Dependency-confusion packages (SafeDep actor handle sl4x0) that mimic the private/internal package names of specific enterprises (Hyatt, Schedaero, Coca-Cola, Genoma, Anduril, Goldman Sachs and others) and beacon host and environment data out-of-band to attacker-controlled collectors. All publisher accounts use emails on sl4x0.xyz; the npm loader family exfiltrates via dns.resolve4() to oob.sl4x0.xyz. Some waves publish generic (untargeted) install-beacon packages that match no identified enterprise namespace.
Objective
Achieve code execution inside targeted organizations by winning the public/private package name resolution race.
Packages
- npm chrome-api-utilsattributed-to
- npm grafana-sentry-datasourceattributed-to
- npm @patternfly-v5/patternflyattributed-to
- npm electron-builder-13attributed-to
- npm graphql.vscode-graphql-syntaxattributed-to
- npm mattermost-cloudnative-bootstrapperattributed-to
- npm hyatt-residential-rosterattributed-to
- npm hyatt-albumattributed-to
- npm hyatt-avatarattributed-to
- npm @Schedaero/sharedattributed-to
- npm oc-aa-module-clientattributed-to
- npm @wame/ngx-adfsattributed-to
- npm @the-coca-cola-company/ngps-global-common-utilsattributed-to
- npm cr-static-shared-componentsattributed-to
- npm @ceeferenderer/fe-renderer-sdkattributed-to
- npm @genoma-ui/componentsattributed-to
- npm rrweb-v1attributed-to
- npm @needl-ai/commonattributed-to
- npm @flex-ng/error-componentattributed-to
- npm @flex-ng/filter-pipeattributed-to
- npm @flex-ng/header-componentattributed-to
- npm @idms-corp/auth-uiattributed-to
- npm @logdna-web/sharedattributed-to
- npm @logdna-web/stylesattributed-to
- npm tme-xcaattributed-to
- npm tme-xca-reactattributed-to
- npm tme-errorattributed-to
- npm enbd-react-loggerattributed-to
- npm enbd-react-error-boundryattributed-to
- npm enbd-react-libattributed-to
- npm box-react-uixattributed-to
- npm sams-sr-sdk-h5attributed-to
- npm chat-adapter-zoomattributed-to
- npm salesforce-vscode-sldsattributed-to
- npm slds-lsp-clientattributed-to
- npm gs-uitk-testing-utilsattributed-to
- npm gs-uitk-object-utilsattributed-to
- npm uploader-frontendattributed-to
- npm uploader-frontend-legacyattributed-to
Indicators
- email [email protected]indicates
- email [email protected]indicates
- file_path lib/6ad264.jsindicates
- file_path lib/b02e30.jsindicates
- email [email protected]indicates
- file_path lib/core.jsindicates
- sha256 ce42880a5be86ce5b7db2e4ce47b04b233308f6e0c0ffff9c9da7a8b39ca5a3findicates
- sha256 397d1435e7291ed6b02b8627033a110124d250a54290b3a8f9f248573fd6a2d4indicates
- sha256 7e5dffc0070dfd23371f2f41227b1e3b0f81b85bfaf4fe87e35c5c64e5ddd748indicates
- sha256 95ed14077ba3da5517e8b1816a38f3961cebd6f6fb84c86b1bd77ab0a4dcdff4indicates
- sha256 0247cc50a0a57a241e6eda6714516e5864f23389977049c30052cfb3a69abd2findicates
- email [email protected]exfiltrates-to
- domain 64.227.183.144communicates-with
- ipv4 64.227.183.144communicates-with
- email [email protected]exfiltrates-to
- domain o4510485815754752.ingest.us.sentry.iocommunicates-with
- url https://o4510485815754752.ingest.us.sentry.io/api/4511632071262208/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511630867824640/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511632708141056/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511630928838656/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511621197856768/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511675212038149/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511664042999808/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511709729914880/envelope/exfiltrates-to
- url https://o4510485815754752.ingest.us.sentry.io/api/4511716882972672/envelope/exfiltrates-to
- domain oob.sl4x0.xyzexfiltrates-to
Techniques
- ttp T1195.001 Compromise Software Dependencies and Development Toolsuses
- ttp T1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttp T1036 Masqueradinguses
- ttp T1105 Ingress Tool Transferuses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1546 Event Triggered Executionuses
- ttp T1552.001 Unsecured Credentials: Credentials In Filesuses
- ttp T1041 Exfiltration Over C2 Channeluses
- ttp T1016 System Network Configuration Discoveryuses
- ttp T1082 System Information Discoveryuses
- ttp T1102 Web Serviceuses
- ttp T1071.004 Application Layer Protocol: DNSuses