# CHQ-ED-2026-012

- **Artifact ID:** CHQ-ED-2026-012
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-012
- **Machine-record SHA-256:** `4e6df8cf58216b196e576a465eeac82501fd40307a9baf84aa84d549f71befaf`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-012",
  "associated_position": "CHQ-P-2026-013 v1.0",
  "relationship": "original",
  "issuance_date": "2026-03-20",
  "evidence_freeze_time": "2026-03-20T00:00:00Z",
  "total_exhibits": 4,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "",
      "claim_text": "AI-powered agents systematically scan open-source repositories for exploitable CI/CD workflows, achieving RCE and credential theft across registry boundaries. Developer supply chain tooling weaponized with prompt injection targeting AI coding agents.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SN-2026-03-11-02: Malicious Rust crates (chrono_anchor, dnp3times, time_calibrator) published to crates.io exfiltrating .env files. AI-powered bot hackerbot-claw scanned 47,391+ repositories for exploitable CI/CD workflows, achieving RCE in 4 targets. Aqua Trivy extension compromised (CVE-2026-28353) with prompt injection targeting AI coding agents. Source: Socket / The Hacker News / crates.io.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-02",
      "position_section": "",
      "claim_text": "A compromised publisher account on Open VSX pushed malicious updates to established extensions with ~25,000 existing installs. Malicious releases remained available for 3+ days through the trusted registry update path.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SN-2026-03-15-01: GlassWorm Wave 2 — compromised publisher account on Open VSX pushed malicious updates to 4 established extensions. Registry assessed as leaked token or unauthorized access. Malicious releases available for 3+ days before removal. Source: Socket / Open VSX Security Team.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-03",
      "position_section": "",
      "claim_text": "First confirmed AI-generated malware deployed by a ransomware group in a live operation, demonstrating AI lowering the production cost of supply chain tooling. Technically mediocre but maintained persistent access for over a week.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SN-2026-03-17-01: IBM X-Force documents Hive0163/Slopoly — first confirmed AI-generated malware deployed by ransomware group. Technically mediocre but maintained persistent access for over a week. Demonstrates AI lowering production cost of supply chain tooling. Source: IBM X-Force.",
      "evidence_class": "E2"
    },
    {
      "claim_id": "C-04",
      "position_section": "",
      "claim_text": "GlassWorm Wave 3 compromised 433 components across four registries using transitive dependency abuse, invisible Unicode payloads, Solana blockchain C2, and LLM-generated cover commits. ZOMBI RAT implemented a self-propagating credential theft cycle operative for four months.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "SN-2026-03-20-01: GlassWorm Wave 3 escalation to 433 components across GitHub, npm, Open VSX, VS Code Marketplace. Transitive dependency abuse via extensionPack/extensionDependencies fields. Invisible Unicode payloads. Solana blockchain C2 (50 transactions, 4 months continuous operation). LLM-generated cover commits across 151+ repositories. ZOMBI RAT with self-propagating credential theft cycle. Source: Socket / GitHub Security Advisory.",
      "evidence_class": "E2"
    }
  ],
  "signals": [],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-009",
      "title": "GlassWorm Wave 1–3: Multi-Registry Supply Chain Campaign",
      "temporal_tag": "OPERATIONAL (OCTOBER 2025 TO MARCH 2026)"
    },
    {
      "id": "CHQ-EX-2026-010",
      "title": "Rust Crates CI/CD Supply Chain Attack: hackerbot-claw & Trivy Extension Compromise",
      "temporal_tag": "OPERATIONAL (FEBRUARY–MARCH 2026)"
    },
    {
      "id": "CHQ-EX-2026-011",
      "title": "Hive0163/Slopoly: First Confirmed AI-Generated Ransomware Tooling",
      "temporal_tag": "OPERATIONAL (MARCH 2026)"
    },
    {
      "id": "CHQ-EX-2026-012",
      "title": "ZOMBI RAT: Solana Blockchain C2 and Self-Propagating Credential Theft",
      "temporal_tag": "OPERATIONAL (NOVEMBER 2025 TO MARCH 2026)"
    }
  ],
  "notice": [
    "This docket records claim-to-source mappings for CHQ-P-2026-013 v1.0.",
    "Evidence classification: E2 throughout. All four claims are behavioral evidence from named institutional sources and confirmed incidents across a 10-day window.",
    "This docket was issued on the basis of four signals: SN-2026-03-11-02 (Rust crates CI/CD attack), SN-2026-03-15-01 (GlassWorm Wave 2), SN-2026-03-17-01 (Slopoly AI malware), SN-2026-03-20-01 (GlassWorm Wave 3 multi-ecosystem). All four signals demonstrate cross-registry credential propagation or AI-augmented supply chain exploitation.",
    "NOTE: Four CHQ-EX-REQUIRED flags indicate operational exhibits pending formal registration. The GlassWorm Wave 1–3 exhibit is the primary evidentiary anchor for this Position's core claim.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-013 v1.0.",
    "Evidence classification: E2 throughout. All four claims are behavioral evidence from named institutional sources and confirmed incidents across a 10-day window.",
    "This docket was issued on the basis of four signals: SN-2026-03-11-02, SN-2026-03-15-01, SN-2026-03-17-01, SN-2026-03-20-01. All demonstrate cross-registry credential propagation or AI-augmented supply chain exploitation.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-012 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-013 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
