Kaspersky Unmasks Sophisticated npm Supply Chain Attack: The Rise of “https-proxy-utils” and AdaptixC2

Listen to this Post

Featured Image

🎯 Introduction: A Silent Threat Hidden in Plain Sight

In the bustling world of open-source development, trust is the foundation that keeps the ecosystem alive. But in October 2025, that trust was exploited in a chilling way. Kaspersky researchers exposed a complex supply chain attack that infiltrated the npm ecosystem through a malicious package known as https-proxy-utils. What seemed like a harmless proxy utility was, in reality, a Trojan horse carrying a dangerous payload — AdaptixC2, a post-exploitation framework capable of giving hackers total control over infected systems.

This revelation marks one of the most sophisticated npm attacks in recent memory, highlighting the growing weaponization of developer tools and the rising threat of typosquatting as a method of deception.

🧩 The Attack That Shook Developers Worldwide

In October 2025, Kaspersky’s cybersecurity team unveiled a deeply engineered supply chain compromise inside the npm ecosystem, one that disguised itself with unsettling precision. The culprit was a package called https-proxy-utils, which masqueraded as a legitimate proxy utility while concealing a far more dangerous purpose.

At its core, the malicious package was programmed to deliver AdaptixC2, a powerful post-exploitation framework first seen in early 2025 and already notorious for its involvement in several high-impact cyber campaigns.

The attackers relied on a time-tested trick — typosquatting — to deceive developers. By slightly altering the names of legitimate packages, they lured victims into installing malware unknowingly. Genuine packages such as http-proxy-agent and https-proxy-agent, which collectively handle over 160 million weekly downloads, became the perfect camouflage. The impostor package https-proxy-utils imitated their naming style with near-perfect precision.

To increase authenticity, the attackers even copied genuine code from another trusted package, proxy-from-env, which has around 50 million weekly downloads. On the surface, everything looked legitimate — until the installation phase.

⚙️ The Hidden Weapon: AdaptixC2 Deployment Mechanism

The real danger began post-installation. Buried within the code was a post-install script that automatically downloaded and executed the AdaptixC2 agent, a payload designed for persistence and stealth.

The sophistication of the attack became evident in how the malware adapted across platforms:

Windows systems were hit first. The malicious script deployed a DLL file into the C:\Windows\Tasks directory, exploiting DLL sideloading by executing it through the legitimate msdtc.exe binary. This method aligns with MITRE ATT&CK technique T1574.001, a common method for achieving stealthy code execution.

macOS systems weren’t spared. The package utilized the Library/LaunchAgents directory, downloading an executable payload and creating a plist file to ensure persistence after reboot. It even detected whether the system ran on x64 or ARM architecture before delivering the matching binary.

Linux systems saw the payload stored under /tmp/.fonts-unix, where it dynamically fetched the correct architecture variant and granted it execution permissions instantly.

This cross-platform adaptability made the attack highly scalable — a single piece of code capable of infiltrating diverse environments without detection.

🚨 The Broader Implications: Growing Supply Chain Threat

Once installed, AdaptixC2 granted remote operators full control over the infected machine. Its capabilities included:

Executing remote commands

Managing files and system processes

Conducting internal network reconnaissance

Maintaining persistence through multiple reboots

This level of control effectively turned every infected developer machine into a potential launchpad for larger attacks.

The incident mirrors the earlier Shai-Hulud worm, which compromised over 500 npm packages using similar post-install scripts. Together, these attacks mark a disturbing trend — the weaponization of open-source software repositories as vectors for malware delivery.

The npm registry has since removed https-proxy-utils, but the discovery underscores a pressing truth: open-source trust is under siege. Developers, once the ecosystem’s guardians, are now its frontline targets.

Security experts urge developers and organizations to:

Double-check package names before installation.

Investigate new or low-download packages before adopting them.

Monitor security feeds and vulnerability alerts for compromised repositories.

This attack isn’t just a breach. It’s a warning.

💡 What Undercode Say:

The https-proxy-utils attack represents a turning point in the ongoing war for supply chain integrity. From an analytical perspective, the sophistication of this campaign lies not only in its technical design but also in its psychological manipulation.

Attackers have realized that developers’ trust is the ultimate vulnerability. By exploiting familiar package names and replicating real code, they’ve weaponized the very culture of open-source collaboration. Unlike phishing or brute-force attacks, supply chain breaches like this bypass traditional security layers entirely, embedding themselves deep inside the development process.

AdaptixC2, in particular, is not just another remote access tool. Its modular architecture, cross-platform support, and persistence strategies point to nation-state-level precision or a highly organized cybercrime syndicate. The payload’s flexibility to operate on Windows, macOS, and Linux shows clear intent to compromise development environments across enterprises — potentially enabling further source code tampering or credential harvesting.

This incident exposes an unsettling truth: open-source ecosystems have become battlegrounds, where every download is a potential security gamble. With over 2 million packages in the npm registry, even a small infiltration can cascade into a massive global compromise.

From a threat intelligence viewpoint, AdaptixC2’s spread pattern and infrastructure connections suggest the operators are testing persistence frameworks for future large-scale operations. Given that post-install scripts have become a recurring vector, npm’s vetting processes may soon require automated behavior analysis rather than relying solely on static scanning.

For developers, the lesson is clear:

Blind trust in open-source software must end.

Each dependency must be treated as potential attack surface.

Security hygiene — from verifying checksums to monitoring network traffic — is now a professional necessity, not a suggestion.

In broader terms, this attack may reshape how the software community perceives “trust-by-default” ecosystems. The next wave of security evolution must focus on transparent provenance, signed packages, and dependency validation systems. Without these, npm and similar repositories remain fertile ground for deception.

The AdaptixC2 campaign doesn’t just compromise code. It compromises confidence. And in cybersecurity, confidence is everything.

🔍 Fact Checker Results

✅ Kaspersky officially confirmed the discovery of the malicious npm package https-proxy-utils in October 2025.
✅ AdaptixC2 is a legitimate post-exploitation framework publicly released in early 2025 and weaponized by attackers.
✅ The malicious package was removed from the npm registry immediately after exposure.

📊 Prediction

🧠 Expect tighter npm security enforcement and the introduction of AI-based package behavior scanners within the next year.
⚙️ Post-install script abuse will remain a favored vector for cybercriminals in 2026.
🌐 Open-source ecosystems will likely adopt mandatory code-signing and supply chain trust frameworks to restore developer confidence.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon