Fallout, this week

What we caught this week while monitoring over 155,936,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

TODAY

Tue Sep 22 · 73 catches · 3 waves · 11 singles
well-knownwell-known/Mcmicro-behaviors/datamicro-behaviorsobjectives/anti-analysisobjectives/impactobjectives/supply-chainobjectives/anti-staticobjectivesobjectives/executionobjectives/command-and-control+4 1h
Corporate_Brief_2026.JS and 7 siblings biggest campaign 1 hour ago

Obfuscated WSH dropper with ActiveX

obfuscation/multi-layerexecution/wsh-reconstruct
micro-behaviors/osmicro-behaviorsobjectives/anti-staticobjectives/anti-analysisobjectives/command-and-controlobjectives/discoveryobjectives/evasionobjectives/impactobjectivesobjectives/persistenceobjectives/execution+5 1h

WMI hidden process, persistence, obfuscation

startup/folderexecution/wmi
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/cryptomicro-behaviors/fsobjectivesobjectives/evasionobjectives/execution+1 1h
WE GH2_RFP PKG f…racha SPEC_REV.js and 2 siblings 1 hour ago

Obfuscated PowerShell download and execution

policy/execution
micro-behaviors/datamicro-behaviorsmetadatametadata/langobjectives/executionmicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osobjectives/evasionobjectives/anti-staticobjectives 1h

Obfuscated VBS executes decoded payload

obfuscation/multi-layerfile/double-ext
micro-behaviors/datamicro-behaviorsobjectives/command-and-controlobjectives/executionobjectives/impactobjectives/persistenceobjectives/supply-chainmicro-behaviors/processmicro-behaviors/fsobjectives/anti-staticobjectives+3 1h
RFQ 269059634.js 1 hour ago

Obfuscated WSH dropper runs PowerShell payload

obfuscation/multi-layerobfuscation/syntax
micro-behaviors/osmicro-behaviorsmetadatametadata/langobjectives/anti-staticmicro-behaviors/processobjectives/command-and-controlobjectivesobjectives/execution 1h
RFQ-SCM04429866,PDF.vbs and 2 siblings 1 hour ago

Obfuscated VBS executes hidden PowerShell

execution/wshvbscript/wmi
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/supply-chainmicro-behaviors/datamicro-behaviors/processmicro-behaviors/cryptoobjectives/command-and-controlobjectivesobjectives/evasionobjectives/execution+3 1h
MM-7953-0053_110…IS 9100052982 .js and 2 siblings 1 hour ago

Obfuscated dropper, C2, PowerShell exec

execution/persistencepolicy/execution
well-known/appwell-knownmicro-behaviors/communicationsmetadata/binarymetadataobjectives/anti-analysisobjectives/collectionmicro-behaviorsmicro-behaviors/processobjectives/anti-staticobjectives+31 3h
polyrouter 1.0.38 javascript 3 hours ago

MITM proxy intercepts AI traffic

eval/requirecreate/hidden
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/supply-chainobjectives/discoverymicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectives/exfiltrationobjectives+1 4h

Exfiltrates system data to attacker server

stealer/httpoob/callback
micro-behaviors/osmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticmicro-behaviors/datamicro-behaviors/processmicro-behaviors/communicationsobjectivesobjectives/exfiltrationobjectives/supply-chain 4h

Obfuscated C2 beacon in install hook

recon-exfil/dnsdns/encoded
objectives/anti-analysisobjectiveswell-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/collectionthird_party+31 6h

Empire C2 framework

Invoke/SshcommandContent/Indicator
objectives/discoveryobjectivesmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/executionobjectives/anti-staticmalwaremalware/toolthird-party+12 9h

Known offensive security toolkit

Attack/Scriptsoffensive/mimikatz
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/evasionobjectives/exfiltration+6 15h
TRON 1111.0.3 firefox 320-otg54rt90h 15 hours ago

Clipboard exfiltration, obfuscated C2, wallet theft

credential/clipboardextension/deception
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/persistenceobjectives/privilege-escalationobjectives+25 16h
pwn 0.5.744 ruby 1,114,862 installs 16 hours ago

Offensive security framework with evasion

elevation-control/sudoservice/systemd

YESTERDAY

Mon Sep 21 · 239 catches · 8 waves · 20 singles
micro-behaviors/communicationsmicro-behaviorsobjectives/evasionobjectives/executionmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 21h
3b0b2a258879… and 12 siblings biggest campaign 21 hours ago

Multi-arch botnet dropper

delivery/execute-downloadbotnet/iot
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/executionmicro-behaviors/datamicro-behaviors/cryptomicro-behaviors/fsobjectives/lateral-movementobjectives/command-and-controlobjectives+2 18h

Webshell deployment exploit toolkit

webshell/embeddedexploit/scanner
micro-behaviors/datamicro-behaviorsmetadatametadata/packageobjectives/evasionobjectives/anti-staticobjectives/executionobjectives/impactobjectives/command-and-controlobjectivesthird_party+4 18h

Webshell and WordPress exploit kit

PHP/Writerwebshell/file-manager
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/executionmicro-behaviors/datamicro-behaviors/cryptomicro-behaviors/fsobjectives/lateral-movementobjectives/command-and-controlobjectives+3 18h

CMS exploit toolkit

webshell/embeddedexploit/scanner
objectives/command-and-controlobjectives/evasionobjectives/impactmicro-behaviors/osobjectives/anti-staticobjectivesmicro-behaviors/fsmicro-behaviors 18h

Installs hidden RAdmin backdoor services, self-deletes

string/concatfile/attributes
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/command-and-controlobjectives/anti-staticobjectives/executionobjectives/impactobjectives/evasionobjectivesmicro-behaviors/process+11 18h

Process injection and code patching

injection/dllinjection/memory
micro-behaviors/fsmicro-behaviorsobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesobjectives/persistence 19h
Trojan.BAT.Caloner.b 19 hours ago

Self-replicating batch trojan

boot/configinfect/script
micro-behaviorsmicro-behaviors/dataobjectives/anti-staticobjectives/collectionmicro-behaviors/fsobjectives/impactobjectivesobjectives/persistence 19h
Virus.BAT.Br 19 hours ago

Self-replicating batch virus

boot/configinfect/script
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 20h
0dc753dac11f… and 2 siblings 20 hours ago

Multi-arch dropper, C2, cleanup

delivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 20h
6141287a6f20… and 3 siblings 20 hours ago

Downloads and executes remote binaries

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 20h
0a9c5f0aef7d… and 4 siblings 20 hours ago

Downloads and executes remote exploits

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsobjectives/discoveryobjectives/executionmicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectives/command-and-controlobjectives 21h
aaf033f60ef8… and 7 siblings 21 hours ago

Downloads and executes remote binaries

delivery/execute-download
objectivesobjectives/command-and-control 21h
ed68ef3bab58… and 4 siblings 21 hours ago

Malicious URL shortcut to IP

delivery/url-shortcut
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/credential-accessobjectives/executionobjectives/lateral-movementobjectivesobjectives/exfiltration+15 23h
Costco Tools by RestockBotAlerts 1.6.7 firefox costco-tools-restockbotalerts 8 installs 23 hours ago

Credential theft, obfuscation, C2 tunnel

oob/endpointbrute-force/password
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/command-and-controlobjectives/discoveryobjectives/evasionobjectives/anti-staticobjectivesobjectives/supply-chainmetadata/package+11 1d

Crypto miner with persistence and C2

payload/encryptedpackage/rubygems
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 1d
t linux 1 day ago

Downloads and executes remote malware

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 1d
lterouter linux 1 day ago

Downloads and executes remote malware

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 1d
w linux 1 day ago

Downloads and executes remote payloads

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/collectionmicro-behaviors/datamicro-behaviors/osmicro-behaviors/dylibobjectives/evasionobjectivesobjectives/exfiltration+1 1d
pullgetsage 0.1.2 python 1 day ago

Steals Telegram data, exfiltrates

http/archiveindicator-removal/cleanup
micro-behaviors/datamicro-behaviorsmetadatametadata/langmicro-behaviors/osmicro-behaviors/processmetadata/signedobjectives/anti-staticobjectives/executionobjectives 1d
BANK SLIP USD 19…4 HG PERTH).vbs and 2 siblings 1 day ago

Obfuscated VBS malware with registry access

vbscript/loaderstring/junking
well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/supply-chainobjectives/command-and-controlobjectives/lateral-movementobjectives/anti-staticobjectives+9 1d

obfuscated WhatsApp bot with remote code execution

string/encodingstring/concat
well-knownwell-known/dual-usemicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/collectionobjectives/executionobjectives/credential-accessobjectives/exfiltrationobjectives+6 1d
InboxHub 1.1.3 chrome jmaebhngjpkdjagbiabligaeonfmfnic 3 installs 1 day ago

Exfiltrates Depop auth tokens to ngrok

oob/endpointbrowser/session-hijack
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/impactobjectives/supply-chainobjectives/command-and-controlobjectivesobjectives/credential-access+17 1d

Ransomware and credential theft code

dropper/obfuscatedtoken/cli
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/executionobjectives/persistenceobjectives+24 1d

curl-pipe-sh, credential theft, persistence

service/systemdautomation/agent
objectives/credential-accesswell-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/collectionobjectivesobjectives/supply-chainobjectives/exfiltration+15 1d
Skip Wait - Smart Wait Time help 1.5.7 firefox skip-wait-smart-wait-time-help 1 installs 1 day ago

Obfuscated credential stealer

exfiltration/sensitive-datatrojanized/dist
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/discoverymicro-behaviors/processmicro-behaviors/datamicro-behaviors/hardwaremicro-behaviors/osobjectives/exfiltrationobjectives+1 1d
rrs 0.4.108 python 1 day ago

Exfiltrates screen capture to Discord

messaging/webhookcredential/platform
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/discoveryobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectives/exfiltrationobjectives+1 1d
rrs 0.4.105 python and 3 siblings 1 day ago

Exfiltrates screen captures to Discord

messaging/webhookcredential/platform
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/credential-accessobjectives/executionobjectives/lateral-movementobjectivesobjectives/exfiltration+15 1d
Costco Tools by RestockBotAlerts 1.6.6 firefox costco-tools-restockbotalerts 8 installs 1 day ago

Credential theft, obfuscation, weak passwords

oob/endpointbrute-force/password
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/exfiltrationobjectivesobjectives/command-and-controlobjectives/supply-chain 1d
@nimbsuedge3/xar 1.1.1 javascript and 2 siblings 1 day ago

preinstall reverse shell C2

scripts/remote-fetchreverse-shell/dev-tcp
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories