PULSE NAME
Operation HEXSTRIKE -- npm Supply Chain Attack Targeting Guardarian Cryptocurrency Exchange.
WHITE PetrP.73 2026-04-26 Modified: 2026-05-26
16
IOCs
MEDIUM VOLUME
Operation HEXSTRIKE is a targeted cybercrime involving a sophisticated supply chain attack that exploited nine malicious npm packages published by an actor using the account umarbek1233. These packages, impersonating Strapi CMS plugins, were released between 02:02 and 03:58 UTC on April 3, 2026. Each package leverages postinstall hooks to deploy a multi-phase command-and-control (C2) agent which stealthily eliminates environment variables, database credentials, JWT secrets, API keys, and cryptocurrency wallet information. This operation notably affects the Guardarian cryptocurrency exchange, with the attacker establishing a reverse shell that polls every five seconds.
Indicators of Compromise (16)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2023-0386 2026-04-26
CVE CVE-2023-22621 2026-04-26
FileHash-MD5 ceab06fdcb027bc20e7a41e49d87a9ce 2026-04-26
FileHash-SHA1 9639769d81d0573e7241d0c5957ef1a900c74ca6 2026-04-26
FileHash-SHA256 27001f1a29590cf6645741769a0ae44dc9ee3c6bc948843c14824b17f49a72ff 2026-04-26
FileHash-SHA256 77b23d754585a5eb5f67cf5dbbc123c4bd9203861018f1b52d13736fa8423b5a 2026-04-26
FileHash-SHA256 b42c4f7b912ccba6f8e3812b68fb664ac52d887e68a4ae5c7d7977912dd81a6c 2026-04-26
FileHash-SHA256 f4aa76c95b3855e16ffd7083834664ee13bd45d91ddacd472f94ec15979e21e3 2026-04-26
URL http://144.31.107.231:22 2026-04-26
URL http://144.31.107.231:4444 2026-04-26
URL http://144.31.107.231:8888 2026-04-26
URL http://144.31.107.231:9999 2026-04-26
URL http://144.31.107.231:9999/c2/ 2026-04-26
URL http://144.31.107.231:9999/ssti-env 2026-04-26
URL http://65.21.203.242:9200 2026-04-26
YARA 5895341d016ae5d8f8399f5824dc538be17b4a2c Detects HEXSTRIKE C2 server (Python) 2026-04-26