#ChainVeil

Incident/Operation

2026-06-16 • ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey

ChainVeil was a malicious npm supply-chain campaign first reported in June 2026 and attributed by its discoverers to an actor tracked as SuccessKey. At least nine typosquatted packages targeted JavaScript developers using Tailwind, Sass, TypeORM, and rate-limiting libraries, executing obfuscated code when imported rather than through installation hooks. The loader resolved encrypted stages through a multi-tier blockchain command channel and delivered a remote-access trojan. Shared wallets, encryption keys, architecture, and final payload linked ChainVeil with ViteVenom at high confidence; separate analysis assessed both as components of the North Korean Lazarus Group’s PolinRider campaign.

Tagged Reports

« Back