Fallout, since Sep 21

What we caught this week while monitoring over 185,582,225 artifacts across 59 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

SUNDAY

Sun Sep 27 · 107 catches · 2 waves · 25 singles
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 1d
@chikawa222224/t…24 2026.9.23-1-31 javascript and 6 siblings biggest campaign 1 day ago

Bundled high-entropy binary payload

binary/dos
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/collectionobjectives/command-and-controlobjectivesobjectives/execution+14 1d

Hidden PowerShell, VBS, and registry persistence

execution/wshvbscript/interpreter
well-knownwell-known/Mcmicro-behaviors/cryptomicro-behaviorsmetadatametadata/binaryobjectives/command-and-controlobjectives/discoveryobjectives/anti-staticobjectivesobjectives/persistence+24 1d

Active Directory attack toolkit

account/createpayload/encoded
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadatamicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processmetadata/package 1d
meka 0.66.0-1 arch 1 day ago

Dependency explicitly classified hostile

micro-behaviors/datamicro-behaviorsobjectives/executionobjectives/anti-staticobjectives 1d
stage2b.js ✓ 1 day ago

obfuscated multi-stage loader

eval/loader
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/persistenceobjectives/anti-analysisobjectives/credential-accessobjectives/command-and-controlobjectives/supply-chainobjectives+11 1d
Taint Bomb auto Java Obfuscator 0.8.0 jetbrains io.namaek2.plugins 1,305 installs 1 day ago

Trojanized obfuscator with process execution

app/ai-agent-toolswebshell/client
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/credential-accessmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/evasionobjectives/exfiltration+5 1d
Tr Wale 16.2.9 firefox tr-wale 1 day ago

Clipboard exfiltration to hidden IP

credential/clipboardextension/deception
objectives/anti-staticobjectivesmicro-behaviors/communicationsmicro-behaviorsmalwaremalware/appmetadatametadata/binaryobjectives/command-and-controlobjectives/persistenceobjectives/execution+21 1d

Hostile dependency embedded

well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/lateral-movementmicro-behaviors/dataobjectives/command-and-controlobjectivesobjectives/execution+3 1d

Exploit code with reverse shell

exploit/http-command-injectionreverse-shell/dev-tcp
objectives/anti-staticwell-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/evasionobjectivesobjectives/command-and-controlthird-party+19 1d

Embedded base64 shellcode in definitions

Encoded/Codewebshell/wordpress
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/command-and-controlobjectives/credential-access+10 1d
Grim Client V5.jar ✓ 1 day ago

Minecraft credential stealer

dropper/staged-loadergaming/minecraft
micro-behaviors/osmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectives/impactobjectivesobjectives/persistenceobjectives/execution+3 1d

WMI hidden process, obfuscated payload

startup/folderexecution/wmi
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/persistenceobjectives/command-and-controlobjectivesobjectives/execution+20 1d

Mythic C2 fields, hidden persistence

execution/wsh
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/persistenceobjectives/command-and-controlobjectivesobjectives/execution+20 1d

RAT features, C2, persistence, obfuscation

execution/wsh
objectives/credential-accessobjectivesmalware/appmetadata/buildmalwaremetadataobjectives/anti-staticobjectives/collectionmicro-behaviors/communicationsmicro-behaviorsmicro-behaviors/process+28 1d
9router-imagefix 0.5.123 javascript and 3 siblings 1 day ago

Installs MITM root CA, intercepts traffic

create/hiddenrequest/credentials
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/buildmicro-behaviors/osmicro-behaviors/fsmetadata/package 1d
vouch 0.1.8-1 arch 1 day ago

Browser automation for credential theft

well-known/libwell-knownmicro-behaviorsmicro-behaviors/communicationsmetadata/binarymetadataobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/evasionmicro-behaviors/process+10 1d

CS2 cheat with hooks

injection/harmony-mod
well-knownwell-known/librarymicro-behaviorsmicro-behaviors/browser-extensionmetadata/importmetadataobjectives/anti-staticobjectives/impactmicro-behaviors/dataobjectives/supply-chainobjectives+9 1d

Patches IDE main.js, injects code

app/replace
micro-behaviorsmicro-behaviors/cryptometadata/buildmetadataobjectives/executionmicro-behaviors/datamicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osobjectives/anti-staticobjectives+3 1d
aseity 0.1.0 python ✓ 1 day ago

obfuscated exec payload in setup

payload/encodedeval/scripting
well-knownwell-known/libmicro-behaviorsmicro-behaviors/browser-extensionmetadata/importmetadataobjectives/anti-staticobjectives/impactmicro-behaviors/dataobjectives/supply-chainobjectives+9 1d

Patches IDE main.js, injects code

app/replace
well-known/libwell-knownmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectives/supply-chainobjectives+15 2d
Xpay Wallet 1.0.0 chrome aaidlfhejdcamjmijpddcojffbidpfek 18 installs 2 days ago

DevTools blocked, raw IP API

extensions/control
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/command-and-controlmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/impact+4 2d
Urban VPN — Рабочий VPN в России 2.4.1 chrome bkdachncbdfpobhecdjhhnheokcilnba 24 installs 2 days ago

Routes all traffic to attacker proxy

degrade/extension
micro-behaviorsmicro-behaviors/cryptometadatametadata/packageobjectives/executionobjectives/impactobjectives/persistencemicro-behaviors/dataobjectives/command-and-controlobjectives/anti-staticobjectives+4 2d
MT Eagle Asia 11…n Information.rar and 2 siblings ✓ 2 days ago

Obfuscated PowerShell malware dropper

obfuscation/multi-layerstaging/encrypted
well-known/librarywell-knownmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/impactobjectives/credential-accessobjectives/command-and-controlobjectives+19 2d
QNet Wallet 2.1.3 chrome pahnggomgmhhjjncgfnmmofmplfhkncg 51 installs 2 days ago

Wallet drainer with fake balances

blockchain/solanawallet/desktop
micro-behaviors/communicationsmicro-behaviorsmetadata/importmalwaremalware/appmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesobjectives/supply-chain+21 2d

Hidden process execution and obfuscation

destroy/file-deletionrecon-exfil/callback
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/command-and-controlobjectives/anti-staticobjectivesobjectives/evasionmicro-behaviors/process+19 2d
mcpywrap 0.3.4 python 2 days ago

Process injection payload included

payload/loaderinjection/native
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/discoveryobjectives/impactobjectives/anti-analysisobjectives/executionobjectives/command-and-controlobjectives+11 2d

Remote command execution agent

tasking/command-httptasking/chunked
micro-behaviors/datamicro-behaviorsmetadata/importmetadatamicro-behaviors/processmicro-behaviors/os 2d
bao-servo-constellation 0.5.18 rust 675 installs 2 days ago

Typosquatted malicious dependency

SATURDAY

Sat Sep 26 · 381 catches · 7 waves · 22 singles
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 2d
@chikawa222224/t…24 2026.9.23-1-25 javascript and 9 siblings biggest campaign 2 days ago

Typosquatting, high release velocity, binary payload

binary/dos
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/impactobjectives/anti-analysisobjectives/anti-staticobjectives/persistenceobjectives/command-and-controlobjectivesobjectives/supply-chain+11 2d
ChainlessChain IDE Bridge 0.4.138 jetbrains com.chainlesschain.ide 2,657 installs 2 days ago

Encoded PowerShell backdoor, C2, ransomware strings

app/ide-extensiondelivery/download
micro-behaviors/communicationsmicro-behaviorsmetadata/importmalware/librarymalwaremetadataobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/impactmicro-behaviors/ui+14 2d

Trojanized dependency rewrites host code

delivery/fetch-evalmanipulation/social
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/collectionobjectives/executionmicro-behaviors/fsmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 2d
Backdoor.ASP.Ace.ar 2 days ago

ASP web shell backdoor

webshell/requestwebshell/file-manager
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/executionmicro-behaviors/fsmicro-behaviors/datamicro-behaviors/processmicro-behaviors/osobjectives/command-and-controlobjectives 2d
Backdoor.ASP.Ace.bg 2 days ago

ASP webshell backdoor

webshell/requestwebshell/file-manager
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/langobjectives/anti-staticobjectives/executionmicro-behaviors/fsmicro-behaviors/datamicro-behaviors/processobjectives/command-and-controlobjectives+1 2d
Backdoor.ASP.Ace.y 2 days ago

ASP web shell backdoor

webshell/file-managerwebshell/obf-dispatch
micro-behaviors/osmicro-behaviors/processmicro-behaviorsmicro-behaviors/communicationsobjectivesobjectives/lateral-movement 2d
Virus.MSWord.Melissa.d and 2 siblings 2 days ago

Melissa virus macro

worm/emailsend/outlook
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 2d

High-entropy binary, rapid release churn

binary/dos
well-known/librarywell-knownmicro-behaviors/datamicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesthird-party+21 2d

Collection of RCE exploits

webshell/execIocs/Dec21
well-known/librarywell-knownmicro-behaviors/datamicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesthird-party+21 2d

Collection of RCE exploit scripts

webshell/execIocs/Dec21
micro-behaviors/browser-extensionmicro-behaviorsmalware/appmalwaremetadatametadata/packageobjectives/collectionobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/evasion+11 2d

Academic dishonesty and anti-detection evasion

anti-bot/automation
objectivesobjectives/discoverymicro-behaviors/fsmicro-behaviorsobjectives/evasionmicro-behaviors/osmicro-behaviors/processmicro-behaviors/timethird_party 2d
07d91c722595… and 6 siblings 2 days ago

Keylogger exfiltrates via email

PWSH/Poshkeylogger
micro-behaviorsmicro-behaviors/dylibobjectives/anti-staticmicro-behaviors/memmetadataobjectivesobjectives/evasionmicro-behaviors/process 2d
b9985b10c43c… and 5 siblings 2 days ago

Shellcode execution via VirtualAlloc

injection/runtime
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmalware/appmalwaremetadataobjectives/command-and-controlobjectives/credential-accessobjectivesobjectives/impactmicro-behaviors/ui+21 2d

typosquatted Docker CLI module

manipulation/social
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/evasionmicro-behaviors/fsmicro-behaviors/datamicro-behaviors/processmetadata/packageobjectives/command-and-controlobjectives 2d

Remote code execution via exec

delivery/fetch-exec
micro-behaviors/datamicro-behaviorsmetadatametadata/binaryobjectives/collectionmicro-behaviors/osmicro-behaviors/fsmicro-behaviors/processobjectives/anti-staticobjectivesobjectives/execution+2 2d
VirusShare_24c8c…01025d2d129fee9d0 and 2 siblings 2 days ago

Obfuscated PowerShell malware

compile/runtimestring/concat
micro-behaviorsmicro-behaviors/datamicro-behaviors/processobjectives/anti-staticobjectives/executionobjectives 2d
VirusShare_af761…80a16585b0fb00180 and 2 siblings 2 days ago

obfuscated VBScript execution

vbscript/interpreterstring/fragmentation
micro-behaviorsmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processmicro-behaviors/timemicro-behaviors/uithird_party 2d
VirusShare_9cb82…74a18ac509db920b3 and 2 siblings 2 days ago

Keylogger exfiltrates via email

PWSH/Poshkeylogger
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/impactmicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/processobjectivesobjectives/collectionobjectives/supply-chain+3 2d
WindAft 0.0.1 chrome lfgjmdjciokgldnaleebdmlhhlldilib 6 installs 2 days ago

Search hijack, data exfiltration

activity/browserextensions/affiliate
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/supply-chainobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/credential-access+6 2d
Meta Cookie Manager 3.3.5 chrome fabgbmbhbgjedkjgljabjojcanaidmoh 119 installs 2 days ago

Cookie theft and credential access

browser/extension
well-knownwell-known/libmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/anti-analysisobjectives/executionobjectivesobjectives/discovery+14 2d
Subzillo 1.0.17 firefox subzillo 1 installs 2 days ago

Steals cookies and tokens

host/geoexploit/chain
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/persistenceobjectives/anti-staticobjectivesobjectives/evasionwell-knownwell-known/dual-usemicro-behaviors/process+7 2d
y linux ✓ 2 days ago

Reverse shell with evasion

process/nametunnel/gsocket
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/persistenceobjectives/anti-staticobjectivesobjectives/evasionwell-knownwell-known/dual-usemicro-behaviors/process+6 2d
x linux ✓ 2 days ago

Installs hidden reverse shell

process/nametunnel/gsocket
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/anti-staticobjectives/command-and-controlobjectives/executionobjectives/supply-chainobjectives+27 2d

Persists autonomous agent, remote C2

extensions/vscode
micro-behaviors/fsmicro-behaviorsmetadata/importmalwaremalware/libmetadataobjectives/impactobjectives/supply-chainmicro-behaviors/dataobjectives/anti-staticobjectives+4 3d
lshlhom 1.0.0 python 3 days ago

Obfuscated payload execution

eval/scriptingpayload/code-in-data
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticmicro-behaviors/processmicro-behaviors/datametadata/packageobjectives/command-and-controlobjectives 3d
solana_util 0.1.3 rust ✓ 3 days ago

Downloads and executes remote payloads

execution/stego-loaderexecution/pipe
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadatamicro-behaviors/processmetadata/packageobjectivesobjectives/command-and-control 3d
solana_util 0.1.2 rust and 2 siblings ✓ 3 days ago

curl-to-shell, encoded PowerShell, typosquat

execution/pipe
micro-behaviors/processmicro-behaviorsmetadata/buildmalwaremalware/libmetadataobjectives/supply-chainobjectives/command-and-controlobjectives/credential-accessobjectives/anti-staticobjectives+10 3d
opencomb 0.19.0 python 3 days ago

obfuscated exec, credential harvesting

payload/encodedeval/scripting
objectives/command-and-controlmetadatametadata/archobjectives/anti-staticobjectives/impactobjectiveswell-known/toolwell-knownmicro-behaviors/processmicro-behaviorsobjectives/evasion+30 3d
metasploit-payloads 1.0.21 gem 5,024,427 installs 3 days ago

Metasploit offensive payloads included

injection/dlloffensive/metasploit

FRIDAY

Fri Sep 25 · 2737 catches · 8 waves · 26 singles
objectivesobjectives/impact 4d
Virus.Multi.Ghostball.2351.b and 2509 siblings biggest campaign 4 days ago

File infector virus behavior

binary/dos
micro-behaviorsmicro-behaviors/communicationsmetadata/buildmalwaremalware/appmetadataobjectives/command-and-controlobjectives/anti-analysisobjectives/anti-staticobjectives/persistenceobjectives+14 3d

installs persistence, evades AV, obfuscated payload

system/supervised
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/command-and-controlobjectives/anti-staticobjectives/impactobjectiveswell-knownwell-known/unwantedmicro-behaviors/ui+15 3d
ConveyThis AI Translation for WordPress 270.8 wordpress conveythis-translate 1,000 installs 3 days ago

Malicious code in SweetAlert2

manipulation/browserunwanted/sweetalert2-protestware
well-known/appwell-knownmicro-behaviors/osmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectives+29 3d

Malicious MCP agent with C2 and evasion

staging/tiny-pe
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticmicro-behaviors/uimicro-behaviors/cryptomicro-behaviors/datamicro-behaviors/hardwaremicro-behaviors/processobjectivesobjectives/credential-access 3d

Phishing page steals wallet seed phrases

wallet/mnemonic
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 3d

High-entropy binary, rapid releases, typosquatting

binary/dos
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectivesobjectives/discovery+23 3d
WLEMMatchMaker 1.0.0.8 chrome fanpkchplmlfccjaicocclkfhmplhfbp 55 installs 3 days ago

LinkedIn automation and data exfiltration

host/geo
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/datamicro-behaviors/fsobjectives/executionobjectives 3d

DNS rebinding path traversal exploit

exploit/access-controlnetwork-service/service-api-abuse
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectives/privilege-escalationobjectives+24 3d

Offensive security tool with evasion

elevation-control/sudoindicator-removal/logs
objectives/command-and-controlwell-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/evasion+26 3d
pwn 0.5.749 ruby 1,135,168 installs 3 days ago

Offensive security tool with exploit capabilities

security-bypass/access-listllm/override
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/credential-accessobjectives/supply-chainobjectives/command-and-controlobjectivesobjectives/execution+19 3d

Credential harvesting and persistence

execution/filelesscredential-theft/registry
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/credential-accessmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/evasionobjectives/exfiltration+6 3d
Trus- EVM&Web3 WALLEТ 199.0.0 firefox y3h8s4j5w6g2u9m 1 installs 3 days ago

Steals wallet seed phrases

credential/clipboardextension/deception
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/evasionobjectives/exfiltration+7 3d
TRON 1111.0.3 firefox f5t1b6v9c2l7r4d 2 installs 3 days ago

Clipboard exfiltration, obfuscated C2

credential/clipboardextension/deception
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesmalware/librarymalwareobjectives/supply-chain+15 3d

Typosquatting, evasion, preinstall hook

manipulation/sociallibrary/fork-branding
well-known/librarywell-knownmicro-behaviors/osmicro-behaviorsmetadata/buildmetadataobjectives/executionobjectives/credential-accessobjectives/anti-staticobjectives/command-and-controlobjectives+17 3d

Contains active exploit and reverse shell code

reverse-shell/dev-tcpreverse-shell/socket-exec
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/evasionmicro-behaviors/datamicro-behaviors/cryptoobjectivesobjectives/credential-accessobjectives/supply-chain+4 3d
catzconnect 1.0.4 rust 132 installs 3 days ago

CI exfiltrates secrets to C2

trojanized/build-pipelineapi-harvest/ci-oidc
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/impactobjectives/anti-analysisobjectives/anti-staticobjectives/persistenceobjectives/command-and-controlobjectivesobjectives/supply-chain+11 3d
ChainlessChain IDE Bridge 0.4.137 jetbrains com.chainlesschain.ide 2,641 installs 3 days ago

Encoded PowerShell, C2, ransomware strings

app/ide-extensiondelivery/download
well-known/appwell-knownmicro-behaviors/processmicro-behaviorsmetadatametadata/buildobjectives/credential-accessobjectives/discoveryobjectives/anti-staticobjectivesobjectives/persistence+19 3d

Obfuscated .pth payload executes code

login/python-pthcode-metrics/structure
well-known/appwell-knownmicro-behaviors/processmicro-behaviorsmetadata/buildmetadataobjectives/credential-accessobjectives/discoveryobjectives/anti-staticobjectivesobjectives/persistence+19 3d

Obfuscated .pth auto-executes payload

login/python-pthcode-metrics/structure
well-known/appwell-knownmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/command-and-controlobjectives/impactobjectives/anti-staticobjectives/credential-accessobjectives+20 3d
XoraPass Zero-Knowledge Vault 1.2.2 firefox xorapass-zero-knowledge-vault 1 installs 3 days ago

Credential capture and exfiltration

credit-card/keywordcredit-card/form-field
objectives/anti-staticwell-known/toolwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-analysisobjectivesobjectives/persistencethird-party+35 4d

Metasploit framework with offensive payloads

exploit/genericaccount/create
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectivesobjectives/exfiltration+25 4d
Blasts & Deals 12.0.26 chrome kogelnejjmbpageloicidjipnaffnkak 15 installs 4 days ago

Credential harvesting and bulk email abuse

remote-command/extensionhttp/report
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osobjectives/executionobjectives+1 4d
github.com/ikkis…1602-4f00182efc02 go and 3 siblings 4 days ago

Java deserialization exploit tool

exploit/deserialization
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/osmicro-behaviors/fsobjectives/executionobjectives+2 4d
github.com/mbech…/ysoserial v0.0.3 go and 2 siblings 4 days ago

ysoserial exploit tool

exploit/deserialization
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/command-and-controlmicro-behaviors/processmicro-behaviors/datamicro-behaviors/fsmetadata/packageobjectives/executionobjectives 4d
github.com/mbech…/ysoserial v0.0.1 go and 3 siblings 4 days ago

ysoserial exploit tool

exploit/deserialization
micro-behaviors/communicationsmicro-behaviorsmetadata/importmalwaremalware/librarymetadataobjectives/anti-staticmicro-behaviors/datamicro-behaviors/fsobjectives/executionobjectives+6 4d
abyss-mitm 1.0.1 rust 46 installs 4 days ago

TLS interception and MITM

exploit/http-desync
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactobjectivesmalwaremalware/unwantedmicro-behaviors/ui+13 4d

Malicious SweetAlert2 payload

unwanted/sweetalert2-protestwaremanipulation/browser
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadatamicro-behaviors/datamicro-behaviors/osmetadata/packagemetadata/importobjectivesobjectives/exfiltrationobjectives/supply-chain 4d

Exfiltrates environment variables on install

stealer/system-infodropper/setup
micro-behaviorsmicro-behaviors/osobjectives/credential-accessobjectives 4d
hive_theft.bat 4 days ago

Credential and AD database theft

dump/systemwindows-registry/hive
well-knownwell-known/libmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectivesobjectives/supply-chain+10 4d
Foxora 1.0.4 chrome lkodiiecfihbdgebffbcdjokmnabbcfi 58 installs 4 days ago

Remote code execution, credential theft

remote-command/extensionextensions/backdoor
objectivesobjectives/command-and-control 4d
Flooder.IRC.Owned and 5 siblings 4 days ago

mIRC botnet dropper

irc/client
micro-behaviorsmicro-behaviors/fsmetadataobjectivesobjectives/impact 4d
Virus.BAT.Silly.i and 3 siblings 4 days ago

Self-replicating batch virus

infect/script
metadataobjectivesobjectives/impact 4d
Virus.BAT.Copier and 4 siblings 4 days ago

Self-replicating batch virus

infect/script
well-known/librarywell-knownmicro-behaviorsmicro-behaviors/communicationsmetadata/buildmetadataobjectives/command-and-controlobjectives/evasionobjectives/anti-staticobjectives/persistenceobjectives+11 4d

Malicious VS Code extension payload

system/supervised

THURSDAY

Thu Sep 24 · 278 catches · 6 waves · 23 singles
objectivesobjectives/command-and-control 5d
IRC-Worm.IRC.Warez and 53 siblings biggest campaign 5 days ago

mIRC worm propagates via DCC

irc/client
micro-behaviors/browser-extensionmicro-behaviorsmalwaremalware/librarymetadatametadata/packageobjectives/credential-accessobjectives/anti-staticobjectives/lateral-movementobjectivesobjectives/exfiltration+16 4d
Costco Tools by RestockBotAlerts 1.6.9 firefox costco-tools-restockbotalerts 9 installs 4 days ago

Credential theft, obfuscation, weak passwords

oob/endpointbrute-force/password
micro-behaviorsmicro-behaviors/cryptoobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processmetadata/packageobjectivesobjectives/impactmetadatametadata/binary+2 4d

High-entropy binary, rapid release churn

binary/dos
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/discoverymicro-behaviors/datamicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/exfiltrationobjectives+1 4d

Exfiltrates system info to webhook

oob/endpointoob/system-profile
objectives/command-and-controlwell-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/credential-accessobjectivesobjectives/lateral-movementthird_party+22 4d

Embedded credential theft rules

EXE/Discordurldelivery/wmi
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/librarymetadatametadata/buildobjectives/anti-staticobjectives/supply-chainobjectives/command-and-controlobjectivesobjectives/execution+10 4d

Malicious font file executes code

trigger/idedelivery/fetch-eval
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/discoverymicro-behaviors/osmicro-behaviors/datametadata/importobjectives/exfiltrationobjectives 4d

Exfiltrates system info to webhook

oob/endpointoob/callback
well-known/Mcwell-knownmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/credential-accessobjectives/discoveryobjectives/command-and-controlobjectives+26 4d

Contains reverse shells and exploits

delivery/execute-downloadreverse-shell/socket-exec
objectives/command-and-controlobjectiveswell-known/Mcmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/credential-accesswell-knownthird-party+27 4d

Contains reverse shells and exploits

Credaccess/Iisrat/powershell-empire
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectives/credential-accessobjectivesobjectives/evasion+19 4d
Eagleanalytix Ticket Data Extension 4.1.50 chrome oegjgjmenakafanmngbflcfdlhdiedbb 168 installs 4 days ago

CAPTCHA solver, cookie exfiltration

anti-bot/captcha-solvingbrowser/extension
micro-behaviors/cryptomicro-behaviorsmetadata/binarymalwaremalware/librarymetadataobjectives/anti-staticobjectives/evasionobjectives/persistenceobjectives/command-and-controlobjectives+22 4d

AgentTesla infostealer payload detected

backdoor/capturestaging/memory
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/processmicro-behaviors/osobjectivesobjectives/command-and-control 4d
wendows.ini 4 days ago

mIRC bot with DoS tools

irc/client
well-known/libwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/supply-chainobjectives+14 4d

Obfuscated code execution in provider

hidden-payload/runtimehidden-payload/archive
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/supply-chainobjectives+14 4d

Obfuscated payload execution in provider

hidden-payload/runtimehidden-payload/archive
well-known/libwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/binaryobjectives/command-and-controlobjectives/anti-staticobjectives/credential-accessobjectives/supply-chainobjectives+14 4d

Obfuscated payload execution in provider

hidden-payload/runtimehidden-payload/archive
micro-behaviors/cryptomicro-behaviorsmetadatametadata/binaryobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectives/impactmicro-behaviors/fsobjectives/supply-chainobjectives+5 4d

Obfuscated payload execution

hidden-payload/runtimehidden-payload/archive
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/discoveryobjectives/supply-chainmicro-behaviors/cryptoobjectives/command-and-controlobjectivesobjectives/evasion+8 4d

Slack C2, self-delete, obfuscation

file/scriptcontrol/slack
well-knownwell-known/appmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/executionobjectives/supply-chainobjectives/command-and-controlobjectives+24 4d

Windows persistence and credential targeting

dropper/node-bootstrapscripts/dynamic-install
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/command-and-control+7 4d
Barie AI 1.0.5 chrome dgiolgbbhmehjfpjclcmalojbpfpmbak 30 installs 4 days ago

CDP control, input blocking, all-URLs

remote-command/extension
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmalwaremalware/toolmetadataobjectivesobjectives/evasionobjectives/supply-chainmetadata/package+8 4d
github.com/Kalei…5737-64ba8a8c0ffd go and 2 siblings 4 days ago

Obfuscated PowerShell dropper in main.go

policy/executionapp/package
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/credential-accessobjectives/anti-staticobjectives/lateral-movementobjectivesobjectives/exfiltration+16 4d
Costco Tools by RestockBotAlerts 1.6.8 firefox costco-tools-restockbotalerts 9 installs 4 days ago

Credential theft, obfuscation, weak passwords

oob/endpointbrute-force/password
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/credential-accessmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/evasionobjectives/exfiltration+5 4d
RABB- EVM&Web3 WALLEТ 177.0.1 firefox k7mnp9qr2stuv3w 11 installs 4 days ago

Exfiltrates wallet seed phrases

credential/clipboardextension/deception
micro-behaviors/datamicro-behaviorsobjectives/anti-analysisobjectives/command-and-controlobjectives/impactmicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectives/anti-staticobjectivesobjectives/execution+1 4d
aa4fca3b-5e1e-42…a261039f18.pdf.JS and 2 siblings ✓ 4 days ago

obfuscated ActiveX file execution

obfuscation/multi-layeractivex/com
objectives/command-and-controlwell-knownwell-known/librarymicro-behaviors/datamicro-behaviorsmetadata/importmetadataobjectives/credential-accessobjectivesobjectives/executionobjectives/lateral-movement+18 4d
rcekit 2.45.3 python 4 days ago

Embedded malicious payload corpus

eval/remoteexploit/container
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/importmetadataobjectives/credential-accessobjectives/command-and-controlobjectives/executionobjectivesobjectives/exfiltration+16 4d
Alien Linkedin Prospector By HANA 1.2.6 chrome ecmcgjidmheglcjojadgibjfebndeoeg 31 installs 4 days ago

Hardcoded live API keys

exfiltration/sensitive-data
micro-behaviorsmicro-behaviors/communicationsmetadata/binarymalware/librarymalwaremetadataobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/evasionmicro-behaviors/process+10 5d

CS2 cheat with hooks

injection/harmony-mod
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/executionobjectives/supply-chainobjectives+26 5d

Persists malicious runtime services

extensions/vscode
micro-behaviorsmicro-behaviors/fsobjectivesobjectives/command-and-controlobjectives/lateral-movement 5d
IRC-Worm.IRC.Wally and 6 siblings 5 days ago

Known IRC worm malware

irc/clientworm/irc
objectivesobjectives/command-and-controlthird-party 5d
Backdoor.ASP.Ace.aa and 8 siblings 5 days ago

Encoded ASP webshell backdoor

ASP/Encodedwebshell/request
micro-behaviorsmicro-behaviors/fsobjectivesobjectives/command-and-control 5d
IRC-Worm.DOS.Apulia and 6 siblings 5 days ago

Worm spreading via mIRC

irc/client

WEDNESDAY

Wed Sep 23 · 288 catches · 18 waves · 26 singles
objectivesobjectives/command-and-controlmicro-behaviorsmicro-behaviors/communicationsthird_party 5d
b75f163ca9b9… and 19 siblings biggest campaign 5 days ago

Hafnium webshell detection

Secchecker/Mar21
well-knownwell-known/dual-usemicro-behaviors/communicationsmicro-behaviorsobjectives/executionobjectives/impactobjectives/collectionobjectives/discoveryobjectives/command-and-controlobjectivesobjectives/lateral-movement+7 5d
pedido.bat 5 days ago

Silent RAT install from bare IP

delivery/auto-downloaddelivery/admin-share
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemalwaremalware/appmetadatamicro-behaviors/datamicro-behaviors/processobjectives/anti-staticobjectivesobjectives/supply-chain+2 5d

preinstall hook executes hidden payload

hidden-payload/encodingcode-metrics/invisible
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/appmetadatametadata/buildmicro-behaviors/datamicro-behaviors/processobjectives/anti-staticobjectivesobjectives/supply-chain+3 5d

Obfuscated preinstall eval payload

code-metrics/invisiblehidden-payload/encoding
objectives/exfiltrationmicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/credential-accessobjectives/command-and-controlobjectives/persistenceobjectives/evasionobjectivesobjectives/execution+13 5d

LLM-driven malware with C2, exfil, injection

automation/autonomous
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 5d

High-entropy binary, rapid release churn

binary/dos
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/uimetadataobjectivesobjectives/evasion 5d

Phishing page with evasion

anti-av/content
micro-behaviors/osmicro-behaviorsmetadata/binarymalwaremalware/appmetadataobjectives/anti-staticobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectives+29 5d

obfuscated binaries, credential theft, C2

staging/tiny-pe
objectivesobjectives/anti-staticmicro-behaviorsmicro-behaviors/communicationsobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/uithird_party 5d
88b4e9c0b358… and 3 siblings 5 days ago

ASP webshell with SQL access

ASP/SQL
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/langmicro-behaviors/processthird-party 5d
068d1b381348… and 4 siblings 5 days ago

JSP webshell executes commands

Encoded/ShellUpload/Write
micro-behaviorsmicro-behaviors/cryptoobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processmetadata/packageobjectivesobjectives/impactmetadatametadata/binary+2 5d

Typosquatting, high release rate, binary payload

binary/dos
micro-behaviors/communicationsmicro-behaviorsmetadata/importmalwaremalware/appmetadataobjectives/anti-staticobjectives/supply-chainobjectives/command-and-controlobjectivesobjectives/execution+16 5d

Steals AI credentials, executes remote code

execution/filelessexploit/http-command-injection
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/supply-chainobjectivesobjectives/impactmalwaremalware/unwantedmicro-behaviors/ui+10 5d

Region-gated UI blocking and audio

manipulation/browserunwanted/sweetalert2-protestware
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/supply-chainobjectivesobjectives/impactmalwaremalware/unwantedmicro-behaviors/ui+10 5d

Region-gated audio playback and input blocking

unwanted/sweetalert2-protestwaremanipulation/browser
objectives/anti-staticwell-known/Mcmicro-behaviors/cryptomicro-behaviorsmetadata/binarymetadataobjectives/anti-analysisobjectives/collectionobjectiveswell-knownobjectives/persistence+30 5d

Empire C2 framework with offensive modules

wmi/subscriptionrat/powershell-empire
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/langthird-party 5d
35dd9906b660… and 11 siblings 5 days ago

JSP webshell executes arbitrary code

Generic/Classloader
micro-behaviors/osmicro-behaviorsmetadata/binarymalwaremalware/appmetadataobjectives/anti-staticobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectives+29 5d

obfuscated binaries, credential access, C2

staging/tiny-pe
micro-behaviorsmicro-behaviors/communicationsthird_party 5d
cmd.aspx and 9 siblings 5 days ago

ASP.NET webshell executes commands

CSHARP/Generic
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/impactwell-knownwell-known/unwantedmicro-behaviors/ui+14 5d
gp247/front 3.0.8 php 1,074 installs ✓ 5 days ago

Malicious region-gated audio payload

unwanted/sweetalert2-protestwaremanipulation/browser
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/credential-accessobjectivesobjectives/impactmalwaremalware/unwantedmicro-behaviors/ui+8 5d
AutoFriends 2.8.5 chrome pmpbhhdmaaccngiofnbaelglocmabnae 9,000 installs 5 days ago

Region-gated audio blocking payload

manipulation/browserunwanted/sweetalert2-protestware
objectivesobjectives/command-and-controlmicro-behaviorsmicro-behaviors/communicationsmetadatametadata/langmicro-behaviors/processthird-party 5d
ISO-8859 10 and 19 siblings 5 days ago

JSP webshell executes commands

Exec/ReqGeneric/Tiny
objectivesobjectives/command-and-controlmicro-behaviorsmicro-behaviors/communicationsmetadatametadata/langmicro-behaviors/processthird-party 5d
one.jsp and 13 siblings 5 days ago

JSP webshell with command execution

SigBase/CustomizeNew/JSP
objectives/command-and-controlmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/langobjectives/anti-staticmicro-behaviors/uimicro-behaviors/datamicro-behaviors/processobjectivesobjectives/collection+1 5d
JspSpy Codz By - Ninty_1.jsp and 10 siblings 5 days ago

JSP web shell with C2

database/queryscreenshot/capture
third-party 5d
UTF 16LE and 7 siblings 5 days ago

JSP webshell executes commands

Generic/Tiny
objectivesobjectives/command-and-controlthird-party 5d
customize.ashx and 5 siblings 5 days ago

ASP webshell with SQL access

ASP/SQL
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/langmicro-behaviors/processobjectives/command-and-controlobjectivesthird-party 5d
苦咖啡专用.jsp and 5 siblings 5 days ago

JSP webshell executes commands

webshell/execNc/Download
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/langobjectives/anti-staticmicro-behaviors/osmicro-behaviors/processmicro-behaviors/uiobjectives/command-and-controlobjectivesobjectives/collection+1 5d
JspSpy Private C… Ninty_encode.jsp and 2 siblings 5 days ago

JspSpy web shell

database/querywebshell/exec
metadatametadata/langthird-party 5d
reflection-aes 1 and 2 siblings 5 days ago

JSP webshell executes commands

Generic/ReflectionEncoded/Shell
well-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlobjectives/lateral-movementobjectiveswell-knownobjectives/supply-chain+21 5d
MemoryOS 2.0.34 python ✓ 5 days ago

Embedded malicious sckit binaries

supply-chain/sckitworm/repository
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/credential-accessobjectives/evasionobjectivesobjectives/exfiltration+18 5d
Chrome Web Store chrome lnpiojnpjlehhikibfjdjipipakodaol 5 days ago

Automated dating bot with credential theft

http/reportllm/override
well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/persistenceobjectives/command-and-controlobjectivesobjectives/execution+20 5d
summrise-agent 1.2.459 javascript and 2 siblings 5 days ago

Mythic C2 fields, hidden persistence

execution/wsh
well-knownwell-known/Mcmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/exfiltrationobjectivesobjectives/command-and-controlobjectives/credential-access+7 5d
Rusherhack.jar and 2 siblings ✓ 5 days ago

Minecraft credential stealer with C2

dropper/staged-loadergaming/minecraft
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/impactobjectives/collectionmicro-behaviors/communicationsmicro-behaviors/datamicro-behaviors/uiobjectives/discoveryobjectives+6 5d
GF Diagnostico Usuarios 6.2.2 firefox gf-diagnostico-usuarios 9 installs 5 days ago

Steals credentials, exfiltrates data

host/geo
micro-behaviors/communicationsmicro-behaviorsmalwaremalware/appmetadatametadata/buildobjectives/executionobjectives/supply-chainobjectives/command-and-controlobjectives/anti-staticobjectives+14 5d
投标报价对比分析驾驶舱 1.0.0 openclaw bid-quote-cockpit 5 days ago

Obfuscated installer with EDR evasion

payload/encodedencoding/content
micro-behaviorsmicro-behaviors/datametadatametadata/buildmicro-behaviors/osmicro-behaviors/processmetadata/packagemetadata/importobjectives/supply-chainobjectives 5d

Exfiltrates credentials during build

credential-theft/envinstall-hook/credential
micro-behaviors/osmicro-behaviorsmalware/toolmalwaremetadatametadata/buildobjectives/anti-staticobjectives/collectionobjectives/command-and-controlobjectivesobjectives/execution+24 5d
suijin 6.9.0 python 5 days ago

Autonomous offensive security framework

execution/pipereverse-shell/dev-tcp
objectives/anti-staticobjectivesmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymalware/Mcmetadataobjectives/executionobjectives/discoveryobjectives/persistencemalware+8 5d
github.com/jm33-…16.1+incompatible go and 2 siblings 5 days ago

Post-exploitation framework with obfuscation

backdoor/emp3r0r
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/binarymetadataobjectives/command-and-controlobjectives/evasionobjectives/executionobjectives/anti-staticobjectives+21 6d
非凡资源下载 1.5.9 firefox 15 installs 6 days ago

Bundled malware, obfuscated dropper

payload/resource
well-known/librarywell-knownmicro-behaviorsmicro-behaviors/communicationsmetadata/binarymetadataobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/evasionmicro-behaviors/process+10 6d

CS2 cheat with hooks and C2

injection/harmony-mod
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/impactobjectives/anti-staticobjectives/collectionmicro-behaviors/communicationsobjectives/credential-accessobjectivesobjectives/discovery+8 6d
Rankyfy - OnPage SEO Checker 1.1 chrome khmojcamopjblojkongknknedpcddoee 19 installs 6 days ago

Steals cookies and tokens

host/geobrowser/session-hijack
well-knownwell-known/appmicro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemetadataobjectives/anti-staticobjectives/collectionobjectives/command-and-controlobjectivesobjectives/execution+14 6d
NoobClaw Browser Assistant 2.0.8 firefox noobclaw-browser-assistant 1 installs 6 days ago

Arbitrary code execution, cookie theft

execution/browserexploit/chain
well-known/librarywell-knownmicro-behaviorsmicro-behaviors/communicationsmetadata/binarymetadataobjectives/anti-staticobjectives/anti-analysisobjectivesobjectives/evasionmicro-behaviors/process+10 6d

CS2 cheat with hooks

injection/harmony-mod
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/buildmicro-behaviors/osmetadata/importobjectives/exfiltrationobjectivesobjectives/supply-chain 6d
kerokwis 99 ruby 57 installs ✓ 6 days ago

Install hook exfiltrates hostname

install-hook/extconfoob/system-profile

TUESDAY

Tue Sep 22 · 198 catches · 6 waves · 18 singles
well-knownwell-known/Mcmicro-behaviors/datamicro-behaviorsobjectives/anti-analysisobjectives/impactobjectives/supply-chainobjectives/anti-staticobjectivesobjectives/executionobjectives/command-and-control+4 6d
Corporate_Brief_2026.JS and 6 siblings biggest campaign ✓ 6 days ago

Obfuscated WSH dropper with ActiveX

obfuscation/multi-layerexecution/wsh-reconstruct
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 6d

High-entropy binary, rapid release churn

binary/dos
micro-behaviors/communicationsmicro-behaviorsmetadata/binarymalwaremalware/librarymetadataobjectives/anti-staticobjectives/evasionobjectives/command-and-controlobjectivesobjectives/execution+11 6d

Disables Task Manager, persistence, C2

execution/loaderdelivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmetadata/binarymalwaremalware/libmetadataobjectives/evasionobjectives/command-and-controlobjectives/anti-staticobjectives/supply-chainobjectives+14 6d

Hidden Lua payload in archive

hidden-payload/execcode-metrics/structure
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/credential-accessobjectives/exfiltrationobjectives/supply-chainobjectives/executionobjectives/command-and-controlobjectives+9 6d

RCE exploit tool with reverse shell

reverse-shell/dev-tcpcmd/injection
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-analysisobjectives/anti-staticobjectives/credential-accessobjectives/supply-chainobjectives+13 6d
Subveris Subscription Insights 1.2.9 firefox subveris-subscription-insights 6 days ago

Exfiltrates cookies, tokens, and Gmail data

extensions/backdoorbrowser/extension
well-knownwell-known/appmicro-behaviors/osmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/collectionobjectives/credential-accessobjectives/command-and-controlobjectives+28 6d

obfuscated binaries, credential access, C2

staging/tiny-pe
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/supply-chainobjectives/impactobjectives+14 6d
yonzofficial 2.1.2 javascript and 3 siblings ✓ 6 days ago

Remote-controlled newsletter auto-follow, obfuscated strings, install hook

manipulation/socialinstall-hook/hook-only
well-knownwell-known/libmicro-behaviors/processmicro-behaviorsmetadatametadata/buildobjectives/supply-chainobjectives/credential-accessobjectives/command-and-controlobjectives/anti-staticobjectives+13 6d
opencomb 0.18.0 python 6 days ago

Obfuscated base64/zlib exec payloads at import

payload/encodedeval/scripting
micro-behaviors/processmicro-behaviorsmalwaremalware/librarymetadatametadata/buildobjectives/supply-chainobjectives/credential-accessobjectives/command-and-controlobjectives/anti-staticobjectives+10 6d
opencomb 0.17.2 python 6 days ago

Obfuscated base64 payload exec plus credential harvesting

eval/scriptingpayload/encoded
micro-behaviors/fsmicro-behaviorsmicro-behaviors/osmicro-behaviors/processobjectives/impactobjectives 6d

Defender update starvation attack

edr/update
micro-behaviors/browser-extensionmicro-behaviorsmetadata/packagemalwaremalware/appmetadataobjectives/executionobjectives/anti-staticobjectives/supply-chainobjectives/credential-accessobjectives+15 6d
Code Copy Extension 1.2 chrome dpllipdelaaomeobglohlbcpbdhcipha 42 installs 6 days ago

Exfiltrates browser data to Dropbox

env/dotenvwallet/extension
well-knownwell-known/appmicro-behaviorsmicro-behaviors/communicationsmetadata/importmetadatamicro-behaviors/fsmicro-behaviors/processmicro-behaviors/cryptoobjectives/impactobjectives+1 6d

Ransomware encrypts files, kills AV

encrypt/bulk-encryption
micro-behaviorsmicro-behaviors/communicationsmetadata/importmalwaremalware/appmetadatamicro-behaviors/fsmicro-behaviors/processmicro-behaviors/cryptoobjectives/impactobjectives+1 6d

Ransomware encrypts files, kills AV

encrypt/bulk-encryption
micro-behaviors/communicationsmicro-behaviorsobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/cryptomicro-behaviors/fsobjectivesobjectives/evasionobjectives/execution+1 6d
WE GH2_RFP PKG f…racha SPEC_REV.js and 2 siblings ✓ 6 days ago

Obfuscated PowerShell download and execution

policy/execution
micro-behaviors/processmicro-behaviorsmalwaremalware/Mcmetadatametadata/buildobjectives/supply-chainobjectives/credential-accessobjectives/command-and-controlobjectives/anti-staticobjectives+9 6d
opencomb 0.16.0 python 6 days ago

Obfuscated exec payload, credential harvesting, bpoorman malware

eval/scriptingpayload/encoded
micro-behaviors/osmicro-behaviorsmetadatametadata/langobjectives/anti-staticmicro-behaviors/processobjectives/command-and-controlobjectivesobjectives/execution 6d
RFQ-SCM04429866,PDF.vbs and 2 siblings ✓ 6 days ago

Obfuscated VBS executes hidden PowerShell

execution/wshvbscript/wmi
well-known/librarywell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/evasionobjectives/anti-analysisobjectives/anti-staticobjectivesobjectives/command-and-control+20 6d

Obfuscated betting bot with CDP

payload/resourcedropper/builder
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/buildobjectives/credential-accessobjectives/anti-staticobjectives/command-and-controlobjectivesobjectives/discovery+15 6d
0kx WALLEТ 7.25.2 firefox bookmark-plus-f5657a 6 days ago

Crypto wallet stealer exfiltrating cookies and seed phrases

host/geo
metadata/importmalwaremalware/appmetadataobjectives/credential-accessobjectives/executionmicro-behaviors/datamicro-behaviors/communicationsmicro-behaviorsobjectivesobjectives/exfiltration+6 6d

Credential theft and obfuscation

credential/dev-filerequest/credentials
micro-behaviors/communicationsmicro-behaviorsmetadata/binarymalwaremalware/libmetadataobjectives/evasionobjectives/anti-staticobjectivesobjectives/command-and-controlobjectives/execution+15 6d
github.com/the18….9.5+incompatible go and 2 siblings 6 days ago

Disables Task Manager, registry persistence

execution/loaderpayload/resource
micro-behaviorsmicro-behaviors/communicationsmetadatametadata/binaryobjectives/command-and-controlobjectives/impactmicro-behaviors/cryptomicro-behaviors/datamicro-behaviors/fsobjectives/supply-chainobjectives+4 7d
github.com/goget…ortedbtree v1.1.0 go and 2 siblings 7 days ago

Obfuscated payload execution in library

hidden-payload/runtimehidden-payload/scanner-blind
micro-behaviors/browser-extensionmicro-behaviorsmetadatametadata/packageobjectives/anti-staticobjectives/credential-accessmicro-behaviors/communicationsmicro-behaviors/dataobjectivesobjectives/evasionobjectives/exfiltration+5 7d
RABB- EVM&Web3 WALLEТ 177.0.1 firefox f45uji78lo78u 4 installs 7 days ago

Steals seed phrases, exfiltrates clipboard over HTTP

credential/clipboardextension/deception
micro-behaviors/communicationsmicro-behaviorsmalware/appmalwaremetadatametadata/binaryobjectives/anti-staticobjectives/privilege-escalationobjectivesobjectives/supply-chainmetadata/package+26 7d
pwn 0.5.744 ruby 1,114,862 installs 7 days ago

Offensive security framework with evasion

elevation-control/sudopackage/rubygems

MONDAY

Mon Sep 21 · 531 catches · 25 waves · 23 singles
metadataobjectivesobjectives/command-and-controlobjectives/credential-access 7d
864cbc0ec041… and 29 siblings biggest campaign 7 days ago

Malicious URL shortcut payload

delivery/url-shortcutcapture/network
micro-behaviorsmicro-behaviors/datametadatametadata/buildmicro-behaviors/memmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/dylibobjectives/evasionobjectivesmicro-behaviors/process+2 7d

Process hollowing injection implementation

injection/thread-hijackinginjection/hollowing
well-knownwell-known/toolmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/evasionobjectivesmicro-behaviors/process+14 7d

Malware injection toolkit

injection/memoryinjection/dll
micro-behaviorsmicro-behaviors/cryptoobjectives/anti-staticobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processobjectivesobjectives/impactmetadatametadata/binary+3 7d

Bundled high-entropy binary payload

binary/dos
objectives/privilege-escalationobjectiveswell-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticobjectives/command-and-controlthird_party+22 7d

Contains multiple kernel exploit binaries

exploit/cve_2022_0847Pwnkit/Strings
well-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/anti-staticobjectives/supply-chainobjectives/evasionobjectives/impactobjectives+17 7d

Obfuscated hidden payload targeting VS Code

destroy/file-deletion
objectives/command-and-controlmicro-behaviors/fsmicro-behaviorsobjectives/anti-staticobjectives/executionmicro-behaviors/processobjectivesobjectives/impactobjectives/evasion 7d

Email worm, AV deletion, self-propagation

file/scriptinfect/script
micro-behaviors/fsmicro-behaviorsobjectives/anti-staticobjectivesobjectives/evasionobjectives/impact 7d
Trojan.DOS.Holop 7 days ago

Trojan overwrites system executables

self-delete/scriptsinfect/script
objectives/command-and-controlobjectives/evasionobjectives/impactmicro-behaviors/osobjectives/anti-staticobjectivesmicro-behaviors/fsmicro-behaviors 7d

Installs hidden RAdmin backdoor services, self-deletes

string/concatfile/attributes
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/command-and-controlobjectives/anti-staticobjectives/executionobjectives/impactobjectives/evasionobjectivesmicro-behaviors/process+11 7d

Process injection and code patching

injection/dllinjection/memory
micro-behaviors/fsmicro-behaviorsmicro-behaviors/osmetadataobjectivesobjectives/evasionobjectives/impact 7d
Virus.BAT.Silly.am and 3 siblings 7 days ago

Self-replicating batch virus

infect/scripthidden/execution
metadataobjectives/command-and-controlobjectivesobjectives/credential-access 7d
JAN-17-2024 765FYDX and 10 siblings 7 days ago

Malicious URL shortcut to IP

capture/networkdelivery/url-shortcut
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/archobjectives/evasionmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
d4479c6a8ad5… and 2 siblings 7 days ago

Multi-arch C2 dropper self-deletes

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
8e3bdcf990ae… and 7 siblings 7 days ago

Downloads and executes remote exploit

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
2b6129f0277a… and 2 siblings 7 days ago

Multi-arch malware dropper

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
6141287a6f20… and 3 siblings 7 days ago

Downloads and executes remote binaries

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
3d51c7c5239a… and 7 siblings 7 days ago

Multi-arch malware downloader

delivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
180e14fce41e… and 3 siblings 7 days ago

Downloads and executes remote script

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
0a9c5f0aef7d… and 5 siblings 7 days ago

Downloads and executes remote exploits

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
907981fbe7d0… and 5 siblings 7 days ago

Downloads and executes remote exploits

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
1cecd1285570… and 4 siblings 7 days ago

Multi-arch malware dropper downloads and executes binaries

delivery/fetch-execdelivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/archmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
dcc157c0abff… and 3 siblings 7 days ago

Multi-arch malware dropper from raw IP

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsobjectives/evasionobjectives/impactmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
f738594b0853… and 3 siblings 7 days ago

Multi-arch IoT botnet dropper

botnet/iotdelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/archmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
93ebc64f645c… and 2 siblings 7 days ago

Dropper downloads and executes remote binaries

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmetadata/binarymetadataobjectives/anti-staticmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processmetadata/packageobjectivesobjectives/exfiltration+1 7d

Exfiltrates environment variables and IP

stealer/system-info
objectivesobjectives/command-and-control 7d
bcdd4cff01ab… and 6 siblings 7 days ago

URL shortcut to WebDAV dropper

delivery/url-shortcut
micro-behaviorsmicro-behaviors/cryptoobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/fsmicro-behaviors/processmetadata/packageobjectivesobjectives/impactmetadatametadata/binary+2 7d

High-entropy binary, rapid release churn

binary/dos
micro-behaviors/communicationsmicro-behaviorsobjectives/evasionobjectives/executionmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
3b0b2a258879… and 13 siblings 7 days ago

Multi-arch botnet dropper

delivery/execute-downloadbotnet/iot
micro-behaviors/communicationsmicro-behaviorsobjectives/evasionmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
f440ab289c21… and 2 siblings 7 days ago

Multi-arch botnet dropper script

botnet/iotdelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsobjectives/discoveryobjectives/executionmicro-behaviors/fsmicro-behaviors/processmicro-behaviors/osobjectives/command-and-controlobjectives 7d
aaf033f60ef8… and 7 siblings 7 days ago

Downloads and executes remote binaries

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/archobjectives/anti-staticmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
ec7bbec9779d… and 2 siblings 7 days ago

Multi-arch dropper from raw IP

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
c40fb1ddbc30… and 2 siblings 7 days ago

Downloads and executes remote binary

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmalware/appmetadata/binarymalwaremetadataobjectives/anti-staticobjectives/credential-accessobjectives/command-and-controlobjectives/impactobjectives+25 7d

Embedded malicious payload strings

disk/mass-deletedelivery/execute-download
well-knownwell-known/appmetadata/packagemetadataobjectives/anti-staticobjectives/command-and-controlobjectives/impactmicro-behaviors/datamicro-behaviorsobjectives/collectionobjectives+18 7d

Hardcoded secrets, obfuscation, exfiltration

stealer/browserformat/css
well-knownwell-known/librarymicro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmetadataobjectives/credential-accessobjectives/executionobjectives/lateral-movementobjectivesobjectives/exfiltration+15 7d
Costco Tools by RestockBotAlerts 1.6.7 firefox costco-tools-restockbotalerts 8 installs 7 days ago

Credential theft, obfuscation, C2 tunnel

oob/endpointbrute-force/password
micro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/command-and-controlobjectives/discoveryobjectives/evasionobjectives/anti-staticobjectivesobjectives/supply-chainmetadata/package+11 7d

Crypto miner with persistence and C2

payload/encryptedpackage/rubygems
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/osmicro-behaviors/processobjectives/command-and-controlobjectives 7d
t linux ✓ 7 days ago

Downloads and executes remote malware

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/fsmicro-behaviors/processobjectives/command-and-controlobjectives 7d
w linux ✓ 7 days ago

Downloads and executes remote payloads

delivery/execute-downloaddelivery/fetch-exec
micro-behaviors/communicationsmicro-behaviorsmicro-behaviors/processmicro-behaviors/fsobjectives/command-and-controlobjectives 7d
traff linux ✓ 7 days ago

Downloads and executes remote payload

delivery/execute-download
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/collectionmicro-behaviors/datamicro-behaviors/osmicro-behaviors/dylibobjectives/evasionobjectivesobjectives/exfiltration+1 7d
pullgetsage 0.1.2 python ✓ 7 days ago

Steals Telegram data, exfiltrates

http/archiveindicator-removal/cleanup
micro-behaviors/datamicro-behaviorsmetadatametadata/langmicro-behaviors/osmicro-behaviors/processmetadata/signedobjectives/anti-staticobjectives/executionobjectives 7d
BANK SLIP USD 19…4 HG PERTH).vbs and 2 siblings ✓ 7 days ago

Obfuscated VBS malware with registry access

vbscript/loaderstring/junking
well-knownwell-known/libmicro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/evasionobjectives/executionobjectives/anti-staticobjectives/command-and-controlobjectives+7 7d

Obfuscated JS payload in font file

delivery/fetch-evalinstruction/insertion-junk
micro-behaviors/browser-extensionmicro-behaviorsmalwaremalware/dual-usemetadatametadata/packageobjectives/collectionobjectives/executionobjectives/credential-accessobjectives/exfiltrationobjectives+6 8d
InboxHub 1.1.3 chrome jmaebhngjpkdjagbiabligaeonfmfnic 3 installs 8 days ago

Exfiltrates Depop auth tokens to ngrok

oob/endpointbrowser/session-hijack
well-known/appwell-knownmicro-behaviors/communicationsmicro-behaviorsmetadata/buildmetadataobjectives/anti-staticobjectives/command-and-controlobjectives/executionobjectives/persistenceobjectives+24 8d

curl-pipe-sh, credential theft, persistence

service/systemdautomation/agent
objectives/credential-accessmicro-behaviors/browser-extensionmicro-behaviorsmalwaremalware/appmetadatametadata/packageobjectives/collectionobjectivesobjectives/supply-chainobjectives/exfiltration+15 8d
Skip Wait - Smart Wait Time help 1.5.7 firefox skip-wait-smart-wait-time-help 1 installs 8 days ago

Obfuscated credential stealer

exfiltration/sensitive-datatrojanized/dist
micro-behaviors/communicationsmicro-behaviorsmetadata/importmetadataobjectives/discoverymicro-behaviors/processmicro-behaviors/datamicro-behaviors/hardwaremicro-behaviors/osobjectives/exfiltrationobjectives+1 8d
rrs 0.4.108 python ✓ 8 days ago

Exfiltrates screen capture to Discord

messaging/webhookcredential/platform
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/discoveryobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/osmicro-behaviors/processobjectives/exfiltrationobjectives+1 8d
rrs 0.4.105 python and 3 siblings ✓ 8 days ago

Exfiltrates screen captures to Discord

messaging/webhookcredential/platform
micro-behaviors/browser-extensionmicro-behaviorsmetadata/permissionmalwaremalware/librarymetadataobjectives/credential-accessobjectives/executionobjectives/lateral-movementobjectivesobjectives/exfiltration+15 8d
Costco Tools by RestockBotAlerts 1.6.6 firefox costco-tools-restockbotalerts 8 installs 8 days ago

Credential theft, obfuscation, weak passwords

oob/endpointbrute-force/password
micro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/exfiltrationobjectivesobjectives/command-and-controlobjectives/supply-chain 8d
@nimbsuedge3/xar 1.1.1 javascript and 2 siblings ✓ 8 days ago

preinstall reverse shell C2

scripts/remote-fetchreverse-shell/dev-tcp
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories