216.73.216.226

The Worm That Keeps on Digging: Latest Wave

· Published 19/05/2026 12:45 · Modified 21/05/2026 17:12

Export JSON

Essential information

Published
19/05/2026 12:45
Modified
21/05/2026 17:12
Tags
2026-05-19 backdoor persistence ci/cd compromise credential-theft developer environments github actions npm packages supply chain attack vscode extension
Related entities
1 observables, 1 intrusion sets (apt), 17 techniques (mitre), 2 others

Description

A sophisticated supply chain campaign targeting the open source developer ecosystem has emerged, compromising in the @antv namespace, including actions-cool/issues-helper, and the nrwl.angular-console. The malware initiates multi-stage infection chains using GitHub-hosted infrastructure and orphaned commits to deploy payloads via bun. It harvests extensive credentials including GitHub tokens, SSH keys, cloud credentials, and browser secrets, exfiltrating data through attacker-controlled public GitHub repositories. The campaign establishes persistence through a Python backdoor that polls GitHub for signed commands containing specific trigger strings, enabling remote code execution. Infrastructure analysis and operational patterns indicate moderate confidence attribution to the threat actor TeamPCP.

External references