← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Operation HEXSTRIKE -- npm Supply Chain Attack Targeting Guardarian Cryptocurrency Exchange.
Operation HEXSTRIKE is a targeted cybercrime involving a sophisticated supply chain attack that exploited nine malicious npm packages published by an actor using the account umarbek1233. These packages, impersonating Strapi CMS plugins, were released between 02:02 and 03:58 UTC on April 3, 2026. Each package leverages postinstall hooks to deploy a multi-phase command-and-control (C2) agent which stealthily eliminates environment variables, database credentials, JWT secrets, API keys, and cryptocurrency wallet information. This operation notably affects the Guardarian cryptocurrency exchange, with the attacker establishing a reverse shell that polls every five seconds.
MITRE ATT&CK & Malware Families
Indicators of Compromise (2 / 16 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2023-0386 | — | 2026-04-26 | |
| CVE | CVE-2023-22621 | — | 2026-04-26 |
References (1)