Malicious postinstall downloads and executes payload
Fallout in javascript, Aug 10 – Aug 16
What we caught this week while monitoring over 163,443,884 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 16 · 23 catches · 0 waves · 3 singlesobfuscated preinstall exfiltration payload
Embedded Xelis cryptominer in npm package
Browser cookie theft, keylogging, stealth
SATURDAY
Sat Aug 15 · 41 catches · 0 waves · 3 singlesExfiltrates ECS metadata via postinstall
postinstall exfiltrates data via curl
Obfuscated dropper, C2, persistence
obfuscated C2 terminal agent
FRIDAY
Fri Aug 14 · 159 catches · 8 waves · 3 singlesTea campaign supply chain malware
Tea campaign supply-chain malware
obfuscated dropper with self-deletion
Tea campaign supply chain malware
Credential exfiltration via install hooks
Tea campaign supply chain malware
Sandbox-gated remote code execution
C2 beacon, removed package, preinstall hook
Malicious postinstall beacon
THURSDAY
Thu Aug 13 · 70 catches · 2 waves · 3 singlespostinstall exfiltrates host data
Dependency confusion staging URL
preinstall exfiltrates host data to OOB
install hook exfiltrates environment
obfuscated postinstall dropper
Embedded protestware payload in SweetAlert2
WEDNESDAY
Wed Aug 12 · 84 catches · 1 wave · 3 singlesDropper downloads and executes DDoS tools
postinstall exfiltrates host data to C2
postinstall exfiltrates system info
Exfiltrates system data to remote server
postinstall exfiltrates command output
TUESDAY
Tue Aug 11 · 94 catches · 3 waves · 3 singlesObfuscated WMI execution, hidden process
Credential stealer with OOB exfil
Supply chain trojan exfiltrates credentials
Obfuscated WScript file dropper
Obfuscated PowerShell dropper with persistence
Obfuscated dropper, kills processes, hidden PowerShell
MONDAY
Mon Aug 10 · 68 catches · 0 waves · 3 singlesObfuscated WSH dropper, C2 IP, PowerShell bypass
Obfuscated dropper with file write