Discussion about this post

User's avatar
Neural Foundry's avatar

Clever exploitation of developer trust in the npm ecosytem. The typosquating approach mimicking bitcoinjs-lib combined with post-install scripts to pull the payload is textbok supply chain attack stuff. Using Discord for C2 is pragmatic since its traffic blends into normal devloper workflows and encryped channels make detection harder. Worth noting this hits at the intersection of two high-value targets: crypto developers who likely hold keys and devs building financial infrastructure.

Expand full comment

No posts

Ready for more?