Fallout in github, Aug 17 – Aug 23

What we caught this week while monitoring over 163,309,944 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

SUNDAY

Sun Aug 23 · 3 catches · 0 waves · 3 singles
well-known/libwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/langobjectives/command-and-controlobjectives/supply-chainmicro-behaviors/dataobjectives/anti-staticobjectives+5 31d

obfuscated crypto drainer in config

obfuscator/js-obfuscatoreval/loader
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+8 32d

Font file hides crypto-stealer payload

trigger/idedelivery/blockchain
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/libobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+7 32d
mrshanshuvo/L2A4 github 32 days ago

Obfuscated crypto-stealer in font file

delivery/blockchaintrigger/ide

SATURDAY

Sat Aug 22 · 61 catches · 0 waves · 3 singles
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionmicro-behaviors/datamicro-behaviors/processobjectives/command-and-controlobjectivesobjectives/execution+5 32d
mdemong87/Coins-Toss-game github and 2 siblings biggest campaign ✓ 32 days ago

Malicious VS Code task payload

delivery/blockchaintrigger/ide
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionobjectives/persistencemicro-behaviors/dataobjectives/command-and-controlobjectivesobjectives/execution+8 32d

Malicious Node payload in font file

trigger/idedelivery/blockchain
objectives/anti-staticmicro-behaviorsmicro-behaviors/communicationsmetadatametadata/buildobjectives/evasionmicro-behaviors/processmicro-behaviors/osobjectivesobjectives/executionobjectives/supply-chain+4 32d

Malicious VS Code tasks and obfuscated payload

trigger/idehidden-payload/worm
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticmicro-behaviors/datamicro-behaviors/processobjectivesobjectives/evasionobjectives/execution+5 32d

Malicious code disguised as font file

trigger/idemasquerade/extension-mismatch

FRIDAY

Fri Aug 21 · 76 catches · 0 waves · 3 singles
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+7 34d
izerekerie/ml_te…ative 1_summative github and 3 siblings biggest campaign 34 days ago

Malicious crypto drainer payload

trigger/idedelivery/blockchain
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/executionobjectives/command-and-controlobjectivesobjectives/evasion+8 33d

Obfuscated C2 payload in font file

blockchain/polygonmasquerade/extension-mismatch
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/evasionobjectives/supply-chainmicro-behaviors/datamicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution+2 33d

Obfuscated payload auto-executes on open

eval/loadereval/dynamic
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticmicro-behaviors/datamicro-behaviors/processobjectivesobjectives/evasionobjectives/execution+6 33d

Disguised crypto stealer in font file

trigger/idemasquerade/extension-mismatch

THURSDAY

Thu Aug 20 · 21 catches · 0 waves · 3 singles
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/supply-chainobjectives/anti-analysisobjectives/collectionobjectives/anti-staticobjectives+17 35d
bun bun-v1.4.0 github 35 days ago

Signed by Codeblog CORP, CDP, persistence

payload/encodedclipboard/capture
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/libobjectives/command-and-controlobjectives/executionobjectives/anti-staticobjectivesobjectives/supply-chain+6 35d

obfuscated payload in tailwind config

hidden-payload/trojaneval/loader
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/supply-chainmicro-behaviors/uimicro-behaviors/datamicro-behaviors/osobjectives/anti-staticobjectivesobjectives/execution+2 35d

Obfuscated payload in postcss config

eval/loadereval/dynamic

WEDNESDAY

Wed Aug 19 · 26 catches · 0 waves · 3 singles
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+9 35d

Malicious code in font file

delivery/blockchaintrigger/ide
well-known/libwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesobjectives/supply-chain+15 35d

Disguised dropper in font file

install-hook/tasksdelivery/blockchain
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/anti-staticobjectives/executionobjectives/command-and-controlobjectivesobjectives/evasion+16 35d

Malicious code hidden in font file

masquerade/extension-mismatchdelivery/blockchain

TUESDAY

Tue Aug 18 · 70 catches · 4 waves · 3 singles
micro-behaviorsmicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/uimetadataobjectives/evasionobjectives 37d
Channelleboiler/…irus-malwarebytes github and 6 siblings biggest campaign 37 days ago

Fake installer redirects to malicious URL

decoy/lureidentity/installer
objectives/anti-staticwell-known/libwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/archobjectives/anti-analysisobjectives/command-and-controlobjectivesobjectives/evasion+14 36d

AMSI patching in embedded PE

platform/defenderanti-av/amsi
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/libobjectives/executionthird_partyobjectives/supply-chainobjectives/anti-staticobjectives+8 36d

Obfuscated backdoor: curl|bash, eval C2, prepare hook

obfuscator/js-obfuscatorscripts/prepare
micro-behaviorsmicro-behaviors/uimetadatametadata/libmetadata/packagemetadata/permissionobjectivesobjectives/evasionobjectives/execution 37d

Disguised Node execution on open

masquerade/extension-mismatchtrigger/ide
metadatametadata/libmetadata/packagemetadata/permissionobjectivesobjectives/evasionobjectives/execution 37d
ub-victor/plsql-…-ushindi-Victoire github and 3 siblings 37 days ago

Malicious VS Code autorun payload

trigger/idemasquerade/extension-mismatch
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+7 37d
ub-victor/JavaScript-ES6-Learning github and 4 siblings 37 days ago

Malicious crypto drainer in font file

delivery/blockchaintrigger/ide
micro-behaviorsmicro-behaviors/communicationsmicro-behaviors/uimicro-behaviors/datametadataobjectives/evasionobjectives 37d
ConstableRegard/…irus-malwarebytes github and 2 siblings 37 days ago

Fake antivirus redirects to malware

decoy/lureidentity/installer
objectives/anti-staticmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/langobjectives/evasionobjectives/executionmicro-behaviors/dataobjectivesobjectives/supply-chainobjectives/command-and-control+3 37d
rounakkhanam06/G…-Coding-Challenge github and 2 siblings 37 days ago

Malicious VSCode task executes hidden payload

delivery/blockchainhidden-payload/trojan

MONDAY

Mon Aug 17 · 10 catches · 0 waves · 2 singles
micro-behaviorsmicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/uimetadataobjectives/evasionobjectives 37d
RoninSanninDefla…rebytes-antivirus github and 7 siblings biggest campaign 37 days ago

Fake installer redirects to malicious URL

decoy/lureidentity/installer
micro-behaviors/communicationsmicro-behaviorsobjectives/credential-accessmicro-behaviors/uimicro-behaviors/datamicro-behaviors/processmetadataobjectives/evasionobjectives 37d

Fake AV redirects to malware

decoy/lureidentity/installer
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/supply-chainobjectiveswell-known/libmetadata/packagemetadata/lib+23 38d

Trojanized dependencies with exfiltration

credential-theft/packagelibrary/source
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories