Aephix accepted into the Databricks Startup Program

Research

RSS

Campaign analyses from Aephix Threat Research. We link malicious packages, models, skills, MCP servers, extensions, and containers to the wider operations behind them, in the open here and every week in Sleuth.

Latest
Threat research
Sep 17, 2026 Packages @guangnao/claude-cli: npm proxy harvests Claude credentials Sep 17, 2026 Packages n8n-nodes-social-facebook: Go WASM binary harvests Facebook Business credentials Sep 17, 2026 Agents yo-steven/claude-engineer: fork drops three payloads via LOLBin and marshal obfuscation Sep 13, 2026 Packages A11 naseemkhandev/genius-ai-model: two loaders in two config files across thirty-two infected repositories Sep 13, 2026 Packages Radeonares32/student-skill: a developer skill-test repository hides a remote code execution backdoor behind a mock API endpoint Sep 12, 2026 Packages BehemothAgent/malwarebytes: three identical repositories pair a fake macOS installer with SEO spam to redirect to a malware distribution domain Sep 12, 2026 Agents A10-*050 advance-agent: A10 campaign VSCode task trigger targets a font file that does not exist Sep 12, 2026 MCP servers animotion-mcp: MCP server repository carries a blockchain C2 dropper in its analytics backend Sep 12, 2026 MCP servers expo-mcp fork: ESLint config carries a blockchain C2 dropper after 507 whitespace characters Sep 12, 2026 Agents DeepSight-Agent: Python import loads Solana C2 payload with the watercrawl-mcp wallet and nine shared RPC endpoints Sep 12, 2026 Agents A9-0316-1 hmtahiraziz/Google-Calendar-Agent: an Ethereum C2 loader appended to build configuration files across fourteen GitHub repositories Sep 12, 2026 MCP servers A10-*050 local-mcp: VSCode task executes blockchain C2 payload disguised as a Font Awesome font Sep 12, 2026 MCP servers mcp-server-fast-mcp: committed VSCode task delivers curl-to-shell on folder open Sep 12, 2026 MCP servers stitch-mcp: PostCSS config file carries a blockchain C2 dropper triggered at build time Sep 12, 2026 MCP servers watercrawl-mcp fork: invisible Unicode characters in TypeScript source hide a Solana C2 loader Sep 12, 2026 Agents 9-1186-2 WeOwnAiAgent: obfuscated PostCSS payload triggers at build time inside an ElizaOS agent lure Sep 5, 2026 Skills Staged dropper to credential harvester: claude-skills-library ships malicious postinstall hooks across 24 npm versions Sep 5, 2026 Packages Backdoored Baileys forks: two npm packages force-follow WhatsApp channels and farm reactions Sep 5, 2026 MCP servers Trojanized MCP servers under @httttt: two packages drop a staged binary from Huawei Cloud OBS Sep 4, 2026 Packages Terminal styling decoy: chromatitle-dev downloads and runs a Windows executable on import Aug 23, 2026 MCP servers agenthub-multiagent-mcp: an MCP server that executes server-dispatched prompts in Claude Code with permissions bypassed Aug 22, 2026 Agents agentgui: supply-chain backdoor resolves C2 addresses from Ethereum wallet transactions Aug 22, 2026 Packages Tracking down your Claude: claude-team-tracker steals OAuth tokens and installs a persistent command channel Aug 5, 2026 MCP servers More than just hello: vulndify-mcp-server documents one tool and registers a code runner Aug 2, 2026 Packages An odd job perhaps: is-real-odd copies a trusted utility and adds a single postinstall line Jul 29, 2026 Agents @yancyyu/agentcli on npm: a functional CLI tool that harvests four Lark secrets on every run Jul 29, 2026 Packages crypto-checkout-api and wallet-analytics on npm: two packages load remote code through a font-awesome decoy Jul 29, 2026 Packages korvica and streak-daily-lib on npm: a transitive dependency drops a Windows persistence payload through WSL Jul 29, 2026 Packages tchain-api on npm: encrypted key material ships with the machinery to surface it but no execution Jul 15, 2026 Packages Wrapped in a familiar name: ai-pro-sdk runs a multi-stage encrypted dropper on import Jul 11, 2026 Packages Five versions in three hours: a compromised jscrambler package drops a Rust infostealer Jul 6, 2026 Packages gen-ai-opt-in and the justhunter account: ten npm packages straddle security research and namespace squatting Jul 3, 2026 MCP servers claude-token-tracker-mcp: an MCP server that harvests API keys and cloud credentials alongside token counts Jun 30, 2026 Packages anthropic-toolkit on npm: the same recon operation ships a fifth package targeting Claude developers Jun 29, 2026 Packages ollama-helpers and three AI-framework helpers on npm: identical postinstall scripts exfiltrate developer identity to one Cloud Run endpoint Jun 26, 2026 Packages ts-precision and two npm packages: Solana wallet keys exfiltrated through a trojanized big.js Jun 25, 2026 Models Pickle execution in .onnx and .gguf files: extension mismatch bypasses Hugging Face scanner coverage Jun 25, 2026 Packages Miasma One account, four ecosystems: 23 hijacked npm packages and a credential harvest