← Back to Pulse Feed
PULSE DETAIL
A sophisticated supply chain campaign targeting the open source developer ecosystem has emerged, compromising NPM packages in the @antv namespace, GitHub Actions including actions-cool/issues-helper, and the VSCode extension nrwl.angular-console. The malware initiates multi-stage infection chains using GitHub-hosted infrastructure and orphaned commits to deploy payloads via bun. It harvests extensive credentials including GitHub tokens, SSH keys, cloud credentials, and browser secrets, exfiltrating data through attacker-controlled public GitHub repositories. The campaign establishes persistence through a Python backdoor that polls GitHub for signed commands containing specific trigger strings, enabling remote code execution. Infrastructure analysis and operational patterns indicate moderate confidence attribution to the threat actor TeamPCP.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | b06b126b9e26af03a7ef2f8b8e90d446 | — | 2026-05-19 | |
| FileHash-SHA1 | 783b4019fc5b942a29846132d28441c8fc31bed8 | — | 2026-05-19 | |
| FileHash-SHA256 | fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142 | — | 2026-05-19 | |
| domain | m-kosche.com | — | 2026-05-19 |