Obfuscated credential theft and persistence
hidden-payload/runtimeobfuscator/js-obfuscator
What we caught this week while monitoring over 163,411,591 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
Obfuscated credential theft and persistence
Exfiltrates files to Telegram C2.
Exfiltrates files via hardcoded Telegram bot
XSS injection in htmlescape dependency
hidden PowerShell, persistence, process injection