PULSE NAME
The Worm That Keeps on Digging: Latest Wave
WHITE TeamPCP AlienVault 2026-05-19 Modified: 2026-05-21
4
IOCs
LOW VOLUME
A sophisticated supply chain campaign targeting the open source developer ecosystem has emerged, compromising NPM packages in the @antv namespace, GitHub Actions including actions-cool/issues-helper, and the VSCode extension nrwl.angular-console. The malware initiates multi-stage infection chains using GitHub-hosted infrastructure and orphaned commits to deploy payloads via bun. It harvests extensive credentials including GitHub tokens, SSH keys, cloud credentials, and browser secrets, exfiltrating data through attacker-controlled public GitHub repositories. The campaign establishes persistence through a Python backdoor that polls GitHub for signed commands containing specific trigger strings, enabling remote code execution. Infrastructure analysis and operational patterns indicate moderate confidence attribution to the threat actor TeamPCP.
Indicators of Compromise (4)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 b06b126b9e26af03a7ef2f8b8e90d446 2026-05-19
FileHash-SHA1 783b4019fc5b942a29846132d28441c8fc31bed8 2026-05-19
FileHash-SHA256 fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142 2026-05-19
domain m-kosche.com 2026-05-19