Fallout in python, Aug 31 – Sep 6
What we caught this week while monitoring over 163,052,840 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 6 · 10 catches · 0 waves · 3 singlesSATURDAY
Sat Sep 5 · 5 catches · 0 waves · 3 singlesRDP enable, sudoers NOPASSWD, masquerade, evasive base64
Powershell/Webdownloadcontrol/rdp
AD pentest framework, credential dumping
Impacket/impacketexploit/vulnerabilities
FRIDAY
Fri Sep 4 · 6 catches · 0 waves · 3 singlesCredential and AI-config exfiltration indicators
impersonation/core-module
Exfiltrates environment variables to remote server
credential-theft/package
THURSDAY
Thu Sep 3 · 4 catches · 0 waves · 3 singlesWEDNESDAY
Wed Sep 2 · 5 catches · 0 waves · 3 singlesProcess injection and evasion APIs
injection/thread-hijackingransom/file-operations
MONDAY
Mon Aug 31 · 3 catches · 0 waves · 3 singlesMalicious SweetAlert2 payload targeting Russian users
supply-chain/sweetalert2-protestwaremanipulation/browser
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories