logo

Backdoored Cemu release linked to TanStack and Mistral supply chain campaign

ID: af7919d3-c670-5de0-baa6-20a542799c29

STIX ID: report--af7919d3-c670-5de0-baa6-20a542799c29

Feed Name: Datadog Security Labs

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

Datadog Security Labs documents a coordinated supply-chain campaign that within hours poisoned npm and PyPI packages and replaced Linux release assets on the official cemu-project/Cemu GitHub release, distributing a backdoored AppImage and Ubuntu zip bundling a Python zipapp (startup.pyz/transformers.pyz). The payload targets Linux hosts, harvests AWS/Azure/GCP/Kubernetes and local credentials, installs persistence as a systemd service, exfiltrates to C2 83.142.209.194 (with GitHub- and repo-based fallback), and contains a geofenced destructive component; IOCs including SHA256 hashes and the C2 IP are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.