Downloads and executes remote binary
Fallout, Sep 14 – Sep 20
What we caught this week while monitoring over 155,936,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 20 · 136 catches · 1 wave · 15 singlesThread hooking, PEB spoofing, self-deletion
Shellcode injection and AV evasion
Shellcode injection and AMSI bypass
Typosquatting wallet key exfiltration
PowerShell Empire C2 framework
Obfuscated PowerShell execution
Uninstalls other extensions, steals cookies
Exfiltrates cookies, full browser control
Installs MITM CA, intercepts traffic
Exfiltrates secrets via Telegram
Exfiltrates LinkedIn cookies to remote server
SATURDAY
Sat Sep 19 · 125 catches · 3 waves · 17 singlesC2 framework with RAT capabilities
Contains actual malware samples
Embedded PHP webshell payload
Embedded PHP webshell payload
Credential exfiltration and remote code execution
installs MITM CA, intercepts AI traffic
Credential theft, account manipulation
Steals auth tokens, automates financial actions
Encoded PowerShell, C2, new package
Remote command execution, cookie theft
Remote command execution, cookie theft
Exfiltrates data to remote server
C2 framework with RAT capabilities
C2 framework with RAT capabilities
Fake VPN extension farm
FRIDAY
Fri Sep 18 · 159 catches · 1 wave · 18 singlesPost-exploitation C2 framework
Mirai botnet malware source
Mirai botnet malware source
Credential harvesting and social media automation
CTF webshells and exploits included
Steals cookies, exfiltrates ticket data
Credential theft, obfuscation, C2, persistence
Steals wallet seed phrases
Offensive security framework with exploit tools
MITM root CA generation
Offensive security framework with agent skills
Exfiltrates cookies, credentials, and user data
Exfiltrates system data via preinstall
OSV-listed malicious cdnshell loader
XHR hooking, C2, obfuscation
Offensive exploit toolkit
Steals credentials, exfiltrates via ngrok
THURSDAY
Thu Sep 17 · 131 catches · 4 waves · 22 singlesC2, credential theft, obfuscation
Post-exploitation framework with obfuscation
Credential theft and persistence
Embedded credentials and lateral movement
Exfiltrates LinkedIn session cookies
Obfuscated ActiveX dropper
Remote config, hidden iframe, header stripping
Steals wallet seed phrases
Obfuscated WSH dropper with ActiveX
Obfuscated dropper with ActiveX and file writes
Steals auth tokens from localStorage
Obfuscated credential theft and C2
Obfuscated VBScript, registry access, execution
obfuscated credential stealer dependency
Malicious payload in sample file
Exfiltrates Google OAuth tokens to raw IP
curl-to-bash, hidden payload, new package
Credential harvesting and obfuscation
obfuscated credential stealer with persistence
WEDNESDAY
Wed Sep 16 · 135 catches · 5 waves · 21 singlesCracked loader, obfuscation, C2, vault
Targets AI agent configs, exfiltrates credentials
Steals credentials, obfuscated exfiltration
Exfiltrates deployment token to webhook
Java deserialization exploit tool
obfuscated credential stealer
Steals OnlyFans session cookies
Credential harvesting and obfuscation
Exfiltrates system data to C2
Steals credentials, automates financial actions
obfuscated credential stealer
Offensive security framework with exploit tools
PowerShell dropper in main.go
Credential theft and persistence
Obfuscated loader, credential access, high-entropy blob
Reverse shell in postinstall
Reverse shell in postinstall
Downloads and executes remote payload
Wallet drainer with clipboard exfiltration
Steals wallet seed phrases
Browser credential theft and exfiltration
Remote code execution loader
TUESDAY
Tue Sep 15 · 78 catches · 2 waves · 17 singlesDownloads and executes remote payloads
Exfiltrates system info via Discord webhook
Offensive security framework with evasion
Reverse shell and data exfiltration
Steals ticket credentials and exfiltrates data
Proxy hijacking, credential theft
Multi-layer obfuscated payload execution
Obfuscated pack with download-write dropper and IFEO persistence
Steals payment data, exfiltrates via ngrok
Browser hijacker redirects searches
postinstall hook, OSV-listed malicious
MONDAY
Mon Sep 14 · 232 catches · 18 waves · 14 singlesObfuscated VBScript with encoded payload
Patches VS Code internals, elevates privileges
Exfiltrates system data via install hook
Obfuscated ActiveX malware
Proc macro exfiltrates environment secrets
Exfiltrates credentials via HTTP
Exfiltrates environment variables via HTTP
Exfiltrates environment variables via HTTP
Credential stealer patterns embedded
Dropper with persistence, hidden VBS, remote payload
Obfuscated JS executes commands, writes files
Obfuscated ActiveX file write
Contains PHP webshell and obfuscation
Impacket offensive security toolkit
Malformed PE, high entropy, evasion
Embedded credential stealer indicators
Obfuscated PowerShell dropper with evasion
Unauthenticated remote code execution
Automated Instagram DM spam tool
Exfiltrates environment variables to hardcoded IP
Obfuscated payload in eslint config