NodeEdgeRAT: JavaScript RAT with All-in-One Script
NodeEdgeRAT is a JavaScript-based remote access tool that ships its entire functionality—command execution, file management, and file transfer—in a single script. It…
NodeEdgeRAT is a JavaScript-based remote access tool that ships its entire functionality—command execution, file management, and file transfer—in a single script. It…
w2.js is a JavaScript payload used in the BdThemes supply chain attack. It contacts a C2 server, creates rogue admin accounts, installs…
x.js is an alternate payload in the BdThemes attack that generates deterministic administrative credentials based on the victim website's hostname, allowing attackers…
A widely used JavaScript library with a critical weak RNG flaw in versions below 4.0.0, affecting cryptocurrency wallet recovery phrase generation.
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…
core-js is a legitimate npm package for polyfilling JavaScript features. The malicious core.js file in typo-crypto was named to impersonate it.
Bun is a JavaScript runtime that the worm's stage one downloads (version 1.3.13) to execute a compiled credential-stealing bundle.
Yarn is a package manager for JavaScript that provides deterministic dependency resolution. It has implemented cooldown controls to enhance supply chain security.
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
ZimReaper is a malicious JavaScript payload delivered via CVE-2025-66376 in Zimbra's Classic UI. It harvests email communications and other sensitive data from…