Typosquatting, HTTP deps, fake author
Fallout in javascript, Aug 31 – Sep 6
What we caught this week while monitoring over 163,052,840 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 6 · 746 catches · 62 waves · 3 singlesRemote control, persistence, credential access
Embedded credential exfiltration payloads
Downloads and executes remote binaries
OOB exfiltration via preinstall hook
OOB beacon, fake version, preinstall
Downloads and executes remote payload
Clipboard exfiltration, screen capture, input injection
Exfiltrates credentials to OOB server
OOB exfiltration and install hooks
OOB exfil, fake version, install hooks
Exfiltrates environment variables to OOB
Exfiltrates environment variables to OOB
Exfiltrates credentials to OOB server
Exfiltrates env data via webhook
Exfiltrates system data to OOB
postinstall downloads and executes remote code
Exfiltrates system data via webhook
Exfiltrates credentials to OOB server
Exfiltrates host info to webhook.site
Downloads and executes remote payload
Exfiltrates system info to OOB
Exfiltrates secrets via install hook
preinstall exfiltrates system info
preinstall downloads and executes Bun
Preinstall exfiltrates system info
Remote agent, persistence, bypass permissions
Preinstall exfiltrates system info
Downloads and executes remote payload
Downloads and executes remote binary
Exfiltrates environment variables to OOB
Exfiltrates system info to OOB
SSH key exfiltration, C2 beacon
Downloads and executes remote binary
Exfiltrates system info to OOB
Exfiltrates system data via OOB
Full-screen ad overlay injection
Exfiltrates system info to OOB
Trojanized dependency with hidden loader
Trojanized package with malicious dependency
preinstall downloads and executes Bun
TikTok scraper with C2 and evasion
Bytecode obfuscation, CDP, shell exec
Discord token stealer
Exfiltrates Discord tokens to webhook
TikTok scraper with C2 and evasion
Remote code execution via eval
Game cheat with process injection
Game cheat with process injection
Exfiltrates system info via install hooks
Bundled RedShell backdoor binary
EtherHiding crypto drainer payload
Remote code execution via base64
Exfiltrates SSH keys, env, Telegram data
Obfuscated credential stealer
AI agent remote control tool
preinstall downloads and executes obfuscated payload
Remote code execution, C2, obfuscation
preinstall downloads and executes remote code
Obfuscated malware in preinstall hook
Exfiltrates system info via install hooks
Obfuscated session wipe and data exfil
SATURDAY
Sat Sep 5 · 6 catches · 0 waves · 3 singlesRemote AI agent control binary
Remote AI CLI control agent
obfuscated self-updating backdoor agent
FRIDAY
Fri Sep 4 · 5534 catches · 447 waves · 3 singlesDownloads and executes remote binaries
postinstall exfiltrates to webhook.site
Downloads and executes remote binaries
Downloads and executes remote payloads
Malicious ad injection and self-update
Obfuscated credential-stealing preinstall hook
Exfiltrates system info to hardcoded IP
Exfiltrates system data to C2
Exfiltrates system data to OOB domain
Trojanized package with obfuscated code
Downloads and executes remote binaries
Preinstall exfiltrates system info to OOB
Downloads and executes remote binary
DNS exfil, payload download, execution
Downloads and executes remote binary
Dropper downloads and executes Bun runtime
Credential stealer with persistence and exfiltration
Downloads and executes remote binaries
Obfuscated credential-stealing preinstall payload
Obfuscated payload, preinstall hook, C2
postinstall exfiltrates logs to OAST
Exfiltrates system info via install hooks
Remote code execution via C2
C2, reverse shell, data exfiltration
Malicious backdoor with C2 and reverse shell
Remote code execution via eval
DNS exfil, binary download, execution
Remote agent bypasses permissions
Exfiltrates system info to OOB
Self-referential dependency, remote code execution
Downloads and executes remote payload
preinstall exfiltrates system data
Obfuscated malware with credential theft
Malicious dependency exfiltrates data
Exfiltrates system info via install hooks
Exfiltrates AWS credentials via OOB
Embedded Shai-Hulud malware payload
Exfiltrates secrets via install hook
Downloads and executes remote payload
npm postinstall credential harvester
Preinstall hook exfiltrates system info
Exfiltrates system info to OOB
preinstall exfiltrates host identity via OOB
preinstall exfiltrates host data via OOB
Dropper downloads and executes obfuscated payload
Browser credential and wallet stealer
Credential theft and email harvesting
Malicious C2 and privilege escalation
Malicious install hook executes payload
Malicious install hook executes hidden PowerShell
Exfiltrates secrets to webhook.site
Downloads and executes remote binary
Exfiltrates email via postinstall
postinstall executes remote code
UAC bypass, C2 beacon, data exfil
Exfiltrates system data to hardcoded IP
Obfuscated C2 beaconing to malicious domain
preinstall executes remote code
Downloads and executes remote payload
Exfiltrates system data to OOB
Typosquat of big.js with trojanized security-hold dependency
preinstall downloads and executes obfuscated payload
Downloads and executes remote binary
Steals wallets, history, exfiltrates data
Exfiltrates secrets to hardcoded IP
Game cheat with process injection
Game cheat with process injection
Preinstall exfiltrates system info
Remote code execution via postinstall
Exfiltrates system info to webhook.site
Base64 obfuscated malicious install command
SSH key injection, data exfiltration
Embedded Shai-Hulud malware payload
preinstall hook executes arbitrary code
Preinstall hook executes remote code
Dynamic code execution, C2 IP
SSH key injection, data exfiltration
Exfiltrates system info to hardcoded IP
Obfuscated payload, preinstall downloads/executes Bun
Exfiltrates environment via preinstall
Trojanized dependency with hidden loader
Exfiltrates sensitive data to remote server
Exfiltrates secrets via Telegram
Credential stealer and dropper
Exfiltrates system info to OOB
postinstall exfiltrates environment data
Exfiltrates credentials, executes remote commands
Exfiltrates secrets to webhook.site
DNS exfil, binary download, execution
preinstall downloads and executes Bun
preinstall hook exfiltrates system info
Exfiltrates system info via preinstall
Exfiltrates system data to OOB
Embedded Shai-Hulud malware payload
Downloads and executes remote payload
Exfiltrates system data to C2
Exfiltrates secrets via preinstall hook
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Exfiltrates system credentials and files
Remote code execution via eval
Exfiltrates system credentials and data
preinstall exfiltrates .env to Telegram
DNS C2, payload download, execution
Token harvester, exfiltrates secrets
Exfiltrates secrets to webhook.site
Obfuscated dropper executes downloaded payload
Exfiltrates files via webhook.site
Credential theft and exfiltration malware
Base64 obfuscated malicious install command
Exfiltrates secrets to webhook.site, spawns detached scripts, republishes packages
Embedded Shai-Hulud malware payload
Remote code execution and persistence
Exfiltrates secrets to webhook.site
Exfiltrates secrets via postinstall hook
Downloads and executes remote binary
preinstall exfiltrates system info
Exfiltrates credentials, deploys malware
Obfuscated credential stealer and dropper
Downloads and executes remote payload
Dependency confusion exfiltration POC
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Dropper downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, Bun dropper, preinstall
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Downloads and executes hidden Bun runtime
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated dropper downloads and executes Bun
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
Downloads and executes obfuscated payload
Preinstall drops obfuscated credential-stealing payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall Bun download
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
Obfuscated payload, downloads and executes Bun runtime
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated credential theft during install
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Downloads and executes obfuscated payload
Credential stealer and C2 exfiltration
postinstall drops and runs encoded stealer
Credential stealer with obfuscation
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated dropper executes hidden payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall hook, C2
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
Obfuscated payload, runtime download, preinstall hook
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated preinstall credential stealer
Downloads and executes remote payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
Obfuscated payload, preinstall hook, runtime download
preinstall downloads and executes obfuscated payload
Obfuscated payload, downloads and executes Bun
Obfuscated dropper spawns hidden child process
Remote code execution via axios
preinstall hook executes obfuscated payload
Remote code execution via axios
Steals credentials, exfiltrates via Telegram
Obfuscated remote code execution
preinstall executes hidden ELF binary
Obfuscated hidden payload execution
OOB exfiltration, dependency confusion POC
Downloads and executes remote binaries
postinstall exfiltrates host recon to remote server
Obfuscated preinstall dropper spawning payload
Disables TLS, downloads from raw IP
EtherHiding malware payload
preinstall executes obfuscated malicious code
preinstall executes obfuscated malicious payload
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
preinstall hook, obfuscated credential theft
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
preinstall hook runs obfuscated payload
obfuscated credential-stealing malware
preinstall hook executes obfuscated payload
Obfuscated credential stealer in preinstall
preinstall hook executes obfuscated payload
preinstall executes obfuscated malicious payload
preinstall hook executes obfuscated malware
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
preinstall executes obfuscated malware
malicious preinstall script
preinstall hook executes obfuscated payload
Obfuscated preinstall credential stealer
Obfuscated payload in postcss config
Downloads and executes obfuscated payload
Obfuscated remote code execution
Obfuscated install script downloads and executes payload
Obfuscated credential stealer in preinstall
Obfuscated credential stealer with install hook dropper
Obfuscated credential stealer
Credential stealer with obfuscation
Obfuscated credential stealer in preinstall
Credential stealer in obfuscated router_init.js
Obfuscated credential stealer and dropper
Obfuscated credential stealer and dropper
Obfuscated credential stealer and dropper
Obfuscated credential stealer with install hook
Obfuscated credential stealer payload
Obfuscated credential stealer and dropper
Obfuscated credential stealer in preinstall
Obfuscated C2 with preinstall hook
Whalent malware, obfuscated C2, self-update
Whalent backdoor, obfuscated C2, self-update
Obfuscated backdoor with C2 and self-update
Obfuscated backdoor with C2 and self-update
Obfuscated backdoor with C2 and self-update
Obfuscated backdoor with C2 and self-update
Malicious persistence and payload execution
Obfuscated backdoor with C2 and self-update
Typosquat of bitcoinjs-lib; postinstall launches hidden bip40 daemon
Exfiltrates secrets via webhook.site
Recon, flag theft, exfiltration to hardcoded IP
Obfuscated credential theft and C2
Embedded secret exfiltration script
Obfuscated C2 beacon in install hook
Embedded Shai-Hulud malware payload
Embedded supply chain malware payload
Obfuscated credential theft and C2
Obfuscated credential theft and C2
Embedded Shai-Hulud malware payload
Exfiltrates secrets to webhook.site
Credential stealer disguised as Mistral SDK
Obfuscated credential stealer in router_init.js
Embedded script exfiltrates GitHub secrets to webhook.site
preinstall downloads and executes obfuscated payload
Obfuscated preinstall downloads and executes payload
Obfuscated dropper downloads and executes Bun
Exfiltrates system info to OOB server
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Obfuscated dropper downloads and executes Bun
Dropper downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Credential stealer, obfuscated, self-daemonizing
Steals credentials, obfuscated, drops runtime
obfuscated dropper downloads and executes payload
obfuscated dropper downloads and executes payload
Obfuscated dropper downloads and executes Bun
Obfuscated dropper downloads and executes Bun
Obfuscated AWS credential theft
Obfuscated credential stealer payload
Obfuscated dropper downloads and executes Bun
Obfuscated credential stealer and dropper
Trojanized dependency easy-day-js
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Embedded secret exfiltration script
Exfiltrates secrets to webhook.site
Shai-Hulud worm payload embedded
Exfiltrates secrets to webhook.site
Shai-Hulud worm payload embedded
Obfuscated agent, CDP, shell exec, install hooks
Embedded secret exfiltration script
Shai-Hulud worm exfiltrates secrets
Shai-Hulud worm payload embedded
Exfiltrates secrets to webhook.site
preinstall dropper executes obfuscated credential-stealing payload
Obfuscated data exfiltration to hardcoded IP
curl piped to zsh C2 dropper
Preinstall downloads and executes obfuscated payload
Obfuscated DNS exfiltration with preinstall hook
Obfuscated payload, preinstall executes Bun
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
preinstall dropper runs obfuscated credential-stealing payload
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Exfiltrates secrets to webhook.site
Downloads and executes remote binaries
Downloads and executes remote payload
Credential harvesting and exfiltration
Obfuscated malicious npm package
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Embedded secret exfiltration script
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Exfiltrates secrets to webhook.site
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Embedded secret exfiltration script
preinstall exfiltrates to oastify
Exfiltrates credentials via preinstall hook
Ignores malware scanners, hides code in bytecode
Exfiltrates system data to webhook
Exfiltrates secrets to webhook.site
Embedded secret exfiltration script
preinstall executes remote shell
Embedded secret exfiltration script
Embedded secret exfiltration script
Embedded secret exfiltration script
Bundle contains secret exfiltration script
Embedded secret exfiltration script
Embedded Shai-Hulud malware payload
Embedded secret exfiltration script
THURSDAY
Thu Sep 3 · 138 catches · 19 waves · 3 singlesDownloads and executes obfuscated payload
Typosquat with reverse shell and exfiltration
Trojanized package with hidden dependency
Exfiltrates environment variables via install hooks
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Disables TLS, downloads from raw IP
obfuscated dropper downloads and executes payload
Downloads and executes remote payload
Downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
obfuscated dropper downloads and executes payload
Downloads and executes remote binary
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated self-defending dist with eval, child_process, OAuth tokens
obfuscated backdoor with self-update
Exfiltrates Coze API tokens and data
WEDNESDAY
Wed Sep 2 · 47 catches · 1 wave · 3 singlesObfuscated payload execution via new Function
Typosquatting, obfuscation, runtime npm install
Exfiltrates credentials, env, and system info
Decodes and executes hidden payload
Sliver implant in binary
TUESDAY
Tue Sep 1 · 5 catches · 0 waves · 3 singlesCredential theft and C2 indicators
MONDAY
Mon Aug 31 · 13 catches · 0 waves · 3 singlesBrowser credential theft and evasion
installs persistent telemetry hooks
Remote agent, persistence, credential access