Success Key
2026-06-16 • Checkmarx • ChainVeil: A Malicious npm Supply Chain Attack by…
SuccessKey is Checkmarx Zero’s designation for the operator of ChainVeil, a malicious npm supply-chain campaign publicly described in June 2026. The actor used the npm account successkeyteck to publish at least nine typosquatted packages containing fourteen malicious versions, targeting JavaScript developers who searched for Tailwind, Sass, TypeORM, and rate-limiting libraries. Malicious code executed when applications imported a package rather than during installation, helping it evade scanners focused on lifecycle scripts. The loader copied metadata from legitimate projects, used layered obfuscation, checked for analysis environments, and resolved rotating payloads through transactions on Tron, Aptos, and Binance Smart Chain. Its final remote-access payload supported interactive shells, arbitrary command and JavaScript execution, file theft, SSH-key and npm-token collection, macOS Keychain access, and hidden persistence in shell configuration files. Infrastructure history indicated a sustained, automated operation beginning by June 2025.
-
28
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster