True Positive Mar 31, 2026

Hunting an npm Supply Chain Attack: axios and UNC1069

Endpoints that ran npm install resolving axios@1.14.1 or axios@0.30.4 between 2026-03-31 00:21 and ~03:15 UTC executed a cross-platform RAT dropper. The postinstall hook, C2 connections, and platform-specific payloads are detectable in default EDR telemetry.

Full dropper chain and RAT execution confirmed via controlled detonation. No customer impact. Built behavioral D&R rules for npm postinstall abuse and cross-platform RAT delivery.

LimaCharlie T1195.002 T1059.007 T1036.005 T1070.004 T1571
Read full writeup →
True Positive Mar 29, 2026

Hunting a PyPI Supply Chain Attack: LiteLLM and TeamPCP

Endpoints that installed litellm v1.82.7 or v1.82.8 from PyPI on March 24 are compromised. The .pth trigger, openssl encryption chain, and systemd persistence are detectable in EDR telemetry.

Caught the .pth auto-exec trigger and openssl encryption pipeline on a compromised host. Built behavioral queries that detect the technique independent of IOCs.

LimaCharlie T1195.002 T1546.018 T1552.001 T1573.001 T1543.002 T1041
Read full writeup →
True Positive Mar 19, 2026

Hunting DeerStealer: DLL Sideloading Through Signed Binaries

Unsigned binaries and DLLs appearing in ProgramData subfolders that don't belong to known, installed software indicate DLL sideloading activity.

Found a DeerStealer variant using a Comodo-signed binary sideloading cmdres.dll, with HijackLoader injecting DeerStealer into a hollowed Q-Dir process.

LimaCharlie T1218.007 T1574.002 T1036.005 T1555.003 T1539
Read full writeup →

Want to talk hunting?

Always down to connect about threat hunting methodologies, tooling, or anything security.

Get In Touch