{
  "Event": {
    "analysis": "1",
    "date": "2026-05-19",
    "extends_uuid": "",
    "info": "[Threat Intel] The Worm That Keeps on Digging: Latest Wave",
    "protected": false,
    "publish_timestamp": "1780196724",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1780196724",
    "uuid": "a8121f4e-198f-47f3-a649-0b881e64d745",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#52774b",
        "local": false,
        "name": "misp-galaxy:producer=\"Wiz Blog\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#8ed4a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials from Web Browsers - T1555.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#e7d11f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Private Keys - T1552.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#f95f85",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Credentials In Files - T1552.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Code Repository - T1567.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Group Policy Preferences - T1552.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#18349e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"One-Way Communication - T1102.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#978602",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Services File Permissions Weakness - T1574.010\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#57997c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Bidirectional Communication - T1102.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#7d37d8",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Python - T1059.006\"",
        "relationship_type": ""
      },
      {
        "colour": "#15723e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Launch Agent - T1543.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a0cbec",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Systemd Service - T1543.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#8d021b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Dead Drop Resolver - T1102.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:malpedia=\"Shai-Hulud\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:online-service=\"3b16bb5a-eb4f-4603-a909-bebc5df4a46d\"",
        "relationship_type": ""
      },
      {
        "colour": "#220082",
        "local": false,
        "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#230087",
        "local": false,
        "name": "rectifyq:samples-found-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418813",
        "to_ids": false,
        "type": "link",
        "uuid": "db2b5ac8-22fe-47fb-a06d-70ec3118a6c5",
        "value": "https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418813",
        "to_ids": false,
        "type": "text",
        "uuid": "a831cc02-e1a9-4a87-8eb1-4da3ae6c0e28",
        "value": "A sophisticated supply chain campaign targeting the open source developer ecosystem has emerged, compromising NPM packages in the @antv namespace, GitHub Actions including actions-cool/issues-helper, and the VSCode extension nrwl.angular-console. The malware initiates multi-stage infection chains using GitHub-hosted infrastructure and orphaned commits to deploy payloads via bun. It harvests extensive credentials including GitHub tokens, SSH keys, cloud credentials, and browser secrets, exfiltrating data through attacker-controlled public GitHub repositories. The campaign establishes persistence through a Python backdoor that polls GitHub for signed commands containing specific trigger strings, enabling remote code execution. Infrastructure analysis and operational patterns indicate moderate confidence attribution to the threat actor TeamPCP."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1779418813",
        "to_ids": false,
        "type": "text",
        "uuid": "1e429b23-f59b-421e-bb64-104626d022bd",
        "value": "Name: The Worm That Keeps on Digging: Latest Wave\nAuthor: AlienVault\nAdversary: TeamPCP\nTags: [\"npm packages\", \"supply chain attack\", \"github actions\", \"credential theft\", \"cicd compromise\", \"vscode extension\", \"backdoor persistence\", \"developer environments\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: [\"T1059.007\", \"T1539\", \"T1555.003\", \"T1552.004\", \"T1552.001\", \"T1567.001\", \"T1552.006\", \"T1102.003\", \"T1574.010\", \"T1195.002\", \"T1102.002\", \"T1059.006\", \"T1543.001\", \"T1071.001\", \"T1543.002\", \"T1105\", \"T1102.001\"]\nIndustries: [\"Technology\"]"
      },
      {
        "category": "Attribution",
        "comment": "Adversary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780140674",
        "to_ids": false,
        "type": "threat-actor",
        "uuid": "12c89651-fd54-46e7-9136-2c776994e5a1",
        "value": "TeamPCP",
        "Tag": [
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:threat-actor=\"TeamPCP\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Backup Malware C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150474",
        "to_ids": true,
        "type": "domain",
        "uuid": "26096641-6562-44c7-a5b8-98529920e422",
        "value": "m-kosche.com",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Backup Malware C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150495",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "a6190c7f-dbaa-4330-a97c-8a4a638f1a4f",
        "value": "185.95.159.32",
        "Tag": [
          {
            "colour": "#c3e702",
            "local": false,
            "name": "asn:asn=\"210644\"",
            "relationship_type": ""
          },
          {
            "colour": "#c047ce",
            "local": false,
            "name": "asn:as-owner=\"AEZA-AS\"",
            "relationship_type": ""
          },
          {
            "colour": "#e1449b",
            "local": false,
            "name": "asn:as-country=\"GB\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united kingdom\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "Backdoor polling to Github for commands",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1780150516",
        "to_ids": true,
        "type": "url",
        "uuid": "f6d7dfbc-4fac-4b7c-88a2-ad7754a6a38a",
        "value": "https://api.github.com/search/commits?q=firedalazer",
        "Tag": [
          {
            "colour": "#2c2142",
            "local": false,
            "name": "false-positive:risk=\"high\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1780150538",
        "uuid": "654859a6-ffab-4246-9301-5201af1c15ab",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "Backdoor",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1780150538",
            "to_ids": true,
            "type": "md5",
            "uuid": "8da74312-7ce4-405e-9ff6-46d6826ffd2e",
            "value": "b06b126b9e26af03a7ef2f8b8e90d446",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Backdoor",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1780149895",
            "to_ids": true,
            "type": "sha1",
            "uuid": "5706cc6d-2a56-4b19-b603-57ea0ce6bbb1",
            "value": "783b4019fc5b942a29846132d28441c8fc31bed8",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "Backdoor",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1780149895",
            "to_ids": true,
            "type": "sha256",
            "uuid": "311b9787-6052-43bf-86a9-a8097b111162",
            "value": "fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#220082",
                "local": false,
                "name": "rectifyq:samples-found-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#230087",
                "local": false,
                "name": "rectifyq:samples-found-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1780147568",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "159e3e60-9a56-48b7-8d15-217a9009847e",
            "value": "96:L2V79jNRLZ1e/MJUJga1wXn3J3WSOGb6eYPd3ZUPtW6i:La9LZ4/MJxKM3RW4bzGxZ0tvi"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1780147568",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "d7f9c99d-db57-4b34-ba19-6826e79b7b98",
            "value": "8081"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "filename",
            "timestamp": "1780147568",
            "to_ids": true,
            "type": "filename",
            "uuid": "25b7eecb-6a57-47af-b3a8-ceb741d4b30c",
            "value": "cat.py"
          },
          {
            "category": "Other",
            "comment": "Checked: 30/05/2026\nLast-scan\t:  30/05/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1780147568",
            "to_ids": false,
            "type": "text",
            "uuid": "f6bb0f83-690c-47bc-80b8-d4c7fdb6d6f6",
            "value": "Backdoor\r\nType Description: Python\nMicrosoft: Backdoor:Python/Vigorf.A\nVT Total Detection:32/62\nFirst Submission:2026-05-21T01:29:11.000000+00:00\nLast Submission:2026-05-29T08:48:32.000000+00:00"
          }
        ]
      }
    ]
  }
}