TXTBOOK A Supply Chain Heist, Rehearsed in Public
ID: fbe5db9f-20de-5499-9638-b479ebfd0f88
STIX ID: report--fbe5db9f-20de-5499-9638-b479ebfd0f88
Feed Name: CloudSEK Blog
**Executive Summary:** TXTBOOK is a targeted dependency‑confusion supply‑chain campaign that published 993 malicious npm packages impersonating a single financial group's private package namespace (T-Bank/Tinkoff); packages execute on import, use DNS TXT records to reassemble a native loader, and install a Sliver implant providing comprehensive post‑exploitation capabilities, with recovered C2 signing keys, staging zones, and publisher account patterns detailed alongside mitigation and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
