Campaign analyses from Aephix Threat Research. We link malicious packages, models, skills, MCP servers, extensions, and containers to the wider operations behind them, in the open here and every week in Sleuth.
@guangnao/claude-cli presents as a Claude API proxy but exfiltrates OAuth tokens to an XOR-obfuscated C2 hub and enrolls the victim host into a compute pool that consumes their Claude subscription.
The npm package n8n-nodes-social-facebook v0.2.0 distributes an 8 MB Go-compiled WebAssembly binary renamed from .wasm to .we that targets Facebook Business Manager tokens, user access tokens, and Ads Manager credentials through the Graph API v23.0. Quota enforcement and plan-gated access suggest credential harvesting as a managed service.
yo-steven/claude-engineer-exploration-20260613 presents as a fork of a deleted Claude coding agent but injects three dropper payloads targeting Windows (ScriptRunner.exe, mshta.exe) and Linux (curl-to-bash), alongside 13 ballast files from six unrelated projects.