Security1 distinct publisher2 min readPublished
CloudSEK's BRIDGEHEAD report tracks forty npm typosquats whose install script tests for Windows underneath Linux, then pulls a Rust stealer that reads the host's wallets and cookies.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
WSL's boundary is a convenience for the developer, not a control for the defender, and BRIDGEHEAD reads it that way. The courier does its work inside the Linux userland where the dependency landed: profile the host, report to a command and control server, then test for a Windows machine underneath [3]. The only feature the campaign needed from the registry was the install script, which all forty packages carried [2]. Registry allowlists, lockfiles, a private mirror, a review gate on new dependencies: all of that governs what gets into the userland, which is the side of the line with nothing on it worth stealing. The paths the stealer carries resolve into the Windows user profile, including Brave directories that did not exist on the analysis machine [15], and by the time CloudSEK captured guest memory it had already built a hardware profile of the box and staged the multipart header for the upload [16].
The takedown record is the part to take into a vendor conversation. According to CloudSEK the two halves of the campaign had opposite lifespans: the npm layer cheap and disposable, the payload layer one GitHub release asset plus a route out through a public file host, and the unpublishing touched neither [17]. Across the window observed on 17 August the asset was being pulled at roughly 3.2 times an hour with no live package left to advertise it [19]. It stopped being available when the bebraz1 account itself returned 404, four hours after the last reading and only because analysts were watching [8]. CloudSEK's own summary is that the npm takedown left the weapon in place [9].
The file is also a lesson in what size tells you. 265 kilobytes of the 22 megabyte binary is code, and 98.6 per cent of it is one unbroken run of 22,638,592 hexadecimal characters [10], which decode to 11,319,296 bytes of encrypted stage [20]. A Rust executable that is roughly one per cent program and the rest a hex string is an anomaly a build or download pipeline could measure by arithmetic alone, and it is close to the only static signal on offer, because the runtime behaviour is designed to produce none [11]. The upload lands on gofile.io, which CloudSEK points out is a legitimate service and cannot be seized the way a criminal domain can [13].
One caveat on sourcing: this is CloudSEK's investigation, published 20 August 2026 [18], and the packages are already gone [1], so the forty-name list is no longer checkable against the live registry.
Ranked by verification strength, evidence, and original report placement.
In August 2026 an operator published forty packages to the public npm registry, each a misspelling of a heavily installed library: chalk, axios, commander, lodash, react and typescript. The packages have since been removed.
The GitHub payload outlived the npm packages by roughly 39 hours.
The payload's download counter was observed rising from 119 at 01:50 UTC on 17 August to 173 by 18:49 UTC the same day, 54 pulls, after the packages that pointed at it had ceased to exist.
CloudSEK states that the npm takedown, on its own, left the weapon in place.
CloudSEK describes the campaign as two layers with opposite lifespans: a loud, cheap, disposable npm layer of forty impersonation packages, and a quiet, durable payload layer of one Rust executable on GitHub plus one exfiltration route through a public file host, neither of which the npm takedown affected.
Every one of the forty npm packages carried an install script.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed primary forensics, single vendor, partly non-reproducible
The report describes first-hand method - archived copies of the removed packages, a hash-verified sample, detonation in an isolated Windows environment, and guest-memory capture of the unwrapped stage - and reports specific, checkable quantities (265 KB of code, 22,638,592 hex characters, 26 wallet paths, counter 119 to 173). That is strong for technical mechanics. It is capped by there being exactly one publisher, who is also the discoverer, by the report's own admission that the GitHub timeline and counter metadata can no longer be re-derived, and by the absence in the supplied text of the package list, hashes or IOCs that would let a third party verify.
Small confirmed pull volume, no victim data
There is real measured exposure rather than none: forty packages reached the public registry, and the payload asset's counter moved from 119 to 173 while no package pointed at it, which is 54 pulls in under seventeen hours. But the npm courier layer lived only 84 minutes, no npm install counts are given, and none of the 173 pulls is tied to a confirmed compromised developer machine - researchers, mirrors and crawlers are not excluded. Real-world impact is therefore small in what is proven and unknown in what is plausible.
Mildly overstated framing on well-documented mechanics
The technical claims are documented at a level that matches or exceeds the framing, and the central defender point - that a registry takedown left the payload and exfiltration route untouched - is directly supported by the 39-hour survival, the moving counter and the late account 404. The overstatement is at the edges: 'the weapon in place' and 'BRIDGEHEAD' framing imply operational impact that the evidence does not size, since no victim, install or successful-exfiltration count is offered and the raw counter includes pulls of unknown origin. The two-layer deliberate-staging narrative is explicitly flagged by the vendor as its reading, which restrains the gap.
Vendor-authored, self-discovered, brand-forward
The sole source is a commercial threat-intelligence vendor reporting its own investigation under its own campaign codename, on a page that carries a funding-milestone banner and a newsletter subscription prompt. CloudSEK is simultaneously the discoverer, the analyst, the arbiter of what evidence is shown, and the commercial beneficiary of the conclusion that existing registry-level controls are insufficient. That is a strong and undisclosed-in-practice alignment between finding and product narrative, even though the technical detail supplied is unusually specific.
Credible mechanics, unreplicated single source
Confidence is moderate: the execution-order analysis is internally consistent and the arithmetic checks out (22,638,592 hex characters decode to 11,319,296 bytes; 119 to 173 over 16h59m is ~3.2 pulls/hour), which supports the mechanics. It is held down by one publisher with a commercial stake, artefacts that cannot be re-derived, no third-party or registry confirmation of the takedown timeline, and no impact measurement. The mechanism claims deserve more trust than the significance claims.
security
A manifest edit, not a code edit: North Korea backdoored three Rust crates via typosquat1 distinct publisher
product
The arrayref compromise turned cargo update into the delivery channel1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
product
Cloudsmith's cooldown policies make delay a control, and that makes it your decision1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.