s1rx-dev is the identified publisher of a malicious npm package used in a software supply-chain compromise. The package impersonated a popular JavaScript formatting dependency through typosquatting and was designed to infect Windows developer or end-user systems after installation. Its embedded JavaScript loader was obfuscated and deployed a secondary executable payload to the Windows Startup folder, establishing persistence while disguising the payload as a legitimate application component. The malware then executed the dropped payload and harvested saved browser credentials, including enterprise account credentials, indicating a credential-theft and data-exfiltration objective. Observed tradecraft includes initial access via a malicious package repository upload, defense evasion through obfuscation and masquerading, persistence through Startup-folder execution, and post-compromise theft of stored credentials from Chrome. Based on the available evidence, s1rx-dev is best characterized as a financially motivated supply-chain threat actor or malicious package publisher rather than a formally attributed nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.