OOB exfiltration of system info
Fallout, Aug 24 – Aug 30
What we caught this week while monitoring over 163,107,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 30 · 18 catches · 0 waves · 11 singlesSMM view-bot automation tool
DLL injection dependency
Malicious region-gated audio injection
clipboard stealer, wallet drainer
Encrypted strings, SOCKS proxy, process execution
Region-gated UI suppression and audio loop
Obfuscated backdoor with C2 and self-update
Remote AI CLI control backdoor
AI CLI remote-control backdoor
Obfuscated Lua payload in wiki
SATURDAY
Sat Aug 29 · 23 catches · 1 wave · 14 singlesDiscord webhook exfiltration
Downloads and executes remote payloads
Exfiltrates credentials to Telegram and external server
Obfuscated credential theft and persistence
Spawns detached Node with decrypted payload
preinstall exfiltrates system info
Backdoor detection and data exfiltration
Bundles protestware payload
Obfuscated Lua payload in Go module
Obfuscated Lua payload, nested archives, masquerading LuaJIT dropper
FRIDAY
Fri Aug 28 · 30 catches · 0 waves · 16 singlespreinstall exfiltrates system info
Credential theft, obfuscated payload, C2
Phishing page exfiltrates credentials
binding.gyp executes OS command
binding.gyp executes OS command
Credential theft, excessive permissions, obfuscation
Fake VPN proxy farm
Bundled SweetAlert2 contains region-gated audio/pointer-events sabotage
Base64 command execution, log deletion
Exfiltrates files to Telegram C2.
Bundled protestware disables browser
Exfiltrates files via hardcoded Telegram bot
Bundled protestware disables UI, plays audio
THURSDAY
Thu Aug 27 · 35 catches · 1 wave · 15 singlesTrojanized npm phishing facade
Obfuscated crypto-stealer payload
obfuscated dynamic import, fake error exit
Credential theft, excessive permissions, obfuscation
Malicious region-gated audio payload
Malicious code in SweetAlert2 library
Credential exfiltration, broad permissions, obfuscation
AV evasion, UAC bypass, persistence
C2 framework with obfuscated Lua payloads
obfuscated remote-updating agent backdoor
Bundled ransomware in SweetAlert2
postinstall beacon exfiltrates hostname
WEDNESDAY
Wed Aug 26 · 218 catches · 5 waves · 19 singlesDownloads and executes raw IP payloads
Credential theft, evasion, broad access
WhatsApp spam automation tool
Credential theft, excessive permissions, obfuscation
Obfuscated PowerShell dropper with persistence
Obfuscated WSH dropper writes payload
Obfuscated WSH dropper writes payload
Obfuscated VBScript dropper with C2
Ransomware binary with attack functions
Native host, PowerShell bypass, credential exfil
obfuscated payload execution in dependency
Obfuscated backdoor with C2 and self-update
malicious htmlescape dependency
XSS injection in htmlescape dependency
SQLi toolkit with embedded exploit payloads
Bundled protestware disables browser
C2 URL in package definition
Dependency clay-server classified hostile
TUESDAY
Tue Aug 25 · 117 catches · 1 wave · 29 singlesDownloads and executes raw IP payloads
Bundled protestware disables browser
Embedded offensive security tooling
Cybersecurity tool with offensive capabilities
postinstall curl-pipe-shell dropper
NPM install hook credential stealer
C2 beacon and reverse shell generator
Keylogger, screen capture, C2, exfiltration
Hostile dependency embedded in archive
sweetalert2 protestware embedded
Telegram-controlled remote desktop malware
Malicious code in SweetAlert2
Trojanized dependency with malicious install hooks
Browser cookie credential extraction
obfuscated C2, credential theft, persistence
obfuscated eval payload, anti-analysis
Contains shellcode execution templates
Bundled region-gated protestware payload
Remote code execution in sandbox
XSS injection in htmlescape dependency
hidden PowerShell, persistence, process injection
Embedded malicious dependency
HTTP desync probe in dependency
Undisclosed adware, IP-based C2
MONDAY
Mon Aug 24 · 138 catches · 7 waves · 28 singlesHostile dependency: credential exfiltration
HTTP desync probe in dependency
Hostile dependency NuGet.exe embedded
embedded reverse shell in dependency
Relays Facebook credentials to third-party server
Credential stealer with install hook
Exfiltrates WhatsApp session credentials
DNS exfiltration in preinstall hook
credential theft via remote relay
Bundled protestware payload
Test file contains webshell payload
obfuscated wasm payload, typosquatting
emp3r0r C2 framework with RAT, BOF, and evasion
Typosquatting with hidden payload
Install hooks exfiltrate system data
Signed malware with C2 and evasion
Signed malware with C2 and injection
malicious dependency htmlescape
Bundled protestware disables browser
EtherHiding malware in disguised font file
Malicious crypto drainer payload
Malicious VSCode autorun executes hidden payload
Bundled protestware disables browser