TaskWeaver: Node.js Loader Used in SimpleHelp Exploitation
A heavily obfuscated Node.js loader delivered as jquery.js, executed via node.exe. It establishes encrypted communications with a remote server and retrieves additional…
A heavily obfuscated Node.js loader delivered as jquery.js, executed via node.exe. It establishes encrypted communications with a remote server and retrieves additional…
An information stealer targeting Windows, macOS, and Linux. Harvests credentials from cloud platforms, source control, package registries, AI assistants, browsers, SSH, and…
Microsoft has discovered a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for.…
A new macOS malware called Gaslight uses embedded prompt injection strings and fake debugging data to confuse AI-assisted malware analysis tools. It…
PteroSand is a malware payload delivered by Gamaredon via HTA downloaders in spear-phishing campaigns targeting Ukraine.
Google Analytics is a web analytics service that was abused by the StegoAd campaign for covert telemetry, providing the operator with real-time…
Microsoft has removed 119 malicious extensions from the Edge Add-ons store that used steganography to hide malware in image and font files.…
Chromium browsers are open-source web browsers that share the same codebase. The StegoAd campaign's indicators of compromise apply to Chromium-based browsers.
Nextron Systems discovered 16 Go packages containing the same malware as the npm packages, targeting the Go ecosystem with a Python infostealer.
ENCFORGE is a compiled Go ransomware, built with Go 1.22.12.