Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
The malicious releases can run while a developer installs dependencies or when npm processes a specially crafted build configuration file... Four later versions also added a preinstall hook.
The condition expression is a Python sandbox escape using the catch_warnings class... imports os, and calls os.system() to run the main payload with Node.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
macOS persistence ~/Library/LaunchAgents/com.user.systemd-detect-fash.plist, ~/Library/LaunchAgents/com.user.sysvinit-detect-fash.plist.
Researchers also found persistence components for Linux... ~/.config/systemd/user/systemd-detect-fash.service and ~/.config/systemd/user/sysvinit-detect-fash.service.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
macOS persistence ~/Library/LaunchAgents/com.user.systemd-detect-fash.plist, ~/Library/LaunchAgents/com.user.sysvinit-detect-fash.plist.
Researchers also found persistence components for Linux... ~/.config/systemd/user/systemd-detect-fash.service and ~/.config/systemd/user/sysvinit-detect-fash.service.
The loader is heavily disguised. It can download the Bun runtime if absent, decrypt the malware, run it from a temporary location, and remove that file afterward.
The loader... run[s] it from a temporary location, and remove[s] that file afterward... If it detects that a token has been revoked, it can trigger a destructive cleanup routine.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token. The malware can use recovered publishing access to modify and republish packages.
Before doing anything, the payload checks several conditions and exits silently... CrowdStrike, SentinelOne, or CarbonBlack directories are present... known fake credential prefixes used by security scanners... [or] the StepSecurity harden-runner tool is active.
On GitHub Actions runners it also requests an OIDC token via ACTIONS_ID_TOKEN_REQUEST_TOKEN and ACTIONS_ID_TOKEN_REQUEST_URL.
Once active, Trinitite searches for credentials linked to GitHub, npm, PyPI, RubyGems, cloud services, HashiCorp Vault, and Kubernetes. It also targets CI secrets and data in AI development-tool locations.
Trinitite searches for credentials linked to GitHub, npm, PyPI, RubyGems, cloud services, HashiCorp Vault, and Kubernetes. It also targets CI secrets and data in AI development-tool locations.
Before doing anything, the payload checks several conditions and exits silently... CrowdStrike, SentinelOne, or CarbonBlack directories are present... known fake credential prefixes used by security scanners... [or] the StepSecurity harden-runner tool is active.
The stolen material is encrypted and committed to public repositories using the victim's GitHub token.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A self-propagating npm supply-chain payload delivered through compromised package releases. It executes through weaponized binding.gyp files and preinstall hooks, can download Bun to decrypt and execute its payload, steals developer, CI/CD, cloud, package-registry, source-code, Kubernetes, Vault, and AI-tool credentials, exfiltrates them through victim GitHub repositories, and uses recovered publishing access to republish compromised packages. It also installs Linux/macOS persistence, adds workflows intended to capture repository secrets, monitors GitHub-token revocation, and may trigger destructive cleanup when a token is revoked.
A self-propagating npm supply-chain worm delivered through malicious releases of @7nohe/openapi-react-query-codegen. It downloads Bun if needed, decrypts and executes its payload, steals developer, cloud, CI/CD, package-publishing, and source-code credentials, exfiltrates them through public GitHub repositories, and uses recovered publishing permissions to republish modified packages. It also establishes Linux and macOS persistence, adds a workflow to collect repository secrets, monitors GitHub-token revocation, and can initiate destructive cleanup when revocation is detected.
A malicious npm supply-chain payload delivered through compromised @7nohe/openapi-react-query-codegen versions. It abuses binding.gyp/node-gyp condition evaluation to execute an obfuscated Node.js payload during installation, downloads Bun, evades security-analysis environments, steals cloud, developer, source-control, cryptocurrency, messaging, VPN, and local credentials, and includes worm-like and destructive functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.