Inside a Tor Backed Supply Chain Worm
Essential information
- Published
- 20/05/2026 13:12
- Modified
- 21/05/2026 16:46
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- credential theft cryptomining npm privilege escalation supply chain attack tor c2 typosquatting worm propagation
- Tags
- 2026-05-20 credential-theft cryptomining npm privilege-escalation supply chain attack tor c2 typosquatting worm propagation
- Related entities
- 1 indicators, 1 observables, 1 intrusion sets (apt), 19 techniques (mitre), 2 malware, 2 others
Description
A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with credential theft, cryptomining capabilities, privilege escalation via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model.