Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type domain · source intel_report_ingest
Shared non-noise tags (narrow join).
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
tags: report:trend_micro, report:unit42
tags: report:microsoft_mstic, report:trend_micro
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.
Title/body text match only.
Typosquatted npm packages used to steal cloud and CI/CD secrets The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals cre
ChainDrop: Inside a Self-Propagating npm Worm Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 . ChainDrop
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Our research examines the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused
ChainDrop supply chain compromise: Anatomy of a self-propagating worm A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected e
Deduped connector weight from graph context.