Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy

PremiumReviewedSigma · Medium · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Cred Access → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Impact

What it detects

This rule detects HTTP POST requests to the Injective testnet gRPC-web telemetry host abused as command-and-control by the trojanized @injectivelabs/sdk-ts npm package. The backdoor base64-encodes wallet mnemonics and private keys derived in PrivateKey.ts and exfiltrates them in the request payload. Detecting this outbound beacon is critical because it represents active theft of cryptocurrency credentials from developer and CI environments.

Related detections9 linkedT1041 — drag to rearrange
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Windows Process Execution of Common Tunneling Tools (httptunnel, plink, socat, stunnel)
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Suspicious C2 Beacon with Legacy MSIE User Agent
Malicious HTTP User Agent zzhbot From Docker API Compromise
Suspicious Process Memory Secret Dump via proc mem
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.