Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

AdaptixC2 Emerges in npm Supply-Chain Exploit Against Developers

Cybersecurity researchers at Kaspersky have uncovered a sophisticated supply chain attack targeting the npm ecosystem. Threat actors distributed the AdaptixC2 post-exploitation framework through a malicious package disguised as a legitimate proxy utility.

Cybersecurity researchers at Kaspersky have uncovered a sophisticated supply chain attack targeting the npm ecosystem. Threat actors distributed the AdaptixC2 post-exploitation framework through a malicious package disguised as a legitimate proxy utility.

This discovery highlights the increasing risk of open-source software repositories being used as attack vectors for delivering advanced malware.

In October 2025, Kaspersky experts identified a malicious npm package named "https-proxy-utils," designed to deceive developers into installing malware on their systems. The package mimicked legitimate proxy-related utilities, presenting itself as a tool for managing proxies within development projects.

The threat actors enhanced its credibility by cloning functionality from "proxy-from-env," a popular legitimate package with approximately 50 million weekly downloads.

The malicious package's name was crafted to resemble trusted packages like "http-proxy-agent" and "https-proxy-agent," which collectively receive over 160 million downloads per week. This typosquatting technique exploits developers who may accidentally install the wrong package or fail to verify package names carefully.

Although the malicious package has been removed from the npm registry, the incident demonstrates how attackers can exploit the trust developers place in open-source ecosystems.

The attack was notable for its sophisticated multi-platform delivery mechanism. The malicious package contained a post-install script that automatically executed upon installation, downloading and deploying the AdaptixC2 agent tailored to the victim's operating system.

Cybersecurity researchers at Kaspersky have uncovered a sophisticated supply chain attack targeting the npm ecosystem.
Danielle Frost · Thehackingpost

AdaptixC2, publicly available since early 2025, serves as an alternative to the Cobalt Strike post-exploitation framework and was first observed being used maliciously in spring 2025.

For Windows systems, the attack used DLL sideloading techniques by dropping the AdaptixC2 agent as a DLL file into the C:\Windows\Tasks directory. It then copied the legitimate "msdtc.exe" file to the same location and executed it, which loaded the malicious DLL.

On macOS, the payload was downloaded as an executable into the Library/LaunchAgents directory, with a plist configuration file for persistence. The script detected whether the system was running x64 or ARM architecture and fetched the appropriate payload variant.

Linux systems were targeted differently, with the framework's agent being downloaded into the /tmp/.fonts-unix temporary directory. Similar to the macOS implementation, the script delivered architecture-specific binary files for x64 or ARM systems and assigned execute permissions to enable the malware to run.

Once deployed, the AdaptixC2 framework provides attackers with extensive capabilities, including remote access, command execution, file and process management, and multiple persistence methods. These features allow threat actors to maintain continuous access to compromised systems, conduct network reconnaissance, and deploy additional attack stages. The framework can transform a developer's machine into a foothold for broader network infiltration.

Advertisement

This incident is part of a trend of supply chain attacks targeting npm. A month prior to this discovery, the Shai-Hulud worm infected more than 500 npm packages using similar post-install script techniques.

These incidents underscore how threat actors increasingly exploit the trusted open-source supply chain to distribute post-exploitation frameworks and other malware. Organizations and developers who rely on npm packages in their products face significant exposure to these threats.

Security experts recommend several protective measures for developers and organizations using open-source software. Users should verify package names before installation, thoroughly vet unpopular and newly created repositories, and monitor updated feeds on compromised packages and libraries.

The AdaptixC2 incident serves as a reminder that even routine development activities like installing dependencies can become entry points for sophisticated cyberattacks when proper security practices are not followed.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories