IceCube is a JavaScript malware deployed by UNK_MassTraction after exploiting CVE-2024-42009 in Roundcube. It steals credentials, 2FA tokens, cookies, and browser information, sending them via HTTP POST. It also uses CSRF tokens to trigger CVE-2025-49113 for further compromise and sets up deferred triggers to maintain infection chains.