AdaptixC2, an open-source post-exploitation framework, has been increasingly leveraged by threat actors for sophisticated cyberattacks. Security researchers discovered that AdaptixC2 was distributed through a malicious npm package named 'https-proxy-utils,' which masqueraded as a legitimate HTTPS proxy utility. This package, now removed from the npm registry, contained a post-install script that downloaded and executed the AdaptixC2 agent, adapting its installation method based on the victim's operating system and architecture. On Windows, the agent was executed via DLL sideloading into msdtc.exe, while on macOS, it was installed as an executable with a plist autorun configuration, and on Linux, it was placed in the /tmp/.fonts-unix directory with execute permissions. The malicious package mimicked legitimate proxy packages with millions of weekly downloads, increasing the likelihood of accidental installation by unsuspecting developers. AdaptixC2 provides a comprehensive suite of command-and-control features, including beaconing, command execution, file management, data exfiltration, credential harvesting, lateral movement, and custom payload deployment through modular plugins called 'extenders.' Researchers have also observed AdaptixC2 being deployed via social engineering attacks, such as impersonating help desk staff on Microsoft Teams, and through AI-generated PowerShell scripts that enable fileless execution and persistence via DLL hijacking and registry run keys. The framework's encrypted configuration, stored in the PE file’s .rdata section and protected with RC4 encryption, poses challenges for defenders but can be analyzed with specialized tools. Recent incidents have linked AdaptixC2 to attacks on financial institutions in Asia, where it was used in conjunction with Fog ransomware, highlighting its role in multifaceted campaigns. The framework's support for SOCKS4/5 proxies and port forwarding enables covert network communication, further complicating detection. Its modular architecture allows attackers to tailor payloads and evasion techniques to specific environments, making it a significant threat to organizations. AdaptixC2's low profile and customizable features have contributed to its growing popularity among both penetration testers and malicious actors. Security teams are urged to strengthen defenses against such advanced post-exploitation tools, as their evolving tactics can bypass traditional security measures. The discovery of AdaptixC2 in a widely used software supply chain underscores the ongoing risks posed by malicious packages in open-source ecosystems. Organizations should monitor for suspicious npm packages and implement robust endpoint detection to mitigate the threat posed by frameworks like AdaptixC2. The incident demonstrates the increasing sophistication of supply chain attacks and the need for vigilance in software dependency management.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that AdaptixC2 was being distributed through a malicious npm package, adding a specific delivery mechanism to the public understanding of the campaign. With no earlier date stated in the reference, the publication date is used.
PolySwarm published research on AdaptixC2, documenting the malware/campaign as a notable security development. The reference does not provide earlier incident dates, so the publication date is used as the event date.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.