Fallout, Sep 14 – Sep 20

What we caught this week while monitoring over 155,936,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

SUNDAY

Sun Sep 20 · 136 catches · 1 wave · 15 singles
micro-behaviors/fsmicro-behaviorsobjectives/executionobjectives/supply-chainmicro-behaviors/communicationsmicro-behaviors/processobjectives/command-and-controlobjectives 1d
nixw.sh and 2 siblings biggest campaign 1 day ago

Downloads and executes remote binary

delivery/execute-downloaddelivery/fetch-exec
well-knownwell-known/librarymicro-behaviors/osmicro-behaviorsmicro-behaviors/datamicro-behaviors/memmicro-behaviors/fsobjectivesobjectives/command-and-controlobjectives/evasionmicro-behaviors/process 1d

Thread hooking, PEB spoofing, self-deletion

hook/inlineloader/native-reflect
objectives/command-and-controlwell-knownwell-known/librarymicro-behaviors/cryptomicro-behaviorsmicro-behaviors/osmicro-behaviors/memobjectivesobjectives/evasionobjectives/persistencemicro-behaviors/process+2 1d

Thread hooking, PEB spoofing, persistence

hook/inlinestartup/registry
well-knownwell-known/toolmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectivesmicro-behaviors/process+16 1d

Shellcode injection and AV evasion

injection/memoryinjection/shellcode
well-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectivesmicro-behaviors/process+16 1d

Shellcode injection and AMSI bypass

injection/memoryinjection/shellcode
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadatamicro-behaviors/cryptomicro-behaviors/dataobjectives/supply-chainobjectives 1d

Typosquatting wallet key exfiltration

trojanized/distimpersonation/clone-and-rename
objectives/anti-staticobjectiveswell-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-analysisobjectives/collectionthird_party+31 1d

PowerShell Empire C2 framework

Invoke/MetasploitInvoke/Shellcodemsil
micro-behaviors/datamicro-behaviorsmetadatametadata/langobjectives/command-and-controlmicro-behaviors/osmicro-behaviors/processmetadata/signedobjectives/anti-staticobjectivesobjectives/execution 1d

Obfuscated PowerShell execution

string/fragmentationvbscript/loader
well-known/librarywell-knownmetadatametadata/buildobjectives/anti-staticobjectives/supply-chainobjectives/collectionobjectives/credential-accessobjectivesmicro-behaviors/browser-extensionmicro-behaviors+14 1d

Uninstalls other extensions, steals cookies

browser-extension/managementphishing/landing
well-known/librarywell-knownmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/supply-chainobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/command-and-control+14 2d
Zero 0.2.2 chrome oekaejfadgmfjkbeibnnjbpjdeknmnbn 186 installs 2 days ago

Exfiltrates cookies, full browser control

remote-command/extensionbrowser/extension
micro-behaviors/communicationsmicro-behaviorsmalware/libmalwaremetadatametadata/importobjectives/anti-staticobjectives/command-and-controlobjectives/collectionobjectives/supply-chainobjectives+12 2d

bytenode, obfuscation, exfiltration, persistence

host-profile/victim
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/anti-staticobjectives/collectionobjectives/command-and-controlobjectives/impactobjectivesobjectives/exfiltration+10 2d
TaskFlow Helper 0.8.12 firefox taskflow-helper 1 installs 2 days ago

Automated payout theft bot

http/report
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/executionmetadata/packageobjectives/supply-chainobjectives+29 2d

Installs MITM CA, intercepts traffic

scripts/prepareautoinstall/package
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/toolsmetadatametadata/importobjectives/command-and-controlobjectives/supply-chainobjectives/discoveryobjectivesobjectives/exfiltration+11 2d
milenium 1.1.2 python 2 days ago

Hardcoded exfil database credentials

network/enumerationmessaging/telegram
well-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/command-and-controlobjectives/supply-chainobjectives/discoveryobjectivesobjectives/exfiltration+11 2d
milenium 1.1.1 python 2 days ago

Hardcoded exfil database credentials

network/enumerationmessaging/telegram
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemalwaremalware/librarymetadataobjectives/discoveryobjectives/anti-analysisobjectives/exfiltrationobjectivesobjectives/supply-chain+9 2d
@siriusbeyond/utils 99.0.0 javascript and 2 siblings 2 days ago

Exfiltrates secrets via Telegram

messaging/telegramrecon-exfil/install-hook
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/supply-chainobjectives/anti-staticobjectives/command-and-controlobjectives/impactmicro-behaviors/communicationsobjectives/credential-accessobjectives+9 2d
flowApply 1.4 chrome bnkmbdoljamcajaciniidbliffdbdpad 5 installs 2 days ago

Exfiltrates LinkedIn cookies to remote server

browser/extensionphishing/mfa-relay

SATURDAY

Sat Sep 19 · 125 catches · 3 waves · 17 singles
well-knownwell-known/dual-usemetadatametadata/packageobjectives/anti-staticobjectives/executionmicro-behaviors/memmicro-behaviorsobjectives/credential-accessobjectivesmicro-behaviors/process+16 3d
github.com/itaym….0.3+incompatible go and 5 siblings biggest campaign 3 days ago

C2 framework with RAT capabilities

dump/processread/dump
objectives/anti-staticmicro-behaviors/processmicro-behaviorsmalware/Mcmetadata/documentmalwaremetadataobjectives/evasionobjectivesobjectives/command-and-controlthird_party+27 2d

Contains actual malware samples

Windows/Wannacrystaging/encrypted
well-knownwell-known/toolmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/executionobjectives+12 2d

Embedded PHP webshell payload

exploit/sandbox-escapeeval/remote
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/toolsmetadatametadata/buildobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/executionobjectives+13 2d

Embedded PHP webshell payload

exploit/sandbox-escapeeval/remote
micro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlobjectives/credential-accessobjectives/evasionobjectives/impactmicro-behaviors/processmicro-behaviors/osobjectives/anti-staticobjectives/executionobjectives+4 2d

Clickfix malware loader

clipboard/pageencoding/content
micro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/evasionmicro-behaviors/processmicro-behaviors/datamicro-behaviors/osobjectives/executionobjectives+1 2d

Clickfix malware loader

clipboard/instructionclipboard/page
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/packagemicro-behaviors/processmetadata/permissionobjectivesobjectives/execution 2d

Remote code execution on open

trigger/ide
micro-behaviors/communicationsmicro-behaviorsmalware/appmalwaremetadatametadata/importobjectives/command-and-controlobjectives/executionobjectives/exfiltrationobjectives/supply-chainobjectives+17 2d
clawdbot-go 1.0.4 javascript 2 days ago

Credential exfiltration and remote code execution

install-hook/remote-binaryinstall-hook/skill-agent
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemalware/librarymalwaremetadataobjectives/supply-chainobjectives/anti-staticobjectivesobjectives/command-and-controlobjectives/exfiltration+7 2d

Exfiltrates env, executes remote code

http/envdelivery/fetch-eval
well-known/appwell-knownmetadata/binarymetadataobjectives/anti-analysisobjectives/collectionobjectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives+31 3d

installs MITM CA, intercepts AI traffic

eval/requirerequest/credentials
well-known/librarywell-knownmetadatametadata/packageobjectives/anti-staticobjectives/supply-chainobjectives/executionmicro-behaviors/processmicro-behaviorsobjectivesobjectives/evasion+13 3d
Chrome Web Store chrome gnmpfkiolmopmndaljgigppfebbhfjam 3 days ago

Credential theft, account manipulation

policy/browserhook/webextension
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/impactobjectivesobjectives/exfiltration+10 3d
TaskFlow Helper 0.8.11 firefox and 3 siblings 1 installs 3 days ago

Steals auth tokens, automates financial actions

http/report
micro-behaviors/communicationsmicro-behaviorsobjectives/impactobjectives/anti-staticobjectives/anti-analysisobjectives/persistenceobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectivesobjectives/supply-chain+10 3d
ChainlessChain IDE Bridge 0.4.129 jetbrains com.chainlesschain.ide 2,397 installs 3 days ago

Encoded PowerShell, C2, new package

app/ide-extensiondelivery/download
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/supply-chainobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/exfiltration+17 3d
NoobClaw Browser Assistant 2.0.6 firefox noobclaw-browser-assistant 1 installs 3 days ago

Remote command execution, cookie theft

remote-command/extensionhttp/report
well-known/librarywell-knownmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/supply-chainobjectives/collectionobjectivesobjectives/exfiltration+11 3d
Phishing Guard 1.0 firefox phishing-guard 3 days ago

Phishing extension with credential capture

http/report
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesobjectives/exfiltration+15 3d
NoobClaw Browser Assistant 2.0.4 firefox noobclaw-browser-assistant 1 installs 3 days ago

Remote command execution, cookie theft

remote-command/extensionhttp/report
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectivesobjectives/collection+18 3d
OpenOffice Calc online for xls spreadsheets 3.0.4 chrome fiffkcnehndkebmpinoknndjbhdpbkcn 20,000 installs 3 days ago

Exfiltrates data to remote server

stealer/browser
objectives/command-and-controlwell-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/persistence+23 3d
pwn 0.5.743 ruby 1,099,243 installs 3 days ago

Offensive security framework with AI agent

shell/rcservice/install
well-knownwell-known/Mcmetadatametadata/packageobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/memmicro-behaviorsobjectives/credential-accessobjectivesmicro-behaviors/process+17 3d
github.com/itaym…3dcd+incompatible go and 3 siblings 3 days ago

C2 framework with RAT capabilities

dump/processread/dump
well-knownwell-known/dual-usemetadatametadata/packageobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/memmicro-behaviorsobjectives/credential-accessobjectivesmicro-behaviors/process+15 3d
github.com/itaym….1.0+incompatible go and 4 siblings 3 days ago

C2 framework with RAT capabilities

dump/processread/dump
well-known/Mcmicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesobjectives/collectionwell-known+6 3d
Myxa Light VPN 1.0.0 chrome innjppfndpgigpnoicbofacmdpiblmge 6 installs 3 days ago

Fake VPN extension farm

supply-chain/fake-vpn-extension-farmnetwork/proxy

FRIDAY

Fri Sep 18 · 159 catches · 1 wave · 18 singles
objectives/anti-staticobjectiveswell-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-analysisobjectives/collectionthird_party+31 3d
github.com/netti….0.3+incompatible go and 4 siblings biggest campaign 3 days ago

Post-exploitation C2 framework

windows/hacktool_sharpwmiKeepassconfig/Gen
objectivesobjectives/lateral-movementwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/evasionobjectives/supply-chainwell-known+13 3d

Mirai botnet malware source

botnet/mirai-katrina
micro-behaviors/communicationsmicro-behaviorsmalware/Mcmetadatametadata/buildobjectives/anti-staticobjectives/evasionobjectives/supply-chainobjectivesobjectives/lateral-movementmalware+14 3d

Mirai botnet malware source

botnet/mirai-katrinabrute-force/iot
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/supply-chainobjectives/anti-staticobjectives/exfiltrationobjectives+16 3d
Chrome Web Store chrome eehkanbgfihkcabiblmokegmdoibcokj 3 days ago

Credential harvesting and social media automation

http/report
well-known/appwell-knownmicro-behaviors/datamicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/executionobjectivesthird_party+26 3d

CTF webshells and exploits included

PHP/Genericexploit/include-gadget
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectives/evasionobjectives+21 3d
Secure My Pass 1.6.17 firefox secure-my-pass 861 installs 3 days ago

Steals cookies, exfiltrates ticket data

masquerade/traffic
well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectives/supply-chainobjectives+15 3d

Credential theft, obfuscation, C2, persistence

app/config-injection
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/credential-accessmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/evasionobjectives/exfiltration+5 3d
R💲bby 177.0.1 firefox dj3iguh594g 15 installs 3 days ago

Steals wallet seed phrases

credential/clipboardextension/deception
micro-behaviors/communicationsmicro-behaviorsmalware/appmetadata/buildmalwaremetadataobjectives/anti-staticobjectives/privilege-escalationobjectivesobjectives/supply-chainmetadata/package+25 4d
pwn 0.5.741 ruby 1,099,243 installs 4 days ago

Offensive security framework with exploit tools

elevation-control/sudopackage/rubygems
micro-behaviorsmicro-behaviors/browser-extensionmalware/appmetadata/buildmalwaremetadataobjectives/anti-analysisobjectives/anti-staticobjectives/persistenceobjectives/supply-chainobjectives+27 4d
zevairouter 1.1.27 javascript and 2 siblings 4 days ago

MITM root CA generation

recon-exfil/wallet-keysystem/supervised
objectives/command-and-controlwell-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectivesobjectives/evasionobjectives/impact+23 4d
pwn 0.5.740 ruby 1,099,241 installs 4 days ago

Offensive security framework with agent skills

services/stopsecurity-bypass/access-list
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/supply-chainobjectives/command-and-controlobjectives/collectionobjectives+12 4d

Exfiltrates cookies, credentials, and user data

stealer/browser
micro-behaviorsmicro-behaviors/processobjectives/supply-chainobjectivesmetadata/packagemetadata 4d

preinstall hook, HTTP deps

package/direct-urldependencies/direct-url
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/Mcmetadatametadata/importobjectives/supply-chainobjectives/command-and-controlobjectives/credential-accessobjectivesobjectives/exfiltration+7 4d

Exfiltrates system data via preinstall

theft/multi-storeexfiltration/sensitive-data
micro-behaviorsmicro-behaviors/processobjectives/supply-chainobjectivesmetadata/packagemetadata 4d

preinstall hook, HTTP deps

package/direct-urldependencies/direct-url
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectives/exfiltrationobjectives+12 4d

Credential harvesting and obfuscation

http/uploadstealer/file
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemalwaremalware/Mcmetadataobjectives/command-and-controlobjectives/collectionobjectives/anti-staticobjectives/supply-chainobjectives+13 4d

OSV-listed malicious cdnshell loader

hidden-payload/runtimeobfuscator/js-obfuscator
well-known/librarywell-knownmicro-behaviors/processmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectives/evasionobjectives+20 4d
Chroma Color Picker 1.0.1 chrome ghcgolhjnajkjeogfjkaakdfohebocfa 32 installs 4 days ago

XHR hooking, C2, obfuscation

policy/browserphishing/credential
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectives/executionobjectives+23 4d
GKN Phantom 0.1.0 openclaw gkn-phantom 4 days ago

Offensive exploit toolkit

exploit/http-desyncexploit/sql-injection
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/credential-accessobjectives/anti-staticobjectives/lateral-movementobjectivesobjectives/exfiltration+17 4d
Costco Tools by RestockBotAlerts 1.6.5 firefox costco-tools-restockbotalerts 7 installs 4 days ago

Steals credentials, exfiltrates via ngrok

oob/endpointbrute-force/password

THURSDAY

Thu Sep 17 · 131 catches · 4 waves · 22 singles
well-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/anti-analysisobjectives/evasionobjectivesobjectives/credential-accesswell-known+8 4d
tankdupe-1.10.0+1.21.10.jar and 5 siblings biggest campaign 4 days ago

C2, credential theft, obfuscation

gaming/minecraftstealer/prefire-shard
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/exfiltrationobjectives/anti-analysisobjectives/anti-staticobjectives/command-and-controlobjectives+12 4d

Embedded reverse shell in code

reverse-shell/pty
well-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/executionobjectivesobjectives/supply-chainmetadata/packagewell-known+10 4d

Post-exploitation framework with obfuscation

backdoor/emp3r0rtrojanized/package
well-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadatametadata/binaryobjectives/anti-analysisobjectives/anti-staticobjectives/evasionobjectives/executionobjectives+29 4d

Credential theft and persistence

exploit/sql-injectionllm/override
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymalwaremalware/librarymetadataobjectives/credential-accessobjectivesobjectives/collectionthird_party+22 4d

Embedded credentials and lateral movement

EXE/Discordurlmonitor/agent-observation
micro-behaviors/datamicro-behaviorsmetadatametadata/importobjectives/anti-staticmicro-behaviors/processobjectives/supply-chainobjectives 4d

obfuscated eval spawn stager

app/sha256hidden-payload/staging
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/exfiltrationmicro-behaviors/cryptomicro-behaviors/osobjectivesobjectives/execution 4d

Forges admin token, exploits empty key

exploit/access-control
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/collectionobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectives/supply-chainobjectivesobjectives/credential-access+7 4d
Zupai LinkedIn Connector 1.0.11 chrome dnnkaadkbfjfgfeamldofojeboeocabf 4 days ago

Exfiltrates LinkedIn session cookies

browser/extension
well-knownwell-known/Mcmicro-behaviors/datamicro-behaviorsobjectives/command-and-controlobjectives/executionobjectives/anti-analysisobjectives/impactobjectives/persistenceobjectives/anti-staticobjectives+5 4d
ORDEN DE COMPRAS.JS and 2 siblings 4 days ago

Obfuscated ActiveX dropper

obfuscation/multi-layerobfuscation/syntax
micro-behaviors/communicationsmicro-behaviorsmetadata/permissionmetadataobjectives/command-and-controlmicro-behaviors/browser-extensionmicro-behaviors/dataobjectives/impactobjectivesobjectives/supply-chainmicro-behaviors/ui+3 4d
Omnibox Search with Anthropic 3.3.8 firefox claude-omni 3,675 installs 4 days ago

Remote config, hidden iframe, header stripping

manipulation/trafficextensions/affiliate
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/collectionobjectives/credential-accessobjectives/impactmicro-behaviors/communicationsobjectivesobjectives/evasionobjectives/exfiltration+6 4d
RB 177.0.1 firefox 54yuj76uki87ulk87u 2 installs 4 days ago

Steals wallet seed phrases

credential/clipboardextension/deception
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/exfiltrationmicro-behaviors/osmicro-behaviors/processmicro-behaviors/datamicro-behaviors/fsobjectivesobjectives/collection+2 4d
aiosendletter 4.5 python 4 days ago

Exfiltrates Telegram credentials

messaging/app
micro-behaviors/osmicro-behaviorsobjectives/lateral-movementobjectivesobjectives/command-and-control 5d

RDP backdoor configuration

control/rdp
well-knownwell-known/Mcmicro-behaviors/datamicro-behaviorsobjectives/command-and-controlobjectives/executionobjectives/anti-analysisobjectives/credential-accessobjectives/impactobjectives/anti-staticobjectives+6 5d
Request for quot…263-H26-2568-1.JS and 2 siblings 5 days ago

Obfuscated WSH dropper with ActiveX

obfuscation/multi-layerobfuscation/syntax
micro-behaviors/datamicro-behaviorsmalwaremalware/Mcobjectives/executionobjectives/anti-analysisobjectives/command-and-controlobjectives/credential-accessobjectives/impactobjectives/anti-staticobjectives+6 5d
Purchase Order -…-2603113056899.JS and 3 siblings 5 days ago

Obfuscated dropper with ActiveX and file writes

obfuscation/multi-layerobfuscation/syntax
well-known/toolwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectivesmetadataobjectives/collection+23 5d
souleyez 5.0.10 python 5 days ago

Automated offensive security tooling

token/metadatafile-targeting/filter
micro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmalwaremalware/appmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesobjectives/exfiltration+9 5d
GOATIMUS - AI Prompt Optimizer 1.0.1 chrome mpkbnhjplbmojkgeebefpdlijimlnpcm 83 installs 5 days ago

Steals auth tokens from localStorage

http/report
well-knownwell-known/appmicro-behaviors/hardwaremicro-behaviorsmetadatametadata/buildobjectives/command-and-controlobjectives/collectionobjectives/anti-staticobjectives/supply-chainobjectives+24 5d

Obfuscated credential theft and C2

hidden-payload/runtimeobfuscation/syntax
micro-behaviorsmicro-behaviors/cryptometadatametadata/langobjectives/privilege-escalationmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution+1 5d
INVPL_pdf.vbs and 2 siblings 5 days ago

Obfuscated VBScript, registry access, execution

vbscript/loaderstring/fragmentation
well-knownwell-known/toolmetadatametadata/packageobjectives/supply-chainobjectives/anti-staticmicro-behaviors/datamicro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlobjectives+2 5d

Malicious payload in sample file

dropper/python-scripturl/php-endpoint
third_party 5d
bashka 0.7.0 rust 5 days ago

Exfiltrates SSH keys, reverse shell

Shellpop/Bash
well-known/librarywell-knownmetadata/packagemetadataobjectives/supply-chainobjectives/credential-accessobjectives/anti-staticmicro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlobjectives+12 5d
AI 推评助手 1.0.1 chrome ikodagccglekglhaolfoenaenfjfoflk 1 installs 5 days ago

Exfiltrates Google OAuth tokens to raw IP

http/transportip/literal
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/osobjectives/command-and-controlobjectivesobjectives/supply-chainmetadata/package+5 5d

curl-to-bash, hidden payload, new package

execution/stealth-spawntrojanized/package
micro-behaviors/browser-extensionmicro-behaviorsmalwaremalware/appmetadatametadata/packageobjectives/credential-accessobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/exfiltration+17 5d

Credential harvesting and obfuscation

http/reportanalysis-bomb/rule-timeout
micro-behaviorsmicro-behaviors/browser-extensionmetadata/binarymalwaremalware/appmetadataobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/supply-chainobjectives+30 5d
Power Agents 3.0.169 vscode neural-llm/power-claude 10,554 installs 5 days ago

obfuscated credential stealer with persistence

hidden-payload/runtimeencoding/arithmetic

WEDNESDAY

Wed Sep 16 · 135 catches · 5 waves · 21 singles
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-analysisobjectives/evasionmicro-behaviors/datamicro-behaviors/processobjectives/anti-staticobjectivesobjectives/command-and-control+2 6d
198macros.org--1…cked-26.2.jar.jar and 17 siblings biggest campaign 6 days ago

Cracked loader, obfuscation, C2, vault

loader/classloaderreflection/class
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/collectionobjectives/supply-chainobjectiveswell-known/librarywell-known+19 5d

Targets AI agent configs, exfiltrates credentials

library/hidden-dep
well-known/librarywell-knownmetadata/permissionmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectivesobjectives/anti-analysismicro-behaviors/communicationsmicro-behaviors+13 5d

Steals credentials, obfuscated exfiltration

ip/literalanalysis-bomb/rule-timeout
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlmicro-behaviors/osmicro-behaviors/datametadata/buildobjectives/supply-chainobjectives/exfiltrationobjectives 5d

Exfiltrates deployment token to webhook

oob/endpointdropper/hook-setup
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlobjectives/impactmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectives/executionobjectives+2 5d

Java deserialization exploit tool

exploit/deserializationexploit/gadget
well-knownwell-known/appmicro-behaviorsmicro-behaviors/browser-extensionmetadata/binarymetadataobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/supply-chainobjectives+30 5d
Power Agents 3.0.166 vscode neural-llm/power-claude 10,205 installs 5 days ago

obfuscated credential stealer

hidden-payload/runtimeobfuscator/js-obfuscator
well-knownwell-known/librarymetadatametadata/packageobjectives/supply-chainobjectives/impactmicro-behaviors/communicationsobjectivesobjectives/exfiltrationmicro-behaviors/browser-extensionmicro-behaviors+5 5d
Chrome Web Store chrome pikonflmhdpgdibfjanleeghjphmpbkl 5 days ago

Steals OnlyFans session cookies

http/browser-extension
well-knownwell-known/appmicro-behaviorsmicro-behaviors/browser-extensionmetadata/binarymetadataobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/supply-chainobjectives+30 5d
Power Agents 3.0.159 vscode neural-llm/power-claude 10,205 installs 5 days ago

Credential harvesting and obfuscation

hidden-payload/runtimeobfuscator/js-obfuscator
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlobjectives/anti-staticobjectivesobjectives/credential-accessobjectives/exfiltration+10 5d
krypton-1.21.11.jar 5 days ago

Minecraft credential stealer with C2

gaming/minecraftcredential/token
objectives/discoveryobjectivesmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/exfiltrationobjectives/supply-chainobjectives/lateral-movementmicro-behaviors/datamicro-behaviors/os+3 5d

Exfiltrates system data to C2

well-knownwell-known/appmicro-behaviorsmicro-behaviors/browser-extensionmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/communicationsobjectives/credential-accessobjectives+8 5d
static-index.js 5 days ago

Steals Discord credentials and payment data

discord/token
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/impactobjectivesobjectives/exfiltration+10 5d
TaskFlow Helper 0.8.5 firefox taskflow-helper 1 installs 5 days ago

Steals credentials, automates financial actions

http/report
micro-behaviorsmicro-behaviors/browser-extensionmetadata/binarymalwaremalware/appmetadataobjectives/collectionobjectives/command-and-controlobjectives/anti-staticobjectives/supply-chainobjectives+30 5d
Power Agents 3.0.158 vscode neural-llm/power-claude 9,947 installs 5 days ago

obfuscated credential stealer

hidden-payload/runtimeobfuscator/js-obfuscator
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/supply-chainmetadata/package+23 5d
pwn 0.5.739 ruby 1,093,953 installs 5 days ago

Offensive security framework with exploit tools

reverse-shell/socket-execpackage/rubygems
objectives/command-and-controlwell-knownwell-known/toolmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectivesobjectives/evasionthird_party+8 5d

PowerShell dropper in main.go

policy/executionOR/Download
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/credential-accessobjectives/exfiltration+15 5d
67client-1.21.11.jar 5 days ago

Minecraft token theft, C2, obfuscation

gaming/minecraftcredential/token
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlmicro-behaviors/dataobjectives/exfiltrationobjectives/supply-chainobjectives 5d

Exfiltrates data to webhook.site

impersonation/depconfoob/endpoint
well-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadatametadata/binaryobjectives/anti-analysisobjectives/collectionobjectives/anti-staticobjectives/executionobjectives+29 6d

Credential theft and persistence

exploit/sql-injectionencoding/shell
well-knownwell-known/gamemicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-analysisobjectives/credential-accessobjectives/anti-staticobjectivesobjectives/command-and-control+4 6d
sigmaclient.net-…t-Fabric 1.21.jar and 9 siblings 6 days ago

Obfuscated loader, credential access, high-entropy blob

loader/classloaderreflection/class
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlmicro-behaviors/dataobjectives/exfiltrationobjectives/supply-chainobjectives 6d

Exfiltrates data to webhook.site

impersonation/depconfoob/endpoint
well-knownwell-known/Mcmicro-behaviorsmicro-behaviors/communicationsmetadatametadata/importobjectives/supply-chainobjectives/anti-analysisobjectives/discoveryobjectives/command-and-controlobjectives+7 6d
strapi-plugin-ccip-meeb 3.6.8 javascript and 5 siblings 6 days ago

Reverse shell in postinstall

reverse-shell/dev-tcp
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/Mcmetadatametadata/importobjectives/supply-chainobjectives/anti-analysisobjectives/discoveryobjectives/command-and-controlobjectives+7 6d
strapi-plugin-honey-meeb 3.6.8 javascript and 4 siblings 6 days ago

Reverse shell in postinstall

reverse-shell/ptyreverse-shell/dup
micro-behaviors/communicationsmicro-behaviorsobjectives/supply-chainmicro-behaviors/processobjectives/command-and-controlobjectivesobjectives/execution 6d
cirqueira.sh_i486.sh and 14 siblings 6 days ago

Downloads and executes remote payload

execution/pipedelivery/pipe
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/credential-accessobjectives/collectionobjectives/impactmicro-behaviors/communicationsobjectivesobjectives/evasionobjectives/exfiltration+7 6d
Audio Amperlifier 199.0.0 firefox audio-amperlifier 6 days ago

Wallet drainer with clipboard exfiltration

credential/clipboardextension/deception
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/collectionobjectives/credential-accessobjectives/impactmicro-behaviors/communicationsobjectivesobjectives/evasionobjectives/exfiltration+6 6d
Extra Volume Booster 177.0.1 firefox extravolumebooster 2 installs 6 days ago

Steals wallet seed phrases

credential/clipboardextension/deception
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectivesobjectives/collection+21 6d
opyt 0.1.0a6 python 6 days ago

Browser credential theft and exfiltration

file-targeting/identity-setphishing/lure
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/dual-usemetadatametadata/importobjectives/supply-chainmicro-behaviors/dataobjectives/anti-staticobjectives/command-and-controlobjectives+4 6d
swnwall 1.2.10 javascript and 2 siblings 6 days ago

Remote code execution loader

delivery/fetch-evaleval/require

TUESDAY

Tue Sep 15 · 78 catches · 2 waves · 17 singles
micro-behaviors/fsmicro-behaviorsobjectives/executionobjectives/supply-chainmicro-behaviors/communicationsmicro-behaviors/processobjectives/command-and-controlobjectives 6d
a3d774070107… and 7 siblings biggest campaign 6 days ago

Downloads and executes remote payloads

delivery/execute-download
micro-behaviors/hardwaremicro-behaviorsmetadata/binarymalware/librarymalwaremetadataobjectives/anti-staticobjectives/evasionobjectives/persistenceobjectives/command-and-controlobjectives+24 6d
547360056534… 6 days ago

Trojanized RMM with obfuscated droppers

control/rmmdelivery/stego
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/exfiltrationobjectivesobjectives/supply-chain+22 6d
Qui-Quo 2.3.2 firefox qui-quo 2,581 installs 6 days ago

Credential theft and obfuscation

trojanized/disthttp/report
objectives/executionobjectives/supply-chainobjectivesmetadata/packagemetadata 6d
tetotest 14.0.0 javascript and 2 siblings 6 days ago

Exfiltrates system info via Discord webhook

scripts/lifecyclebuild/behavioral
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmalware/appmetadata/buildmalwaremetadataobjectivesobjectives/evasionobjectives/supply-chainmetadata/package+23 6d
pwn 0.5.737 ruby 1,090,566 installs 6 days ago

Offensive security framework with evasion

package/rubygemssecurity-bypass/access-list
well-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/evasionobjectives/anti-analysisobjectivesobjectives/credential-accesswell-known+16 6d
Gooba-cracked-client.jar 6 days ago

Minecraft credential theft and C2

gaming/minecraftstealer/prefire-shard
micro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlobjectives/anti-analysisobjectives/discoveryobjectives/exfiltrationmicro-behaviors/processmicro-behaviors/osobjectives/executionobjectives/supply-chainobjectives+1 6d

Reverse shell and data exfiltration

recon-exfil/initcmd/injection
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemalwaremalware/appmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectives/evasionobjectives+21 6d
Secure My Pass 1.6.15 firefox secure-my-pass 832 installs 6 days ago

Steals ticket credentials and exfiltrates data

masquerade/traffic
micro-behaviorsmicro-behaviors/communicationsmetadata/packagemetadatamicro-behaviors/processobjectives/supply-chainobjectives 6d
csa-mfa 1.1.15 javascript 6 days ago

Preinstall exfiltrates system info

oast/envscripts/host-profile
micro-behaviorsmicro-behaviors/communicationsmetadata/packagemetadatamicro-behaviors/processobjectives/supply-chainobjectives 6d
csa-mfa 1.1.16 javascript 6 days ago

Preinstall exfiltrates system data

oast/envscripts/host-profile
well-known/toolwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectivesmetadatathird_party+23 7d
souleyez 5.0.6 python 7 days ago

Automated offensive security tooling

PHP/Generictoken/metadata
micro-behaviors/fsmicro-behaviorsobjectives/evasionobjectives/executionobjectives/command-and-controlobjectives/discoveryobjectives/lateral-movementmicro-behaviors/processobjectivesobjectives/credential-access 7d
vss-ntds-theft.cmd 7 days ago

NTDS credential theft script

dump/system
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/anti-analysisobjectives/command-and-controlobjectivesmalware/librarymalwareobjectives/supply-chain+11 7d
Cloudway-beta 3.0.0 chrome oncnlmgacmhmmeomdamfajmondebfbfa 7 installs 7 days ago

Proxy hijacking, credential theft

execution/evallibrary/framework
micro-behaviors/communicationsmetadatamicro-behaviorsmicro-behaviors/dataobjectives/anti-staticobjectives 7d
SOA August'2026.js and 2 siblings 7 days ago

Multi-layer obfuscated payload execution

eval/powershell-loaderformat/script
objectives/anti-staticobjectivesmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/command-and-controlobjectives/persistencemicro-behaviors/cryptomicro-behaviors/datathird_party+4 7d

Obfuscated pack with download-write dropper and IFEO persistence

CAPE/Obfuscar
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/credential-accessobjectives/anti-staticobjectives/lateral-movementobjectivesobjectives/exfiltration+17 7d
Costco Tools by RestockBotAlerts 1.6.2 firefox costco-tools-restockbotalerts 8 installs 7 days ago

Steals payment data, exfiltrates via ngrok

oob/endpointbrute-force/password
well-known/toolwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/privilege-escalationobjectives/credential-accessobjectives+20 7d
adpentest 1.5.0 python 7 days ago

Active Directory attack framework

dump/systemexploit/vulnerabilities
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/librarymetadatametadata/permissionobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectives/supply-chainobjectives+7 7d
Chrome Web Store chrome mhjgkeookbbpfgdfleaihlcbbelpfnik 7 days ago

Browser hijacker redirects searches

extensions/affiliate
well-known/toolswell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildobjectives/anti-analysisobjectives/anti-staticobjectives/credential-accessobjectivesmetadatathird_party+26 7d
reconpro 11.1.0 python 7 days ago

Typosquatting, credential theft, C2

OR/Downloadtoken/metadata
well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlobjectives/persistenceobjectivesobjectives/supply-chain+24 7d

postinstall hook, OSV-listed malicious

shell/configscripts/hook-file

MONDAY

Mon Sep 14 · 232 catches · 18 waves · 14 singles
micro-behaviorsmicro-behaviors/datametadatametadata/langmicro-behaviors/osmicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution 8d
HR Leave Schedul…026 (Updated).vbe and 6 siblings biggest campaign 8 days ago

Obfuscated VBScript with encoded payload

vbscript/loaderstring/junking
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/supply-chainobjectives/command-and-controlobjectivesobjectives/execution+10 7d
Lynx Theme Pro + (Icons) 5.3.6 vscode bastndev.lynx-theme 6,795 installs 7 days ago

Patches VS Code internals, elevates privileges

execution/stealth-spawn
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/importobjectives/discoveryobjectives/exfiltrationmicro-behaviors/processmicro-behaviors/osmetadata/packageobjectives/supply-chainobjectives+1 7d
fulfillment-cupr…auth-widget 3.7.1 javascript and 2 siblings 7 days ago

Exfiltrates system data via install hook

host-profile/install-contextpackage/direct-url
micro-behaviors/datamicro-behaviorsobjectives/command-and-controlmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution 7d
Purchase Order -…-2603113056899.js and 4 siblings 7 days ago

Obfuscated ActiveX malware

obfuscation/multi-layeractivex/com
well-knownwell-known/librarymicro-behaviors/fsmicro-behaviorsmicro-behaviors/osobjectivesobjectives/impact 7d
48-linux-nvme.js and 2 siblings 7 days ago

Destructive block device wipe

disk/device
micro-behaviors/datamicro-behaviorsmalwaremalware/librarymetadatametadata/importmicro-behaviors/processmicro-behaviors/fsmicro-behaviors/hardwareobjectivesobjectives/impact+1 7d
46-linux-urandom.js 7 days ago

Wipes disk with urandom

disk/device
micro-behaviors/fsmicro-behaviorsmicro-behaviors/processmicro-behaviors/hardwaremicro-behaviors/osobjectivesobjectives/impact 7d
29-linux-mbr.py 7 days ago

Destroys MBR via dd

disk/device
micro-behaviors/fsmicro-behaviorsobjectives/discoverymicro-behaviors/processmicro-behaviors/hardwaremicro-behaviors/osobjectivesobjectives/impact 7d

Hardcoded disk wipe command

disk/device
micro-behaviorsmicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectivesobjectives/impact 7d
12-linux-dd.go and 3 siblings 7 days ago

Destructive disk wipe via dd

disk/device
micro-behaviors/fsmicro-behaviorsobjectives/supply-chainmicro-behaviors/processmicro-behaviors/osobjectivesobjectives/impact 7d
40-linux-mbr.rs and 3 siblings 7 days ago

Destructive MBR wipe command

disk/device
micro-behaviors/fsmicro-behaviorsmicro-behaviors/osobjectivesobjectives/impact 7d
38-linux-nvme.rs and 3 siblings 7 days ago

Destructive block device wipe

disk/device
micro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/impactobjectives 7d
13-linux-openfile.go and 3 siblings 7 days ago

Destructive disk wipe code

disk/device
micro-behaviors/communicationsmicro-behaviorsobjectives/credential-accessmicro-behaviors/osobjectivesobjectives/exfiltration 7d
rust-runtime-cargo-token.tgz and 2 siblings 7 days ago

Exfiltrates Cargo registry token

credential/dev-file
micro-behaviors/communicationsmicro-behaviorsobjectives/credential-accessobjectives/supply-chainmicro-behaviors/osobjectivesobjectives/exfiltration 7d
rust-custom-cargo-token.tgz and 2 siblings 7 days ago

Exfiltrates Cargo registry token

credential/dev-file
objectives/exfiltrationmicro-behaviors/osmicro-behaviors/communicationsmicro-behaviorsobjectivesobjectives/supply-chain 7d
rust-proc_macro.tgz and 3 siblings 7 days ago

Proc macro exfiltrates environment secrets

build/behavioralrequest/credentials
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/credential-accessobjectives/supply-chainmicro-behaviors/osobjectivesobjectives/exfiltration 7d
rust-build-named-token.tgz and 2 siblings 7 days ago

Exfiltrates Cargo credentials

credential/dev-file
micro-behaviors/communicationsmicro-behaviorsobjectives/credential-accessmicro-behaviors/fsobjectivesobjectives/exfiltration 7d
rust-runtime-cre…ntial-files.crate and 2 siblings 7 days ago

Exfiltrates credentials via HTTP

credential/dev-file
metadatametadata/packagemicro-behaviors/osmicro-behaviors/communicationsmicro-behaviorsobjectivesobjectives/supply-chain 7d
python-pkg-__init__-py-False.tgz and 2 siblings 7 days ago

Exfiltrates environment variables via HTTP

credential-theft/envrequest/credentials
objectives/exfiltrationmicro-behaviors/osobjectivesobjectives/supply-chainmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/build 7d
rust-build-helper-module.crate and 3 siblings 7 days ago

Exfiltrates environment variables via HTTP

request/credentialsbuild/behavioral
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/exfiltrationobjectives/credential-accessmicro-behaviors/dataobjectives/persistenceobjectivesobjectives/impact+6 8d
Claude Code Native 6.0.0 jetbrains dev.lain.claude-code-for-jetbrains 8,306 installs 8 days ago

Credential stealer patterns embedded

wipe/user-datalogin/multi-technique
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/lateral-movementobjectives/command-and-controlobjectives/evasionmalware/toolsmalwareobjectives/credential-accessobjectives+12 8d
adpentest 1.3.1 python 8 days ago

AD attack framework with credential theft

dump/systemoffensive/mimikatz
micro-behaviors/fsmicro-behaviorsmetadatametadata/importobjectives/command-and-controlobjectives/supply-chainobjectives/executionobjectives/impactobjectives/evasionobjectivesobjectives/persistence+5 8d
main.tar.gz javascript 8 days ago

Dropper with persistence, hidden VBS, remote payload

file/scriptstartup/shortcut
micro-behaviors/datamicro-behaviorsmicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectives/anti-staticobjectivesobjectives/execution 8d
info_New_Order_7….shtml(~99 KB).JS and 3 siblings 8 days ago

Obfuscated JS executes commands, writes files

obfuscation/multi-layeractivex/com
micro-behaviors/datamicro-behaviorsobjectives/command-and-controlmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution 8d
ADNOC Contract info -specs.JS and 2 siblings 8 days ago

Obfuscated ActiveX file write

obfuscation/multi-layeractivex/com
micro-behaviors/processmicro-behaviorsobjectives/command-and-controlmicro-behaviors/fsmicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/osmetadataobjectives/anti-staticobjectivesthird_party 8d

Contains PHP webshell and obfuscation

PHP/Genericcode-metrics/identifiers
objectives/command-and-controlobjectiveswell-known/toolwell-knownmicro-behaviors/cryptomicro-behaviorsmetadata/buildmetadataobjectives/evasionobjectives/credential-accessthird_party+16 8d

Impacket offensive security toolkit

OR/DownloadMulti/Ntlmrelayx
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmalwaremalware/dual-usemetadatametadata/buildobjectives/discoveryobjectivesobjectives/credential-accessthird_party+11 8d

Embedded credential stealer indicators

EXE/Discordurldiscord/token
micro-behaviors/datamicro-behaviorsobjectives/executionobjectives/command-and-controlmicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osmetadataobjectives/anti-staticobjectives 8d
JD261393 OVPB26Q001011.pdf.js and 3 siblings 8 days ago

Obfuscated PowerShell dropper with evasion

obfuscation/multi-layerobfuscation/syntax
micro-behaviors/communicationsmicro-behaviorsmalware/librarymalwaremicro-behaviors/datamicro-behaviors/fsmicro-behaviors/osmicro-behaviors/uiobjectives/evasionobjectivesobjectives/credential-access+5 8d
Next-Cart Store to WooCommerce Migration 3.9.10 wordpress nextcart-woocommerce-migration 21,966 installs 8 days ago

Unauthenticated remote code execution

theft/filesecurity-bypass/tls
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadatamicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/osobjectivesobjectives/credential-access+5 8d
AI Appointment Setter for Instagram DMs 2.6.34 chrome nkfhgjjkimnaamoenpjoimklpehfpheh 111 installs 8 days ago

Automated Instagram DM spam tool

browser/extension
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadatamicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectivesobjectives/command-and-controlobjectives/exfiltration 8d
n8n-nodes-sysdiag 1.0.2 javascript and 3 siblings 8 days ago

Exfiltrates environment variables to hardcoded IP

credential/multi-sourceinfrastructure/ip-port
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/supply-chainobjectives/credential-accessobjectives/anti-staticobjectivesobjectives/execution+13 8d

Obfuscated payload in eslint config

eval/loadereval/dynamic
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories