🚀 A CloudSEK se torna a primeira empresa de segurança cibernética de origem indiana a receber investimentos da
Leia mais

On 15 September 2026, between 15:36:25 and 15:39:38 UTC, a single npm account named prime0 published 85 packages under the scope @prime0. Every name is a one or two character misspelling of one of 29 of the registry's most downloaded libraries, among them chalk, semver, debug, minimatch and ajv, and every one of the 84 packages CloudSEK archived carries the same remote command code. CloudSEK's supply chain monitoring ingested all 85 as they were published. 3 of them appear in public malicious package advisories; the other 82 do not, and the scope has since been removed from the registry. Read one at a time, each package is a typosquat of the library it imitates. That reading is correct but incomplete, because a mistyped install cannot reach a scoped name, and the names were built for a different route. The package's C2 host, 69.48.229.140, also runs a separate service: a live GPU-cryptojacking panel targeting the vast.ai marketplace, documented in the next report. What ties the two is the shared host and, at the confidence set out below, the operator; the npm implant is a generic command agent, no evidence shows it feeding the GPU operation, and the two hit different victims, so the established relationship is shared infrastructure rather than one campaign driving the other.
The names of all the typosquatting packages were generated using an algorithm. The generator deletes one of a library name's first three characters, and only where that deletion is already a registered unscoped package does it fall back to another one character edit, such as a neighbouring key: chalk becomes dhalk, fhalk and xhalk because calk, chlk and halk are taken. The result is 85 names, not one of which has an unscoped owner. A developer who types "npm install fhalk" gets a ‘not found’ error. The same typo entered in npm's search or in an editor's package autocomplete would put @prime0/fhalk at the top of the results, because the search ranks a scoped package first when no unscoped package carries the name. The code is a template whose header comment still reads "<PKGNAME>", a placeholder that was never filled in. Installing a package sends a fingerprint of the host to 69.48.229.140 on port 8080. Loading it into a program starts an agent that asks the same server for a shell command every 30 seconds, runs it and returns the output. There is no targeting condition, no encryption and no authentication.
It is recommended to block 69.48.229.140 at egress and search dependency manifests and lockfiles for any reference to @prime0. Treat a machine that only installed one of these packages as having disclosed its host details, and a machine or build runner where a program loaded one as having run an operator controlled command channel for as long as that program ran. Detection should key on the shipped code and the network sequence rather than on the package names, which are generated and disposable. Nothing in this analysis evidences a successful compromise, and whether any developer found these packages through search is not established.