Typosquatting, HTTP deps, fake author
Fallout, Aug 31 – Sep 6
What we caught this week while monitoring over 163,052,840 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 6 · 777 catches · 62 waves · 22 singlesHardcoded Telegram C2 exfiltration
Downloads and executes hidden PowerShell payload
Remote control, persistence, credential access
Process injection APIs present
Process injection and evasion APIs
Credential theft, broad permissions, evasion
Embedded credential exfiltration payloads
cookie exfil, credential harvesting, autonomous agent
Obfuscated self-deleting Ethereum C2 dropper
Obfuscated crypto miner in font file
Disables competing proxy extensions
Agent traffic interception and credential theft
Downloads and executes remote binaries
OOB exfiltration via preinstall hook
OOB beacon, fake version, preinstall
Downloads and executes remote payload
Clipboard exfiltration, screen capture, input injection
Exfiltrates credentials to OOB server
Exfiltrates credentials to OOB server
OOB exfiltration and install hooks
Exfiltrates system data to OOB
Exfiltrates environment variables to OOB
Exfiltrates system data via webhook
Exfiltrates environment variables to OOB
postinstall downloads and executes remote code
OOB exfil, fake version, install hooks
Exfiltrates env data via webhook
Exfiltrates host info to webhook.site
Exfiltrates credentials to OOB server
Downloads and executes remote payload
Exfiltrates system info to OOB
Exfiltrates secrets via install hook
preinstall exfiltrates system info
preinstall downloads and executes Bun
Preinstall exfiltrates system info
Preinstall exfiltrates system info
Remote agent, persistence, bypass permissions
Downloads and executes remote payload
Downloads and executes remote binary
Exfiltrates environment variables to OOB
Exfiltrates system info to OOB
SSH key exfiltration, C2 beacon
Downloads and executes remote binary
Exfiltrates system info to OOB
Exfiltrates system data via OOB
Full-screen ad overlay injection
Exfiltrates system info to OOB
Trojanized package with malicious dependency
Trojanized dependency with hidden loader
preinstall downloads and executes Bun
TikTok scraper with C2 and evasion
Exfiltrates Discord tokens to webhook
Discord token stealer
Bytecode obfuscation, CDP, shell exec
TikTok scraper with C2 and evasion
Remote code execution via eval
Game cheat with process injection
Game cheat with process injection
Exfiltrates system info via install hooks
Bundled RedShell backdoor binary
EtherHiding crypto drainer payload
Remote code execution via base64
Exfiltrates SSH keys, env, Telegram data
Obfuscated credential stealer
AI agent remote control tool
preinstall downloads and executes obfuscated payload
Remote code execution, C2, obfuscation
preinstall downloads and executes remote code
Obfuscated malware in preinstall hook
Exfiltrates system info via install hooks
Obfuscated session wipe and data exfil
Russian propaganda audio injection
SATURDAY
Sat Sep 5 · 37 catches · 0 waves · 16 singlesRemote AI agent control binary
Obfuscated Lua dropper in archive
Remote AI CLI control agent
Fake GitHub domain impersonates AWS ECS Agent
Obfuscated dropper with anti-analysis
Browser hijacker, data exfiltration
RDP enable, sudoers NOPASSWD, masquerade, evasive base64
AD pentest framework, credential dumping
Malicious SweetAlert2 payload
obfuscated self-updating backdoor agent
Steals Twitter auth tokens
Harvests marketplace session cookies
FRIDAY
Fri Sep 4 · 6203 catches · 470 waves · 17 singlesDownloads and executes remote binaries
config.php contains webshell eval
Exfiltrates wallet private keys
postinstall exfiltrates to webhook.site
Downloads and executes remote binaries
Downloads and executes remote payloads
Malicious ad injection and self-update
Obfuscated credential-stealing preinstall hook
Exfiltrates system info to hardcoded IP
Exfiltrates system data to OOB domain
Exfiltrates system data to C2
Trojanized package with obfuscated code
Downloads and executes remote binaries
Preinstall exfiltrates system info to OOB
Downloads and executes remote binary
DNS exfil, payload download, execution
Downloads and executes remote binary
Dropper downloads and executes Bun runtime
Credential stealer with persistence and exfiltration
Downloads and executes remote binaries
Obfuscated credential-stealing preinstall payload
Obfuscated payload, preinstall hook, C2
Exfiltrates system info via install hooks
postinstall exfiltrates logs to OAST
Remote code execution via C2
C2, reverse shell, data exfiltration
Malicious backdoor with C2 and reverse shell
Remote code execution via eval
DNS exfil, binary download, execution
Remote agent bypasses permissions
Exfiltrates system info to OOB
Self-referential dependency, remote code execution
Downloads and executes remote payload
preinstall exfiltrates system data
Obfuscated malware with credential theft
Malicious dependency exfiltrates data
Exfiltrates system info via install hooks
Exfiltrates secrets via install hook
Embedded Shai-Hulud malware payload
Exfiltrates AWS credentials via OOB
Downloads and executes remote payload
npm postinstall credential harvester
Preinstall hook exfiltrates system info
Exfiltrates system info to OOB
preinstall exfiltrates host identity via OOB
preinstall exfiltrates host data via OOB
Dropper downloads and executes obfuscated payload
Browser credential and wallet stealer
Credential theft and email harvesting
Malicious C2 and privilege escalation
Malicious install hook executes hidden PowerShell
Malicious install hook executes payload
Exfiltrates secrets to webhook.site
Downloads and executes remote binary
Exfiltrates email via postinstall
postinstall executes remote code
UAC bypass, C2 beacon, data exfil
Exfiltrates system data to hardcoded IP
Obfuscated C2 beaconing to malicious domain
preinstall executes remote code
Downloads and executes remote payload
Exfiltrates system data to OOB
Typosquat of big.js with trojanized security-hold dependency
preinstall downloads and executes obfuscated payload
Downloads and executes remote binary
Steals wallets, history, exfiltrates data
Exfiltrates secrets to hardcoded IP
Game cheat with process injection
Game cheat with process injection
Preinstall exfiltrates system info
Remote code execution via postinstall
Base64 obfuscated malicious install command
Exfiltrates system info to webhook.site
SSH key injection, data exfiltration
Embedded Shai-Hulud malware payload
preinstall hook executes arbitrary code
Preinstall hook executes remote code
Dynamic code execution, C2 IP
SSH key injection, data exfiltration
Exfiltrates system info to hardcoded IP
Obfuscated payload, preinstall downloads/executes Bun
Exfiltrates environment via preinstall
Exfiltrates sensitive data to remote server
Trojanized dependency with hidden loader
Exfiltrates secrets via Telegram
Credential stealer and dropper
Exfiltrates system info to OOB
Exfiltrates credentials, executes remote commands
postinstall exfiltrates environment data
Exfiltrates secrets to webhook.site
DNS exfil, binary download, execution
Exfiltrates system info via DNS
preinstall downloads and executes Bun
Exfiltrates system info via preinstall
preinstall hook exfiltrates system info
Exfiltrates system data to OOB
Embedded Shai-Hulud malware payload
Downloads and executes remote payload
Exfiltrates system data to C2
Exfiltrates secrets via preinstall hook
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Exfiltrates system credentials and files
Remote code execution via eval
Exfiltrates system credentials and data
preinstall exfiltrates .env to Telegram
DNS C2, payload download, execution
Token harvester, exfiltrates secrets
Exfiltrates secrets to webhook.site
Obfuscated dropper executes downloaded payload
Exfiltrates files via webhook.site
Credential theft and exfiltration malware
Base64 obfuscated malicious install command
Exfiltrates secrets to webhook.site, spawns detached scripts, republishes packages
Embedded Shai-Hulud malware payload
Remote code execution and persistence
Exfiltrates secrets to webhook.site
Steals crypto wallet secrets, exfiltrates to C2
Embedded agent installer with persistence
Credential and AI-config exfiltration indicators
Fake VPN, known malicious relay domains
Obfuscated font file executes C2
Exfiltrates secrets via postinstall hook
Downloads and executes remote binary
preinstall exfiltrates system info
Exfiltrates credentials, deploys malware
Obfuscated credential stealer and dropper
Downloads and executes remote payload
Dependency confusion exfiltration POC
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall downloads/executes Bun
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Dropper downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Downloads and executes hidden Bun runtime
preinstall downloads and executes Bun
Obfuscated payload, Bun dropper, preinstall
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, preinstall Bun dropper
Preinstall drops obfuscated credential-stealing payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated dropper downloads and executes Bun
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, downloads and executes Bun runtime
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated credential theft during install
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun download
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall runtime download
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall downloads/executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
Obfuscated payload, preinstall Bun dropper
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes Bun
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated payload, preinstall runtime download
Downloads and executes obfuscated payload
Credential stealer and C2 exfiltration
postinstall drops and runs encoded stealer
Credential stealer with obfuscation
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes Bun
preinstall downloads and executes Bun
Obfuscated payload, runtime download, preinstall hook
Obfuscated dropper executes hidden payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
preinstall downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Obfuscated preinstall credential stealer
Obfuscated payload, preinstall hook, C2
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall Bun dropper
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes remote payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, C2
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall hook, runtime download
Obfuscated payload, downloads and executes Bun
Obfuscated dropper spawns hidden child process
Remote code execution via axios
preinstall hook executes obfuscated payload
Remote code execution via axios
Steals credentials, exfiltrates via Telegram
OOB exfiltration, dependency confusion POC
Obfuscated hidden payload execution
Downloads and executes remote binaries
Obfuscated remote code execution
preinstall executes hidden ELF binary
postinstall exfiltrates host recon to remote server
Obfuscated preinstall dropper spawning payload
Disables TLS, downloads from raw IP
EtherHiding malware payload
preinstall executes obfuscated malicious code
preinstall executes obfuscated malicious payload
preinstall hook executes obfuscated payload
preinstall hook, obfuscated credential theft
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
preinstall hook executes obfuscated payload
obfuscated credential-stealing malware
preinstall hook runs obfuscated payload
Obfuscated credential stealer in preinstall
preinstall hook executes obfuscated payload
preinstall executes obfuscated malware
malicious preinstall script
preinstall hook executes obfuscated payload
preinstall executes obfuscated malicious payload
preinstall hook executes obfuscated malware
preinstall hook executes obfuscated payload
Obfuscated preinstall credential stealer
preinstall hook executes obfuscated payload
Obfuscated payload in postcss config
Downloads and executes obfuscated payload
Obfuscated remote code execution
Obfuscated install script downloads and executes payload
Obfuscated credential stealer in preinstall
Obfuscated credential stealer with install hook dropper
Obfuscated credential stealer
Credential stealer with obfuscation
Obfuscated credential stealer in preinstall
Obfuscated credential stealer payload
Obfuscated credential stealer and dropper
Obfuscated credential stealer in preinstall
Obfuscated credential stealer and dropper
Credential stealer in obfuscated router_init.js
Obfuscated credential stealer and dropper
Obfuscated credential stealer with install hook
Obfuscated credential stealer and dropper
Obfuscated C2 with preinstall hook
Whalent malware, obfuscated C2, self-update
Whalent backdoor, obfuscated C2, self-update
Obfuscated backdoor with C2 and self-update
Obfuscated backdoor with C2 and self-update
Malicious persistence and payload execution
Obfuscated backdoor with C2 and self-update
Obfuscated backdoor with C2 and self-update
Typosquat of bitcoinjs-lib; postinstall launches hidden bip40 daemon
Obfuscated backdoor with C2 and self-update
Exfiltrates secrets via webhook.site
Recon, flag theft, exfiltration to hardcoded IP
Obfuscated credential theft and C2
Embedded secret exfiltration script
Obfuscated C2 beacon in install hook
Embedded Shai-Hulud malware payload
Embedded supply chain malware payload
Obfuscated credential theft and C2
Obfuscated credential theft and C2
Exfiltrates secrets to webhook.site
Embedded Shai-Hulud malware payload
Credential stealer disguised as Mistral SDK
Obfuscated credential stealer in router_init.js
Embedded script exfiltrates GitHub secrets to webhook.site
preinstall downloads and executes obfuscated payload
Obfuscated preinstall downloads and executes payload
Exfiltrates system info to OOB server
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Dropper downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Steals credentials, obfuscated, drops runtime
Obfuscated dropper downloads and executes Bun
Credential stealer, obfuscated, self-daemonizing
obfuscated dropper downloads and executes payload
Obfuscated credential stealer payload
Obfuscated dropper downloads and executes Bun
Obfuscated dropper downloads and executes Bun
Obfuscated dropper downloads and executes Bun
obfuscated dropper downloads and executes payload
Obfuscated AWS credential theft
Obfuscated credential stealer and dropper
Trojanized dependency easy-day-js
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Exfiltrates secrets to webhook.site
Embedded secret exfiltration script
Exfiltrates secrets to webhook.site
Shai-Hulud worm payload embedded
Exfiltrates secrets to webhook.site
Shai-Hulud worm payload embedded
Embedded secret exfiltration script
Shai-Hulud worm payload embedded
Obfuscated agent, CDP, shell exec, install hooks
Exfiltrates secrets to webhook.site
Shai-Hulud worm exfiltrates secrets
preinstall dropper executes obfuscated credential-stealing payload
curl piped to zsh C2 dropper
Obfuscated data exfiltration to hardcoded IP
Obfuscated DNS exfiltration with preinstall hook
Preinstall downloads and executes obfuscated payload
Obfuscated payload, preinstall executes Bun
Preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall dropper runs obfuscated credential-stealing payload
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes obfuscated payload
Obfuscated dropper downloads and executes Bun
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Downloads and executes obfuscated payload
Exfiltrates secrets to webhook.site
Downloads and executes remote binaries
Downloads and executes remote payload
Credential harvesting and exfiltration
Obfuscated malicious npm package
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Embedded secret exfiltration script
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Exfiltrates secrets to webhook.site
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Embedded secret exfiltration script
preinstall executes obfuscated payload
preinstall executes obfuscated payload
preinstall executes obfuscated payload
Exfiltrates credentials via preinstall hook
preinstall exfiltrates to oastify
Ignores malware scanners, hides code in bytecode
Exfiltrates system data to webhook
preinstall executes remote shell
Exfiltrates secrets to webhook.site
Embedded secret exfiltration script
Embedded secret exfiltration script
Embedded secret exfiltration script
Embedded secret exfiltration script
Embedded Shai-Hulud malware payload
Embedded secret exfiltration script
Embedded secret exfiltration script
Bundle contains secret exfiltration script
Malicious install hook exfiltrates data
setup.py downloads and executes remote malware
Malicious PowerShell download cradle in starter.py
Exfiltrates environment variables to remote server
Steals and exfiltrates Roblox cookies
Dropper with obfuscation and cleanup
Downloads and executes remote RAT
Raw-IP dropper with anti-forensics
Multi-arch botnet dropper script
Encoded subprocess, useradd, cloned repo
Exfiltrates flag via HTTP to IP
CAPTCHA solver, cookie theft, evasion
THURSDAY
Thu Sep 3 · 366 catches · 29 waves · 19 singlesDownloads and executes obfuscated payload
Malicious install hook exfiltrates data
Malicious install hook exfiltrates data
Exfiltrates mnemonic to hardcoded IP
Exfiltrates flag via install hook
C2, persistence, credential theft
Exfiltrates system info to hardcoded IP
Typosquat with reverse shell and exfiltration
Steals Sui wallet keys
Trojanized package with hidden dependency
Exfiltrates environment variables via install hooks
preinstall downloads and executes obfuscated payload
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
preinstall downloads and executes Bun
Disables TLS, downloads from raw IP
obfuscated dropper downloads and executes payload
preinstall downloads and executes obfuscated payload
Preinstall downloads and executes obfuscated payload
Downloads and executes remote payload
preinstall downloads and executes obfuscated payload
obfuscated dropper downloads and executes payload
Obfuscated dropper downloads and executes Bun
preinstall downloads and executes Bun
Downloads and executes remote binary
Downloads and executes obfuscated payload
preinstall downloads and executes obfuscated payload
Obfuscated self-defending dist with eval, child_process, OAuth tokens
Credential-stealing browser extension
obfuscated backdoor with self-update
Signed with malicious 'ollypwn' cert
Post-exploitation framework with obfuscation
嵌入base64-gzip载荷,大量可疑JavaScript执行
SQL injection attack tool
Metasploit Meterpreter payloads
Metasploit Meterpreter payload gem
Metasploit Meterpreter payload gem
Bundled SweetAlert2 contains Russian-targeted sabotage payload
Steals cookies, hooks, evades detection
Metasploit framework dependency
Exfiltrates Coze API tokens and data
WEDNESDAY
Wed Sep 2 · 66 catches · 1 wave · 17 singlesObfuscated payload execution via new Function
Typosquatting, obfuscation, runtime npm install
Malicious region-gated audio payload
Exfiltrates credentials, env, and system info
Obfuscated PHP webshell included
Decodes and executes hidden payload
Sliver implant in binary
Steals wallet secrets and clipboard
Clipboard exfiltration, fake wallet UI
Clipboard exfiltration, wallet drainer
Process injection and evasion APIs
Trojanized extension with hidden payload
Base64 tasking backdoor, log wiping, self-destruct
Embedded Russian regional malware payload
Malicious code in bundled JS
TUESDAY
Tue Sep 1 · 36 catches · 1 wave · 16 singlesobfuscated preinstall dropper executes commands
Disables other extensions, bypasses LMS security
Steals credentials, exfiltrates to C2
Signed malware with RAT capabilities
Clipboard stealer, wallet drainer
Process injection, C2, privilege escalation
Supply chain sabotage in SweetAlert2
Embedded Russian propaganda payload
Embedded webshell signature payload
Automated spam and CAPTCHA bypass
Backdoor activation detection logic
Keylogger, screen capture, anti-analysis
Malicious code in SweetAlert2 library
Credential theft and C2 indicators
MONDAY
Mon Aug 31 · 45 catches · 0 waves · 18 singlesMalicious SweetAlert2 payload targeting Russian users
Malicious regional browser hijack code
Writes DLL to AppData and creates rundll32 scheduled-task persistence
embedded eval webshell payload
Embedded Russian regional malware payload
Embedded Russian-targeted sabotage payload
Mythic C2 framework source
Mythic C2 framework source
Browser credential theft and evasion
installs persistent telemetry hooks
Malicious payload in SweetAlert2
Remote agent, persistence, credential access
Exfiltrates credentials, hooks XHR, debugger