{
  "Event": {
    "analysis": "1",
    "date": "2026-05-14",
    "extends_uuid": "",
    "info": "[Threat Intel] Inside a Tor Backed Supply Chain Worm",
    "protected": false,
    "publish_timestamp": "1780284549",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780284549",
    "uuid": "76c07ddc-0f70-481e-9f63-c99aef0650b6",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#7bf409",
        "local": false,
        "name": "misp-galaxy:producer=\"CloudSEK\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Host Software Binary - T1554\"",
        "relationship_type": ""
      },
      {
        "colour": "#a0cbec",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#5780f7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Default Accounts - T1078.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Local Account - T1087.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Group Policy Preferences - T1552.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#7541db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Service Session Hijacking - T1563\"",
        "relationship_type": ""
      },
      {
        "colour": "#71ecdb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Account Manipulation - T1098\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Multi-hop Proxy - T1090.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d37d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#161c8d",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Setuid and Setgid - T1548.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#57b2ae",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Resource Hijacking - T1496\"",
        "relationship_type": ""
      },
      {
        "colour": "#68f2ff",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Data from Local System - T1005\"",
        "relationship_type": ""
      },
      {
        "colour": "#a9f8b1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over C2 Channel - T1041\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418854",
        "to_ids": false,
        "type": "link",
        "uuid": "96510902-356f-433a-b8d9-008f3ff17c01",
        "value": "https://www.cloudsek.com/blog/inside-a-tor-backed-supply-chain-worm"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418854",
        "to_ids": false,
        "type": "text",
        "uuid": "a4d4a7e6-2c41-4094-a7c4-2bf241c11957",
        "value": "A sophisticated npm supply chain attack was uncovered involving the typosquatted package crypto-javascri, designed to mimic the legitimate crypto-js library. The malware harvests npm and GitHub credentials from infected systems, hijacks maintainer accounts, and automatically republishes trojanized versions of packages under trusted identities. The final payload incorporates a weaponized Arti Tor client with credential theft, cryptomining capabilities, privilege escalation via SUID exploitation, and systemd-based persistence mechanisms. The campaign specifically targets Linux developer systems and CI/CD environments, using Tor-based command-and-control infrastructure to maintain anonymity and resilience. The attack creates significant downstream supply chain risk through its worm-like propagation model."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418854",
        "to_ids": false,
        "type": "text",
        "uuid": "b5c6ef7a-5ddf-4a3d-abbf-dac54ba6d8b5",
        "value": "Name: Inside a Tor Backed Supply Chain Worm\nAuthor: AlienVault\nAdversary: Sukob\nTags: [\"typosquatting\", \"npm\", \"supply chain attack\", \"Tor C2\", \"credential theft\", \"cryptomining\", \"privilege escalation\", \"worm propagation\"]\nTgtd countries: []\nMlwr families: [\"crypto-javascri\", \"Arti\"]\nAttack_ids: [\"T1195.002\", \"T1554\", \"T1543.002\", \"T1027\", \"T1078.004\", \"T1078.001\", \"T1087.001\", \"T1552.001\", \"T1552.006\", \"T1563\", \"T1098\", \"T1036.005\", \"T1090.003\", \"T1071.001\", \"T1059.006\", \"T1548.001\", \"T1496\", \"T1005\", \"T1041\"]\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418854",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "bfc6b3c1-d63d-4588-b80c-e610194e77f6",
        "value": "Sukob"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780199731",
        "to_ids": true,
        "type": "domain",
        "uuid": "49610465-700f-4880-a453-f93e7f2ca482",
        "value": "1cpur2zdsv762uzyoyzma6pvzz4a2xhv64zdouxpjlu3exyks7gh7leyd.onion",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}