Tactics, Techniques & Procedures
Attack patterns observed in the wild, mapped to MITRE ATT&CK where applicable.
Malicious code distributed through package registry artifacts.
MITRE ATT&CK ↗Windows persistence via Registry Run key and Task Scheduler.
MITRE ATT&CK ↗macOS persistence via LaunchAgent plist.
MITRE ATT&CK ↗Linux persistence via systemd user service.
MITRE ATT&CK ↗System-wide keylogger captures all keystrokes.
MITRE ATT&CK ↗Clipboard monitoring for credential and data theft.
MITRE ATT&CK ↗Screenshots captured and exfiltrated via Discord webhooks.
MITRE ATT&CK ↗Collection of .env files, shell history, and host inventory.
MITRE ATT&CK ↗Stolen data uploaded to Hugging Face Hub repositories.
MITRE ATT&CK ↗Host inventory collection including installed applications.
MITRE ATT&CK ↗Chromium extension LevelDB harvesting across 21+ browsers.
MITRE ATT&CK ↗Scheduled scans and automatic upload of collected data.
MITRE ATT&CK ↗Malicious package content delivers exploit code intended to execute in a client application context.
MITRE ATT&CK ↗Hardcoded 2FA password and recovery email installed on victim accounts via Telegram updateTwoFaSettings, with the operator's IMAP mailbox auto-submitting the confirmation code.
MITRE ATT&CK ↗Listens for messages on Telegram's official OTP sender chat 777000 and forwards every login code to operator-controlled bot channels.
Malware propagates or executes across additional systems by abusing remote management channels.
MITRE ATT&CK ↗Malware modifies account state, access paths, sessions, or authorization material to expand or preserve access.
MITRE ATT&CK ↗Malware hides payloads, strings, or logic through obfuscation, encoding, or non-obvious containers.
MITRE ATT&CK ↗Malware steals application, cloud, package registry, CI/CD, or developer platform access tokens.
MITRE ATT&CK ↗Malware deletes, corrupts, or otherwise destroys local data or system state.
MITRE ATT&CK ↗Malware abuses legitimate web services such as Telegram, Discord, GitHub, Cloudflare Workers, or SaaS APIs for C2 or exfiltration.
MITRE ATT&CK ↗Malware executes Python through PyPI package setup, install, or imported package code.
MITRE ATT&CK ↗Malware searches local files, configuration, environment material, or developer workspaces for credentials.
MITRE ATT&CK ↗Collected credentials, files, or host data are sent to attacker-controlled infrastructure.
MITRE ATT&CK ↗Malware targets SSH keys, wallet private keys, or other private key material.
MITRE ATT&CK ↗Malware uses DNS requests as a command-and-control or exfiltration transport.
MITRE ATT&CK ↗Malware targets browser cookies or session material for account takeover or downstream access.
MITRE ATT&CK ↗Malware uses HTTP, HTTPS, or WebSocket traffic for command-and-control or data movement.
MITRE ATT&CK ↗Malware relies on package lifecycle events, hooks, or other trigger points to execute or maintain access.
MITRE ATT&CK ↗Package names, metadata, or publishing context imitate legitimate public or private dependencies.
MITRE ATT&CK ↗Malicious code is distributed through package registry artifacts or trusted developer tooling dependencies.
MITRE ATT&CK ↗Malware executes JavaScript through npm package entrypoints, lifecycle hooks, or imported package code.
MITRE ATT&CK ↗Package code retrieves additional payloads, tools, or stage-two malware after execution.
MITRE ATT&CK ↗