Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception — Threadlinqs Intelligence
As of 2026-09-02, Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception is a high-severity supply chain threat attributed to STARDUST CHOLLIMA (DPRK-nexus (North Korea (STARDUST CHOLLIMA); unattributed/eCrime (ALTERED SPIDER)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-2294 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: STARDUST CHOLLIMA (DPRK-nexus · North Korea (STARDUST CHOLLIMA); unattributed/eCrime (ALTERED SPIDER) · FINANCIAL
DPRK-nexus STARDUST CHOLLIMA (aka Lazarus Group/Bluenoroff) poisoned 131+ Mastra AI framework npm packages via a typosquatted dependency, and eCrime actor ALTERED SPIDER (aka TeamPCP) ran a
CrowdStrike's 2026 Threat Hunting Report (published 2026-08-03) named two distinct, high-volume open-source supply chain campaigns as the trigger for a new Falcon sensor capability that intercepts and quarantines poisoned package downloads before execution. On 2026-09-02, CrowdStrike detailed this endpoint-embedded protection, framing the problem around agentic AI tools (Claude Code, ChatGPT Codex, and similar coding agents) that auto-download npm/PyPI dependencies on behalf of non-developer staff, expanding the population of endpoints exposed to a poisoned install beyond traditional developer workstations.
STARDUST CHOLLIMA, a DPRK-nexus (North Korea) financially-motivated intrusion set publicly overlapping with Lazarus Group and Bluenoroff, has run at least two documented 2026 campaigns against the npm ecosystem. On 2026-03-31, the group used stolen maintainer credentials to inject the cross-platform ZshBucket implant into the widely-used axios HTTP client package (CrowdStrike attributes this with moderate confidence, citing infrastructure overlap with prior STARDUST CHOLLIMA operations as well as shared hosting with FAMOUS CHOLLIMA's InvisibleFerret malware). On 2026-06-17, over an 88-minute automated window (01:12-02:39 UTC), the group hijacked a maintainer account and republished 131-142 packages across the @mastra npm scope (a popular AI-agent framework, combined weekly downloads over 1.1M) with a single injected dependency, easy-day-js — a typosquat of the dayjs date library carrying an obfuscated postinstall dropper that fetched a second-stage payload and then deleted itself.
ALTERED SPIDER (publicly tracked as TeamPCP), an eCrime actor active since at least November 2025, escalated in 2026 to a self-propagating, credential-stealing npm/PyPI worm lineage related to the 'Shai-Hulud' family. On 2026-05-19, a wave dubbed 'Mini Shai-Hulud' compromised the @antv namespace and 300+ npm packages (128K+ weekly downloads) in a 22-minute automated burst (01:39-02:06 UTC), using a bun-executed obfuscated payload (CanisterWorm) that harvested npm tokens, GitHub PATs, SSH keys, and cloud/CI-CD credentials, then re-published itself to every package reachable with the stolen tokens and exfiltrated secrets to newly-created public GitHub repositories. A later wave (publicly reported as CHAINDROP, disclosed around 2026-08-06 and reflected in a Singapore CSA advisory) hit the keyv cache-utility monorepo and 400+ related packages (1,300+ versions, ~2B monthly downloads), adding persistence via VS Code tasks.json and Claude Code's .claude/settings.json SessionStart hook, plus C2 address resolution through an Ethereum smart-contract resolver as a takedown-resistant fallback.
A thematically related but organizationally distinct campaign, PromptMink (disclosed by ReversingLabs on 2026-04-29 and attributed to Famous Chollima, a sibling DPRK cluster also tracked as Void Dokkaebi/PurpleBravo/UNC5342), demonstrates the specific AI-agent-targeting mechanism CrowdStrike's announcement warns about: packages engineered (polished READMEs, complete TypeScript typings, binary-obfuscated payloads) to be autonomously selected and installed by LLM coding agents rather than human developers, with at least one confirmed case of an agent installing the credential-stealing dependency with no human review, prompt injection, or jailbreak involved.
Weaknesses (CWE)
CWE-829, CWE-494
Target sectors: technology, software development, financial services, cryptocurrency, cloud services, artificial intelligence
Target regions: Global
Timeline
- ALTERED SPIDER (publicly tracked as TeamPCP) first observed active as an eCrime supply-chain actor.
- IP 23.254.203.244 confirmed as STARDUST CHOLLIMA infrastructure, later reused in the Axios compromise.
- STARDUST CHOLLIMA uses stolen maintainer credentials to inject ZshBucket malware into the axios npm package (v1.14.1), the first observed cross-platform (Windows/macOS/Linux) ZshBucket deployment.
- ReversingLabs discloses PromptMink, a related DPRK-nexus (Famous Chollima) campaign engineering npm/PyPI packages specifically to be autonomously installed by LLM coding agents.
- ALTERED SPIDER's Mini Shai-Hulud/CanisterWorm campaign compromises 300+ npm package versions across the @antv namespace in a 22-minute automated burst (01:39-02:06 UTC).
- STARDUST CHOLLIMA hijacks an npm maintainer account and republishes 131-142 @mastra AI-framework packages with the easy-day-js typosquat dependency over an 88-minute window (01:12-02:39 UTC).
- CrowdStrike publishes its 2026 Threat Hunting Report, publicly naming both the STARDUST CHOLLIMA (131 packages) and ALTERED SPIDER (300+ packages/day) campaigns.
- A further Shai-Hulud-lineage wave (CHAINDROP) compromises the keyv monorepo and 400+ related packages (1,300+ versions); Singapore CSA issues advisory AD-2026-009.
- CrowdStrike announces real-time supply chain attack protection embedded in the Falcon sensor, citing both named campaigns and the growing role of agentic AI tools in expanding package-download exposure.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1588.002, T1195.001, T1195.002, T1059.007, T1059.006, T1546, T1027, T1070.004, T1552.001, T1552.004