logo

Inside a Tor Backed Supply Chain Worm

ID: 482bf1be-bb10-5dbc-a1ba-5a81a2987c18

STIX ID: report--482bf1be-bb10-5dbc-a1ba-5a81a2987c18

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-07-20

...
...

CloudSEK TRIAD identified a sophisticated npm typosquatting supply-chain campaign distributing the package "crypto-javascri" that embeds a Rust ELF to harvest npm and GitHub credentials, silently republish trojanized packages under compromised maintainer accounts, and deploy a weaponized Arti (Tor) client providing credential theft, cryptomining, privilege escalation, systemd persistence, and Tor-based C2; defenders should monitor for unexpected npm preinstall hooks, audit and revoke tokens, and alert on Tor/Arti activity and unusual user-level persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.