← Back to list
● Based on the 2025-11 GJTec/Qilin ransomware ("Korean Leaks") campaign — 28 institutions breached

I reproduced the MSP supply-chain attack exactly,
and I'm publishing the code that contains it

I reproduced the structure behind the "Korean Leaks" incident, where one compromised managed-service-provider (MSP) account cascaded into a breach of 28 downstream clients. It shows how per-client scoped access, instead of one shared credential, contains the blast radius to a single client. Both are free right now.

See live demo → Jump to code

Who this is for

Not for real MSP operators — this is a learning resource for backend/infra developers running multi-tenant SaaS or managing multiple client systems, to see in code exactly why one compromised vendor can take down everyone downstream.

28
Institutions breached in the "Korean Leaks" campaign
2TB
Total data exfiltrated (over 1 million files)
$0
What this code costs right now — free

Code — shared-credential-access.js

A vulnerable MSP access model where one credential reaches every client tenant.

shared-credential-access.js
// Vulnerable MSP access model — modeled on the "Korean Leaks" campaign:
// a single compromised GJTec credential cascaded into a breach of 28
// downstream financial institutions. The flaw: one credential has
// standing access to every client tenant.
class SharedCredentialAccess {
  constructor(tenants) {
    this.tenants = tenants; // [{id, name}, ...]
    this.credential = { id: 'msp-admin', scope: 'all-tenants' };
  }

  // A stolen credential can act against ANY tenant — no isolation.
  accessTenant(credential, tenantId) {
    if (credential.scope !== 'all-tenants') return { status: 'denied' };
    const tenant = this.tenants.find(t => t.id === tenantId);
    return { status: 'breached', tenant };
  }

  simulateCompromise() {
    // Attacker has the one credential; every tenant is reachable.
    return this.tenants.map(t => this.accessTenant(this.credential, t.id));
  }
}

module.exports = { SharedCredentialAccess };

Code — tenant-isolated-access.js

The fix: per-tenant scoped credentials that contain a breach to one client.

tenant-isolated-access.js
// The fix: credentials are scoped to exactly one tenant and expire
// quickly. Compromising the credential used against one client never
// grants access to any other client — this is what would have
// contained the GJTec-style MSP breach to a single institution.
class TenantIsolatedAccess {
  constructor(tenants) {
    this.tenants = tenants;
    this.credentials = new Map(
      tenants.map(t => [t.id, { tenantId: t.id, issuedAt: Date.now(), ttlMs: 15 * 60 * 1000 }])
    );
    this.blockedAttempts = [];
  }

  accessTenant(credential, tenantId) {
    if (credential.tenantId !== tenantId) {
      this.blockedAttempts.push({ credentialTenant: credential.tenantId, attemptedTenant: tenantId });
      return { status: 'denied', reason: 'scope_mismatch' };
    }
    const tenant = this.tenants.find(t => t.id === tenantId);
    return { status: 'breached', tenant }; // only the targeted tenant is ever reachable
  }

  simulateCompromise(compromisedTenantId) {
    const stolenCredential = this.credentials.get(compromisedTenantId);
    return this.tenants.map(t => this.accessTenant(stolenCredential, t.id));
  }
}

module.exports = { TenantIsolatedAccess };

Price

Free (for now)
A deeper version (credential rotation, cross-tenant anomaly detection, incident-response guide) ships later — pay-what-you-want, starting at $0.
goalsgo7574@gmail.com
This isn’t a purchase — just email me "notify me about the paid version" and I’ll reach out when it ships.
Note: This is a scaled-down learning implementation. No credential rotation, anomaly detection, or real MSP operations — don't drop this into a real multi-tenant system.

Leave feedback

Questions or feedback about this product? Leave your email if you'd like a reply (optional).