Qui-Quo 2.3.2
Credential theft and obfuscation
“Подборка туров клиенту в два клика!”
Browser extension forwards captured login credentials to a hardcoded remote hostBuilt bundle ends with a remote script injector
SHA-25696c5a0db06c12e0f1eede45ba301223257b75e2fe41cde877b27318010cb10bc