216.73.216.6

Inside a Tor Backed Supply Chain Worm

· Published 20/05/2026 13:12 · Modified 21/05/2026 16:46

Export JSON

Essential information

Published
20/05/2026 13:12
Modified
21/05/2026 16:46
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
credential theft cryptomining npm privilege escalation supply chain attack tor c2 typosquatting worm propagation
Tags
2026-05-20 credential-theft cryptomining npm privilege-escalation supply chain attack tor c2 typosquatting worm propagation
Related entities
1 indicators, 1 observables, 1 intrusion sets (apt), 19 techniques (mitre), 2 malware, 2 others

Description

A sophisticated was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with , capabilities, via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model.

External references