← Back to Pulse Feed
PULSE DETAIL
The npm ecosystem experienced a critical shift in September 2025 with the Shai-Hulud worm, marking the transition from isolated attacks to systematic supply chain compromises. In April 2026, TeamPCP launched a coordinated campaign through a malicious @bitwarden/cli package targeting multiple distribution channels including Docker Hub, GitHub Actions, and VS Code extensions. The multi-stage payload employs advanced obfuscation, harvests credentials from cloud providers and developer workstations, exfiltrates data through encrypted HTTPS and GitHub repositories, and self-propagates by backdooring npm packages using stolen tokens. The malware implements GitHub's search API as a resilient command-and-control fallback mechanism and features anti-detection measures including Russian locale killswitches. This represents an evolution toward wormable propagation, infrastructure-level persistence, and dormant payloads that activate under specific conditions.
MITRE ATT&CK & Malware Families
Indicators of Compromise (7)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | bc544f455d7c06c8a1f3446160a6d9a4a8236b11 | — | 2026-04-25 | |
| FileHash-SHA256 | 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad | — | 2026-04-25 | |
| FileHash-SHA256 | 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb | — | 2026-04-25 | |
| FileHash-SHA256 | f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d | — | 2026-04-25 | |
| URL | http://audit.checkmarx.cx:443 | — | 2026-04-25 | |
| domain | checkmarx.cx | — | 2026-04-25 | |
| hostname | audit.checkmarx.cx | — | 2026-04-25 |