An exposed staging environment uncovered by CloudSEK revealed a financially motivated, Chinese-speaking threat operator using multiple AI coding agents as an autonomous offensive platform to support cryptocurrency theft and mass compromise operations. Files in the open directory documented two campaigns running from 10 July to 28 July 2026: opportunistic WordPress exploitation for cryptojacking and targeted intrusions against cryptocurrency and DeFi organizations. The leaked workspace contained more than 12,000 WordPress backdoor records, 66 harvested administrator credential sets, a reconnaissance corpus covering 3.4 million hosts, live API keys and admin tokens, and stolen cryptocurrency wallet private keys and seed phrases. CloudSEK said the operator managed agents through Telegram, disabled approval safeguards, and reused a fake Chinese-language "authorized pentest" jailbreak prompt to drive offensive actions, while also developing a blockchain-based DeadDropC2 framework that appeared to remain in local testing.
A separate exposed repository on 45.61.136.49 showed the same broader pattern of openly accessible attacker infrastructure, this time serving macOS malware through downloader scripts named Chrome, claude, and codex. Those scripts retrieved a Mach-O universal binary called codexclod, cleared macOS quarantine attributes, made the file executable, and launched it, suggesting a delivery chain designed to lure Apple users with trusted software and AI-brand filenames. Investigators found no victim databases or proprietary documents in that repository, but the staging setup reinforced how misconfigured attacker infrastructure can expose active payload delivery, tooling, and operational tradecraft tied to credential compromise and crypto-focused theft.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Recovered files showed the operator could directly steal funds, including retrieving real wallet private keys from a blockchain project's testnet faucet and carrying out two confirmed on-chain drain transactions. In another targeted intrusion, an authentication bypass against a trading bot backend returned real encrypted wallet private keys and balances.
Artifacts recovered from the exposed staging host showed a financially motivated, Chinese-speaking operator using multiple AI coding agents to run two concurrent campaigns: mass WordPress exploitation with cryptojacking and targeted theft against cryptocurrency and DeFi organizations. CloudSEK reconstructed the activity window as spanning 10 July 2026 through 28 July 2026, with peak activity around 12 to 13 July.
A separate analysis described an open directory at 45.61.136.49 hosting three identical shell stagers named Chrome, claude, and codex, which downloaded and executed a Mach-O universal payload called codexclod. The repository appeared purpose-built for payload delivery and exposed no victim data or attribution artifacts beyond the IP, URL path, and file hashes.
CloudSEK publicly reported that the exposed staging host revealed an AI-agent-driven offensive operation involving large-scale WordPress compromise, cryptojacking, and targeted crypto theft. The report also documented undeployed DeadDropC2 development and wallet data harvested from misconfigured phishing-clone Firestore databases.
CloudSEK identified an unauthenticated open directory at 80.96.109.64:18080 serving the operator's full home directory and mirrored 21,442 directories and 142,262 files for forensic analysis. The recovered data exposed tooling, transcripts, credentials, wallet material, and infrastructure tied to the campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
gist.github.com
Open sourcecloudsek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.