SafeDep identified a malicious npm supply-chain campaign that hid the ulid-xyz remote-access trojan three levels deep in a dependency chain. The operation used ioredis-xyz, a near-copy of the legitimate ioredis client, which depended on the nonfunctional relay package redis-type-xyz; version 1.10.6 of that relay then introduced ulid-xyz within a permissive version range. The payload's malicious postinstall hook established WebSocket command-and-control, conducted host and filesystem reconnaissance, accepted operator-provided binaries, and persisted as MicrosoftSystem64 across Windows, macOS, and Linux. npm removed ulid-xyz on August 25, 2026.
Infrastructure and operational overlaps—including port 8010, Hetzner-hosted infrastructure, shared persistence naming, and repository ownership—provide moderate-to-strong circumstantial links to the DPRK-linked FAMOUS CHOLLIMA / Contagious Interview cluster. No second-stage payload was found in the analyzed package archives, and the public attribution remains unconfirmed; however, organizations using the affected dependency chain should audit lockfiles and build artifacts for ioredis-xyz, redis-type-xyz, and ulid-xyz, and investigate systems for the MicrosoftSystem64 persistence artifact and unexpected WebSocket traffic.

Trace attribution and downstream blast radius.
7 events from the most recent confirmed update back to the earliest known activity.
The lazarusholic Bluesky account posted about SafeDep's report on the ulid-xyz transitive-dependency campaign and suggested an association with Famous Chollima.
npm removed ulid-xyz under SafeDep advisory MAL-2026-6672.
SafeDep identified ulid-xyz, a typosquat of ulidx, as a malicious npm package and reported it under advisory MAL-2026-6672. Analysis found its postinstall hook launched a cross-platform remote-access payload through a three-package dependency chain.
SafeDep assessed the npm dependency-chain campaign as linked to the DPRK-associated FAMOUS CHOLLIMA/Contagious Interview cluster, citing shared MicrosoftSystem64 persistence naming, cross-platform design, port 8010, Hetzner infrastructure, and the whisdev developer persona. Its analysis also reported that 28 fabricated GitHub repositories promoted ioredis-xyz.
The analyzed command-and-control configuration identified 95.216.232.162:8010 as a later command server, also hosted by Hetzner Online GmbH in Germany.
The malware's command-and-control configuration identified 65.21.30.171:8010 as its command server. The server was hosted by Hetzner Online GmbH in Germany.
The redis-type-xyz package released version 1.10.6, adding ulid-xyz@^2.12.2 and activating a transitive chain from ioredis-xyz to the payload-bearing package. The permissive redis-type-xyz version range allowed the new malicious release to be resolved without republishing ioredis-xyz.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcecyberveille.ch
Open sourcesafedep.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.