PULSE NAME
The npm Threat Landscape: Attack Surface and Mitigations
WHITE TeamPCP AlienVault 2026-04-25 Modified: 2026-04-27
7
IOCs
LOW VOLUME
The npm ecosystem experienced a critical shift in September 2025 with the Shai-Hulud worm, marking the transition from isolated attacks to systematic supply chain compromises. In April 2026, TeamPCP launched a coordinated campaign through a malicious @bitwarden/cli package targeting multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The multi-stage payload employs advanced obfuscation, harvests credentials from cloud providers and developer workstations, exfiltrates data through encrypted HTTPS and GitHub repositories, and self-propagates by backdooring npm packages using stolen tokens. The malware implements GitHub's search API as a resilient command-and-control fallback mechanism and features anti-detection measures including Russian locale killswitches. This represents an evolution toward wormable propagation, infrastructure-level persistence, and dormant payloads that activate under specific conditions.
Indicators of Compromise (7)
All FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 bc544f455d7c06c8a1f3446160a6d9a4a8236b11 2026-04-25
FileHash-SHA256 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad 2026-04-25
FileHash-SHA256 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb 2026-04-25
FileHash-SHA256 f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d 2026-04-25
URL http://audit.checkmarx.cx:443 2026-04-25
domain checkmarx.cx 2026-04-25
hostname audit.checkmarx.cx 2026-04-25