DEV#POOPER: Remote Access Trojan Family
DEV#POOPER is a malware family that delivers remote access trojans (RATs) via compromised npm packages, often using blockchain-based command-and-control infrastructure.
DEV#POOPER is a malware family that delivers remote access trojans (RATs) via compromised npm packages, often using blockchain-based command-and-control infrastructure.
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
The Dysphoria IoT botnet, tracked by CNCERT and XLab (Qi'anxin), has evolved to use blockchain-based name services and infected-device relays following a…
Dysphoria is an IoT botnet tracked by CNCERT and XLab. It evolved after the JackSkid disruption to use ENS and SNS for…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
SuccessKey is the threat actor attributed to the ViteVenom and ChainVeil campaigns, which use blockchain-based C2 infrastructure to deliver remote access trojans…
ViteVenom is a malware campaign discovered by Checkmarx that uses seven malicious scoped npm packages to deliver a RAT via blockchain-based C2…
ChainVeil is a previous malware campaign that used unscoped typosquat npm packages and a four-tier blockchain C2 infrastructure to deliver a remote…
PolinRider is a threat cluster assessed to be related to the Contagious Interview campaign, known for using multi-blockchain resolver structures (Tron, Aptos,…