# Reputation Radar #12: Manufactured Trust > This week's malware didn't wait for a click. One npm operation faked hundreds of millions of downloads to look trustworthy; another crew hid stealers inside genuine Claude and ChatGPT share links. The trust was real. The code riding on it wasn't. - Published: 2026-09-23 - Author: Reput.io Team - Tags: Threat Intelligence, Infrastructure Reputation, SOC, Weekly Report - Canonical: https://www.reput.io/blog/reputation-radar-12 --- Last week's trick asked you to click something. This week's didn't need you to. You ran `npm install` like you do every day, or you opened a shared AI chat a colleague sent you, and the payload arrived through a front door you never think to question. The shift is subtle and it matters. A phishing link is something you can be trained to distrust. A **package in a registry you pull from a hundred times a day**, or a link on a domain you've allowlisted since forever, is not. Two campaigns this week ran on exactly that gap, and one of them went a step further: it didn't just borrow a trust signal, it **manufactured one**. ## The download count was the lie A developer vetting an unfamiliar npm package usually glances at one number first: weekly downloads. Lots of downloads, lots of eyes, probably fine. That instinct is now a targeting mechanism. That is roughly what happened here. JFrog spent six months tracking an npm operation they named **Equation of Compromise**: two dozen packages dressed up as maths and finance libraries, showing **more than 370 million downloads between them**. Almost none of those downloads were real people. The crew had wired up a farm of throwaway GitHub repos that did nothing but re-install the packages in a loop, day after day, until the counter said "trusted". The reputation wasn't earned. It was printed. One package from the same batch, `indexed-btree`, got a closer look from Checkmarx, and it shows how careful these people are. It borrowed the name of a real utility, `sorted-btree`, so a tired glance would read right past it. Then it did something clever: it left the install step completely clean. Most tools that scan for a bad package watch what happens during `npm install`. This one had nothing there to find. The malicious code sat dormant inside the library and only woke up later, when your own application actually called it. By then the install was long over and nobody was watching. Checkmarx summed it up plainly: it *"runs entirely from application code at runtime."* Once awake, it did the usual: sized up the machine, phoned home over Slack and Telegram, and fetched its next stage from a blockchain contract so there was no server to take down. The operators walked away with about a quarter of a million euros in crypto before the packages came off npm. The money isn't the interesting part. What should worry a SOC is that every shortcut we use to decide a package is safe, the download count, the familiar-looking name, the quiet install log, was either faked or deliberately dodged. ## The platform was real. That was the point. The second campaign didn't fake anything. It used the genuine article. NSFOCUS documented a wave of infostealer infections delivered through **legitimate AI platforms**, and the variety is the point. Some victims clicked a Bing ad for "Claude Desktop" that led to a malicious **Claude Artifact**. Others followed a `claude.ai/share` link that read like an Apple Support guide and talked them into pasting a stealer into their Mac. Others just searched "how to clear disk space on macOS" and landed on a poisoned **ChatGPT or Grok conversation** that handed back the malware. Different doors, same building: nearly thirty organizations were hit. The researchers' own conclusion is the line to keep: *"None of these three attack vectors breached the security mechanisms of the AI platforms themselves; instead, they exploited users' trust in familiar brands and legitimate domains."* The malware sat on real `claude.ai` and `chatgpt.com` URLs. A domain-reputation check waves those through, correctly, because the platform genuinely is trustworthy. The thing that wasn't trustworthy was the specific artifact served under its name, and no reputation lookup on the domain will ever tell you that. ## What the reputation column shows We ran the platforms from both stories through our own API to see what a SOC actually gets back, and the interesting part is where the answers diverge. `claude.ai` comes back **likely_benign**, labelled a first-party AI service. That's the right call: Anthropic doesn't resell general hosting on that domain, so the traffic is near-certainly real API usage. `npmjs.com` lands **likely_benign** too, flagged as a Microsoft-owned corporate property. Both are legitimate, and pretending otherwise would just be noise. The registry and the model hub read differently. `registry.npmjs.org` holds at **investigate**, with a plain note: *"Popularity alone isn't trust. Check what the domain actually does."* `huggingface.co` holds at **investigate** too, and its hint could be the summary of this whole issue: *"Identify the specific model, Space, or repo behind the request, not just the platform."* The line between the two groups is simple. A first-party API is only as trustworthy as the company that runs it. A registry or a model hub is only as trustworthy as **the exact thing you just pulled from it**, and that answer sits one level below the domain, out of reach of the download count and the URL. That layer is the whole game right now. The registry is fine. `indexed-btree` was not. The platform is fine. The Artifact was not. Reputation on the front door tells you less than it used to, because the front door is exactly what the attacker went and rented. ## Also on the radar - **Cisco ISE, patch now.** **CVE-2026-76460** is an authentication bypass in Cisco's Identity Services Engine being exploited in the wild for root on the box ([Bitsight](https://www.bitsight.com/blog/critical-vulnerability-alert-cve-2026-76460-cisco-ise-authentication-bypass)). ISE decides who gets on the network, so root on it is root on your access policy. - **ScreenConnect under active attack.** CISA is warning on **CVE-2026-84869** in ConnectWise ScreenConnect, exploited for remote file transfer inside live sessions ([SC Media](https://www.scmagazine.com/news/connectwise-screenconnect-bug-exploited-in-the-wild-cisa-says)). Remote-support tooling is a standing foothold with a support engineer's reach. - **Microsoft names the device-code crew.** In a rare bit of good news, Microsoft published a deep dive on **EvilTokens** (tracked as Storm-2992), a device-code phishing operation that abuses Microsoft's own legitimate sign-in flow to steal tokens ([Microsoft Security](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/)). Same theme, different surface: the trusted login prompt is the lure. - **Check Point management server zero-day.** Check Point patched **CVE-2026-93616** after it was exploited in attacks against its Quantum management infrastructure ([BleepingComputer](https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/)). The box that manages your firewalls is a better prize than any single firewall. If you want the longer read on why a trusted registry, cloud, or AI platform in the reputation column is a starting question rather than a green light, we walked through it in [Borrowed reputation: when attackers hide behind trusted infrastructure](/blog/borrowed-reputation-cloud-phishing). See you next week. *Sources are linked inline; credit to the original researchers and reporters. If we got a detail wrong, tell us and we'll fix it.* > **About Reputation Radar:** This is written by the small team building Reput.io, not a marketing department. It's our weekly read on the infosec landscape, with a bias toward the thing we care most about: how attackers borrow the reputation of legitimate infrastructure so their traffic looks normal. Every item links the original reporting, and any claim about our own API is run against it live and labelled.