Remote command execution backdoor tool
Fallout in python, Aug 3 – Aug 9
What we caught this week while monitoring over 163,642,969 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 9 · 16 catches · 1 wave · 3 singlesEmbedded credentials and admin remote execution
Embedded private key, admin tool invocation
Obfuscated credential, stealth browser automation
SATURDAY
Sat Aug 8 · 8 catches · 0 waves · 3 singlesComplex AI agent framework with persistence and evasion
Embedded private key, admin tool invocation
FRIDAY
Fri Aug 7 · 17 catches · 0 waves · 3 singlesExecutes base64 payload on install
AI pentesting platform with offensive tools
THURSDAY
Thu Aug 6 · 8 catches · 0 waves · 3 singlesimport-time exfiltration in init
Batch script writes exe to AppData
WEDNESDAY
Wed Aug 5 · 13 catches · 0 waves · 3 singlesReverse shell and credential theft tool
TUESDAY
Tue Aug 4 · 8 catches · 0 waves · 3 singlesRemote terminal agent with persistence
AI agent runtime executes arbitrary code
Discord token stealer with obfuscation
MONDAY
Mon Aug 3 · 14 catches · 0 waves · 3 singlesAutomation tool executes arbitrary code
Automated offensive pentest and exploit framework