Supply-Chain Malware Handoffs
Purpose: Canonical handoff payloads for Chain's live supply-chain malware recipes. Read when: A lockfile, IDE hook, runtime, git-history, CI, or maintainer-publish finding must move between Chain and a domain owner.
All payloads follow _common/HANDOFF.md. Emit one target per handoff, reference concrete evidence, defang attacker URLs, and never include credential values.
Inbound
USER_TO_CHAIN_MALWARE_REQUEST
from: User
to: Chain
intent: malware-scan | campaign-scan | lockfile | eradicate | rotate | harden | propagation
context:
os: macOS | Linux | Windows | WSL | container | CI
suspect_window: "<UTC range>"
suspect_campaign: "<campaign or unknown>"
scope: ["<repo path, host scope, image, or runner>"]
prior_actions: "<actions already taken>"
constraints:
read_only_until_confirm: true
may_quarantine: falseSENTINEL_TO_CHAIN_MALWARE_REQUEST
from: Sentinel
to: Chain
trigger: malicious_pin | slopsquat_candidate | install_script_anomaly
context:
package: "<name@version>"
lockfile_path: "<path>"
advisory: "<CVE, GHSA, or source URL>"
confidence: HIGH | MEDIUM | LOW
ask:
- Confirm live-environment persistence, droplet, and process evidence
- Return infection grade and evidence chainBUILDER_OR_TRAIL_TO_CHAIN_MALWARE_REQUEST
from: Builder | Trail
to: Chain
trigger: lockfile_diff | optional_dependency | install_script | suspicious_commit | force_pushed_tag
context:
ref_or_commit: "<sha>"
changed_files: ["<path>"]
author: "<if relevant>"
ask:
- Cross-check exact evidence against the campaign IoC database
- Block merge only on an evidence-backed malicious matchTRIAGE_TO_CHAIN_MALWARE_REQUEST
from: Triage
to: Chain
trigger: supply_chain_incident
context:
incident_id: "<id>"
severity: SEV1 | SEV2
affected_targets: ["<host, runner, repo, or image>"]
constraints:
approved_actions: ["<pre-authorized persistence-stop action>"]
blocked_actions: ["credential revocation", "production infrastructure changes"]
ask:
- Run a full IoC scan and classify the infection
- Stop IoC-matched persistence if actively bleeding and authorized
- Return evidence chain, eradication gate, and rotation eligibilityOutbound
CHAIN_TO_TRIAGE_MALWARE_INCIDENT
from: Chain
to: Triage
trigger: CONFIRMED | ACTIVELY_BLEEDING
context:
campaign: "<name>"
grade: CONFIRMED | ACTIVELY_BLEEDING
evidence:
persistence: [{path: "<path>", sha256: "<hash>", status: stopped | running}]
lockfile_pins: [{package: "<name@version>", path: "<lockfile>"}]
passive_exfil_traces: [{host: "<defanged host>", evidence: "<log line>"}]
quarantine_path: "/tmp/chain-malware-quarantine-<utc>/"
eradication_status: in_progress | verified_clean | blocked
rotation_status: not_eligible | ready | issued
retaliation_risk: "<why rotation remains gated>"CHAIN_TO_SENTINEL_MALICIOUS_PIN
from: Chain
to: Sentinel
trigger: confirmed_malicious_version_pin
context:
package: "<name@version>"
lockfiles: ["<path>"]
clean_version: "<name@version>"
campaign: "<name>"
ask:
- Find the pin across the organization
- Propose an upgrade and rollback plan
- Add a slopsquat rule if applicableCHAIN_TO_GEAR_MALWARE_HARDENING
from: Chain
to: Gear
trigger: verified_clean_rebuild
context:
affected_surfaces: [npm_runtime, github_actions, container_image, dependency_bot]
controls:
- "ignore-scripts=true"
- "minimum release age of at least 7 days"
- "full-SHA GitHub Action pinning"
- "OIDC instead of long-lived tokens"
- "registry proxy and provenance checks"
ask:
- Rebuild runners and images from a clean base
- Apply controls and return verification evidenceCHAIN_TO_VIGIL_MALWARE_RULES
from: Chain
to: Vigil
trigger: new_source_cited_ioc
context:
campaign: "<name>"
signatures:
- type: filename | sha256 | process_cmdline | network_endpoint | git_pattern
value: "<exact or defanged value>"
source: "<advisory URL + date>"
ask:
- Author and test Sigma or YARA coverage
- Map the evidence to current MITRE ATT&CK techniquesCHAIN_TO_LORE_MALWARE_PATTERN
from: Chain
to: Lore
trigger: repeated_campaign_pattern | novel_persistence | eradication_order_lesson
context:
pattern_summary: "<short, non-sensitive summary>"
recurrence_count: <n>
affected_agents: [Sentinel, Chain, Vigil, Triage, Gear]
ask:
- Curate the reusable pattern without raw credentials or confidential payloadsHandoff Hygiene
- One target per handoff; do not combine Triage, Sentinel, Gear, and Vigil requests.
- Include exact paths, hashes, timestamps, package pins, and source citations.
- Defang attacker URLs (
httpstohxxps,.comto[.]com) and use passive evidence only. - Preserve
persistence stopped before revokeandverify-clean before rotationas explicit gates. - A confirmed IDE-hook compromise remains within Chain: quarantine only after approval, then rerun
intakeand regenerate.chain-manifest.jsonon the cleaned directory.
Overlap Boundaries
| Partner | Chain supplies | Partner owns |
|---|---|---|
| Triage | IoC grade, evidence, eradication and rotation gates | Incident command, severity, communications, disclosure |
| Sentinel | Confirmed malicious pin and campaign evidence | Org-wide dependency remediation, SAST, slopsquat rules |
| Gear | Clean-rebuild and hardening specification | CI/CD, runner, image, and dependency-policy implementation |
| Vigil | Source-cited detection primitives | Sigma/YARA authoring, ATT&CK mapping, detection validation |
| Trail | Campaign cross-check for suspicious commits | Git archaeology and public-ref cleanup analysis |
| Lore | Reusable non-sensitive campaign pattern | Ecosystem memory and propagation |