OOB exfiltration of system info
Fallout in javascript, Aug 24 – Aug 30
What we caught this week while monitoring over 163,107,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 30 · 9 catches · 0 waves · 3 singlesObfuscated backdoor with C2 and self-update
Remote AI CLI control backdoor
AI CLI remote-control backdoor
SATURDAY
Sat Aug 29 · 3 catches · 0 waves · 3 singlesSpawns detached Node with decrypted payload
preinstall exfiltrates system info
FRIDAY
Fri Aug 28 · 15 catches · 0 waves · 3 singlespreinstall exfiltrates system info
binding.gyp executes OS command
binding.gyp executes OS command
THURSDAY
Thu Aug 27 · 21 catches · 1 wave · 3 singlesTrojanized npm phishing facade
Obfuscated crypto-stealer payload
obfuscated dynamic import, fake error exit
obfuscated remote-updating agent backdoor
postinstall beacon exfiltrates hostname
WEDNESDAY
Wed Aug 26 · 3 catches · 0 waves · 3 singlesobfuscated payload execution in dependency
Obfuscated backdoor with C2 and self-update
Dependency clay-server classified hostile
TUESDAY
Tue Aug 25 · 7 catches · 0 waves · 3 singlesEmbedded offensive security tooling
Cybersecurity tool with offensive capabilities
obfuscated C2, credential theft, persistence
MONDAY
Mon Aug 24 · 37 catches · 3 waves · 3 singlescredential theft via remote relay
Relays Facebook credentials to third-party server
Credential stealer with install hook
DNS exfiltration in preinstall hook
obfuscated wasm payload, typosquatting
Install hooks exfiltrate system data