logo

TXTBOOK A Supply Chain Heist, Rehearsed in Public

ID: fbe5db9f-20de-5499-9638-b479ebfd0f88

STIX ID: report--fbe5db9f-20de-5499-9638-b479ebfd0f88

Feed Name: CloudSEK Blog

Threat Score
87/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

...
...

**Executive Summary:** TXTBOOK is a targeted dependency‑confusion supply‑chain campaign that published 993 malicious npm packages impersonating a single financial group's private package namespace (T-Bank/Tinkoff); packages execute on import, use DNS TXT records to reassemble a native loader, and install a Sliver implant providing comprehensive post‑exploitation capabilities, with recovered C2 signing keys, staging zones, and publisher account patterns detailed alongside mitigation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.