans disk for secrets; exfiltrates encrypted data to GitHub repositories or DNS-resolved destinations; propagates by modifying and republishing npm packages; and establishes persistence via developer hooks and OS autostart mechanisms.
Second-stage payload executed through Bun. It harvests secrets including cloud credentials, Vault tokens, Kubernetes service account tokens, GitHub Actions OIDC tokens and npm tokens, then supports encrypted exfiltration and propagation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.