H-ISAC TLP White: NPM IconBurst Supply Chain Attack Campaign: A Brief Overview

June 2022

In response to a detailed investigation into the IconBurst supply chain attack campaign conducted by Reversing Labs, Health-ISAC is releasing this brief overview of the IconBurst campaign. This campaign is actively targeting developers at the third stage of the software development lifecycle (SDLC), systems design. The final objective of this campaign is to embed as many applications with malicious package managers. 

The brief overview includes the following: 

  • Initial Incorporation
  • Typo Squatting
  • Data Exfiltration
  • Threat Actor Information

​​​​​​​See the detailed report below.