JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Drops — Threadlinqs Intelligence
As of 2026-06-28, JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Drops is a critical-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0987 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Sophisticated supply chain attack exploiting two hijacked npm packages (html-to-gutenberg v4.2.11, fetch-page-assets v1.2.9) and 16 compromised Go packages to deploy multi-stage credential and
JadeSnow represents a sophisticated multi-vector supply chain attack discovered June 2026 that compromised the npm and Go package ecosystems. The attack exploits VSCode folder-open tasks configured with runOn: 'folderOpen' to auto-execute hidden JavaScript payloads when developers open malicious projects, circumventing npm v12 lifecycle script security hardening.
The attack chain comprises five linked stages. Stage 1 (Fake Font Loader) executes JavaScript disguised as a WOFF2 font file and retrieves encrypted payloads from blockchain transaction dead drops (Tron, Aptos, BSC JSON-RPC). Stage 2 (Boot Payload) decodes XOR-encrypted payloads and connects to attacker C2 infrastructure (166.88.134.62, 198.105.127.210, 23.27.202.27) using victim-marker HTTP headers. Stage 3 (Socket.io Backdoor) establishes persistent interactive access via socket.io library with full command execution, clipboard access, and arbitrary code execution. Stage 4 (Runtime Bootstrapper) creates user-level npm dependency directories (~/.node_modules) and loads a Python interpreter, downloading python.zip/python.7z from attacker infrastructure if missing. Stage 5 (Python Infostealer) performs comprehensive credential harvesting across Chromium browsers (Chrome, Edge, Brave, Vivaldi, Opera, Arc, Comet, Dia), Firefox, 30+ cryptocurrency wallets (MetaMask, Phantom, Trust Wallet, Binance, Coinbase, OKX, Ledger, Trezor, etc.), password managers (1Password, LastPass, Bitwarden, Keeper, RoboForm, Proton Pass, NordPass), and developer credentials (Git, GitHub, VS Code global storage, SSH keys, cloud provider tokens).
The npm packages were uploaded May 25, 2026; the discovery came June 24, 2026, by which time attacker infrastructure remained active. Sixteen additional Go packages were compromised using identical malicious payload structure, spanning legitimate projects with recent commits in 2023-2026. The attack avoids common detection by leveraging public blockchain APIs for payload exfiltration, creating a resilient command-and-control layer that persists as long as blockchain services remain accessible. Collected data is staged in %USERPROFILE%\.npm (Windows) or /tmp/.npm (Linux/macOS), encrypted, and uploaded via HTTP POST to C2 endpoints or Telegram bot APIs. The attacker utilizes dynamic Telegram bot tokens returned by C2 endpoints, creating an additional exfiltration channel that bypasses traditional email-based defenses.
Weaknesses (CWE)
CWE-95, CWE-94, CWE-426, CWE-427, CWE-829, CWE-200, CWE-502, CWE-347
Target sectors: software-development, financial-services, cryptocurrency-exchanges, cryptocurrency-wallets, password-management, saas, infrastructure
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1195, T1195, T1204, T1059, T1059, T1059, T1203, T1547, T1547, T1027