ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey
ID: 4464f547-c70a-555b-ba07-44282f02ee38
STIX ID: report--4464f547-c70a-555b-ba07-44282f02ee38
Feed Name: Checkmarx Zero
Checkmarx researchers uncovered "ChainVeil," an active, high‑sophistication supply‑chain campaign run by the npm actor 'successkeyteck' that published at least nine typosquat packages embedding an import‑time RAT. The loader (lib/lib.min.js) uses seeded string shufflers and a four‑tier blockchain‑backed C2 (Tron, Aptos, BSC) plus an HTTP fallback to deliver a 77KB RAT capable of system fingerprinting, WebSocket reverse shell, credential harvesting, file exfiltration, and stealthy persistence via padded shell‑config injection; the report includes comprehensive IoCs, network rules, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
