Bundled high-entropy binary payload
Fallout, since Sep 21
What we caught this week while monitoring over 185,582,225 artifacts across 59 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Sep 27 · 107 catches · 2 waves · 25 singlesHidden PowerShell, VBS, and registry persistence
Active Directory attack toolkit
Dependency explicitly classified hostile
Trojanized obfuscator with process execution
Clipboard exfiltration to hidden IP
Hostile dependency embedded
Exploit code with reverse shell
Embedded base64 shellcode in definitions
WMI hidden process, obfuscated payload
Installs MITM root CA, intercepts traffic
Browser automation for credential theft
DevTools blocked, raw IP API
Routes all traffic to attacker proxy
Obfuscated PowerShell malware dropper
Wallet drainer with fake balances
Hidden process execution and obfuscation
Typosquatted malicious dependency
SATURDAY
Sat Sep 26 · 381 catches · 7 waves · 22 singlesTyposquatting, high release velocity, binary payload
Encoded PowerShell backdoor, C2, ransomware strings
Trojanized dependency rewrites host code
Dependency classified hostile, credential access
High-entropy binary, rapid release churn
Collection of RCE exploits
Collection of RCE exploit scripts
Academic dishonesty and anti-detection evasion
typosquatted Docker CLI module
Obfuscated PowerShell malware
obfuscated VBScript execution
Keylogger exfiltrates via email
Search hijack, data exfiltration
Cookie theft and credential access
Metasploit offensive payloads included
FRIDAY
Fri Sep 25 · 2737 catches · 8 waves · 26 singlesFile infector virus behavior
installs persistence, evades AV, obfuscated payload
Malicious code in SweetAlert2
High-entropy binary, rapid releases, typosquatting
LinkedIn automation and data exfiltration
DNS rebinding path traversal exploit
Offensive security tool with evasion
Offensive security tool with exploit capabilities
Credential harvesting and persistence
Steals wallet seed phrases
Clipboard exfiltration, obfuscated C2
Typosquatting, evasion, preinstall hook
Contains active exploit and reverse shell code
Encoded PowerShell, C2, ransomware strings
Obfuscated .pth payload executes code
Obfuscated .pth auto-executes payload
Credential capture and exfiltration
Metasploit framework with offensive payloads
Credential harvesting and bulk email abuse
Java deserialization exploit tool
Malicious SweetAlert2 payload
Exfiltrates environment variables on install
Remote code execution, credential theft
Malicious VS Code extension payload
THURSDAY
Thu Sep 24 · 278 catches · 6 waves · 23 singlesCredential theft, obfuscation, weak passwords
High-entropy binary, rapid release churn
Exfiltrates system info to webhook
Embedded credential theft rules
Malicious font file executes code
Contains reverse shells and exploits
Contains reverse shells and exploits
CAPTCHA solver, cookie exfiltration
AgentTesla infostealer payload detected
Obfuscated code execution in provider
Obfuscated payload execution in provider
Obfuscated payload execution in provider
Obfuscated payload execution
Windows persistence and credential targeting
CDP control, input blocking, all-URLs
Obfuscated PowerShell dropper in main.go
Credential theft, obfuscation, weak passwords
Exfiltrates wallet seed phrases
obfuscated ActiveX file execution
Hardcoded live API keys
WEDNESDAY
Wed Sep 23 · 288 catches · 18 waves · 26 singlespreinstall hook executes hidden payload
Obfuscated preinstall eval payload
High-entropy binary, rapid release churn
Typosquatting, high release rate, binary payload
Steals AI credentials, executes remote code
Region-gated UI blocking and audio
Region-gated audio playback and input blocking
Empire C2 framework with offensive modules
Malicious region-gated audio payload
Region-gated audio blocking payload
Automated dating bot with credential theft
Minecraft credential stealer with C2
Dependency explicitly classified hostile
Steals credentials, exfiltrates data
Obfuscated installer with EDR evasion
Exfiltrates credentials during build
Post-exploitation framework with obfuscation
Steals cookies and tokens
Arbitrary code execution, cookie theft
TUESDAY
Tue Sep 22 · 198 catches · 6 waves · 18 singlesObfuscated WSH dropper with ActiveX
High-entropy binary, rapid release churn
Disables Task Manager, persistence, C2
Hidden Lua payload in archive
RCE exploit tool with reverse shell
Exfiltrates cookies, tokens, and Gmail data
Remote-controlled newsletter auto-follow, obfuscated strings, install hook
Obfuscated base64 payload exec plus credential harvesting
Exfiltrates browser data to Dropbox
Obfuscated PowerShell download and execution
Obfuscated exec payload, credential harvesting, bpoorman malware
Obfuscated VBS executes hidden PowerShell
Crypto wallet stealer exfiltrating cookies and seed phrases
Hostile dependency included
Credential theft and obfuscation
Disables Task Manager, registry persistence
Obfuscated payload execution in library
Steals seed phrases, exfiltrates clipboard over HTTP
MONDAY
Mon Sep 21 · 531 catches · 25 waves · 23 singlesMalicious URL shortcut payload
Process hollowing injection implementation
Malware injection toolkit
Bundled high-entropy binary payload
Contains multiple kernel exploit binaries
Installs hidden RAdmin backdoor services, self-deletes
Process injection and code patching
Malicious URL shortcut to IP
Downloads and executes remote exploit
Downloads and executes remote binaries
Downloads and executes remote script
Downloads and executes remote exploits
Downloads and executes remote exploits
Multi-arch malware dropper downloads and executes binaries
Multi-arch malware dropper from raw IP
Dropper downloads and executes remote binaries
High-entropy binary, rapid release churn
Downloads and executes remote binary
Embedded malicious payload strings
Hardcoded secrets, obfuscation, exfiltration
Credential theft, obfuscation, C2 tunnel
Crypto miner with persistence and C2
Obfuscated VBS malware with registry access
Obfuscated JS payload in font file
Exfiltrates Depop auth tokens to ngrok
curl-pipe-sh, credential theft, persistence
Obfuscated credential stealer
Exfiltrates screen captures to Discord
Credential theft, obfuscation, weak passwords
preinstall reverse shell C2