Packages
- npm llm-oracleattributed-to
- npm redis-oracleattributed-to
- npm themes-vendorattributed-to
- npm x509-escapingattributed-to
- npm keycloak-serverattributed-to
- npm module-stubattributed-to
- npm postject-copyattributed-to
- npm micrometer-docsattributed-to
- npm orbit-playroomattributed-to
- npm weekendfeattributed-to
- npm nyc-configattributed-to
- npm slf4j-api-jsattributed-to
- npm express-cookie-parserattributed-to
- npm tensorflowjsattributed-to
- npm pino-sdk-v2attributed-to
- npm react-refresh-updateattributed-to
- npm axiosattributed-to
- npm express-session-jsattributed-to
- npm mgcattributed-to
- pypi hermes-pxattributed-to
- npm @velora-dex/sdkattributed-to
- npm npm-global-utilattributed-to
- npm martinez-polygon-clipping-tonyattributed-to
- npm noon-contractsattributed-to
- npm art-templateattributed-to
Indicators
- email josh.weavery@gmail.comexfiltrates-to
- ipv4 13.60.183.44communicates-with
- ipv4 13.60.0.0communicates-with
- ipv4 13.63.255.255communicates-with
- ipv4 8.152.163.60communicates-with
- ipv4 206.214.129.67communicates-with
- sha256 863d274bbeb22ab969f742a06d89bdf0ababb99fdeb074a0fd9057f28b1ef257indicates
- sha1 9066ceeb391d9c7ba6aba650109c2fa3f8e088ebindicates
- email graphite7199@gmail.comexfiltrates-to
- email graphitediscord199@gmail.comexfiltrates-to
- domain discord.comcommunicates-with
- sha256 3733f0add545e5537a7d3171a132df51e0b4105aebe85db35dbe868a056d3d24indicates
- domain malicanbur.procommunicates-with
- ipv4 31.220.48.155communicates-with
- ipv4 173.211.46.22communicates-with
- sha256 0be2375362227f846c56c4de2db4d3113e197f0c605c297a7e0e0c154e94464eindicates
- sha256 5196c3a832897e30c26da768379750bd3c886890e74d0f28a8921bbd19b553fcindicates
- email jaimeandujo086@gmail.comexfiltrates-to
- domain sfrclak.comcommunicates-with
- ipv4 142.11.206.73communicates-with
- sha256 5bb67e88846096f1f8d42a0f0350c9c46260591567612ff9af46f98d1b7571cdindicates
- sha256 59336a964f110c25c112bcc5adca7090296b54ab33fa95c0744b94f8a0d80c0findicates
- sha256 fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cfindicates
- sha256 e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09indicates
- email npm-oidc-no-reply@github.comexfiltrates-to
- email ifstap@proton.meexfiltrates-to
- email jasonsaayman@gmail.comexfiltrates-to
- email nrwise@proton.meexfiltrates-to
- domain jsonkeeper.comcommunicates-with
- domain 216.126.237.71communicates-with
- ipv4 216.126.237.71communicates-with
- ipv4 216.126.229.166communicates-with
- ipv4 216.126.227.239communicates-with
- sha256 b5cca27ca1d792bd8c46b83fccfa4e5ba38916eb78877a19cbb39392ce98cc39indicates
- md5 a36adbc35e69b22acbf9f834a0deb286indicates
- email tj@vision-media.caexfiltrates-to
- domain admondtamang.com.npcommunicates-with
- domain gist.github.comcommunicates-with
- domain gist.githubusercontent.comcommunicates-with
- sha256 40aa5d412a50db79a814ac5ad65237745727cb4777843d66a760f64285a5a3e6indicates
- sha1 1c5d51c2002f452a4dd58a1a73a9dd90a7fe0297indicates
- md5 814132e794e5d007e9b8ebd223a9494findicates
- md5 0c0fc7a0c23cdb5e1c8f66b208053ed6indicates
- email admondtamang@gmail.comexfiltrates-to
- domain prod.universitecentrale.netcommunicates-with
- domain urlvoelpilswwxkiosey.supabase.cocommunicates-with
- domain chat.universitecentrale.netcommunicates-with
- ipv4 146.0.0.0communicates-with
- sha1 333e5b7c412736685b3c296a58663a7763744949indicates
- sha1 4c385d4376314b24793b6b4e3526783f72383667indicates
- sha1 2a6e3839766d215e40785f6b277dc2a34d4e2f71indicates
- sha1 442158353951337678587c236567276e767a3d39indicates
- sha1 3f3922326c646a2d2f78703073224a3e4a366761indicates
- sha1 3c335f732e6f5c3b48665745325c572b25724a60indicates
- sha1 2968623b3a4c275d544149674522663559617b74indicates
- domain 89.36.224.5communicates-with
- domain datahub.inkcommunicates-with
- domain cloud-sync.onlinecommunicates-with
- domain byte-io.uscommunicates-with
- domain api.ipify.orgcommunicates-with
- domain ipinfo.iocommunicates-with
- ipv4 89.36.224.5communicates-with
- ipv4 208.115.220.17communicates-with
- sha256 0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270indicates
- sha256 0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783dindicates
- sha1 dfd224461edb06c556ee0d5677bd78ddda80b910indicates
- domain webhook.sitecommunicates-with
- domain franki.requestcatcher.comcommunicates-with
- ipv4 169.254.169.254communicates-with
- email npmtpoc@gmail.comexfiltrates-to
- domain 172.86.73.132communicates-with
- ipv4 172.86.73.132communicates-with
- sha256 86d17961e9662c53e1fb61701388b7c741bf79c093061df968a3e53c829dcb16indicates
- email info@w8r.nameexfiltrates-to
- email daltonchristiano060@gmail.comexfiltrates-to
- domain 82.221.101.203communicates-with
- ipv4 82.221.101.203communicates-with
- sha256 263df2348f54f1f4980542a41f69d77b085fb28091a95979ba7f0e9f3d0da861indicates
- email noondeved94ed@wshu.netexfiltrates-to
- domain utaq.cfww.shopcommunicates-with
- domain git.youzzjizz.comcommunicates-with
- ipv4 180.178.50.158communicates-with
- ipv4 172.67.141.14communicates-with
- ipv4 104.21.40.254communicates-with
- sha256 273206e2973df6ba7474aa66693797c98dcf26b794da4c3e863ab8d8c694868dindicates
- sha256 5b5fe5d92808a732d0d44246cd706295cc739ed7f4dcae19112df666bc5d4f7dindicates
- sha256 101afde88ff8b5c02fd341eda55022a39203088c2ff11dcb73214911cf5afb77indicates
- sha256 d8e3973a0b3c5359d1f53a22491b56bdd31dee13a51c01c7126bc6694584512findicates
- sha256 f31bdd069fe7966ae11be1f78ee5dd44445938856dd1df12379e0e84a6851f5cindicates
- sha1 57620206d62079baad0e57e6d9ec93120c0f5247indicates
- sha1 14669ca3b1519ba2a8f40be287f646d4d7593eb0indicates
Techniques
- ttp T1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttp T1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttp T1105 Ingress Tool Transferuses
- ttp T1036 Masqueradinguses
- ttp T1539 Steal Web Session Cookieuses
- ttp T1102 Web Serviceuses
- ttp T1552.001 Unsecured Credentials: Credentials In Filesuses
- ttp T1041 Exfiltration Over C2 Channeluses
- ttp T1528 Steal Application Access Tokenuses
- ttp T1071.001 Application Layer Protocol: Web Protocolsuses
- ttp T1546 Event Triggered Executionuses
- ttp T1552.004 Unsecured Credentials: Private Keysuses
- ttp T1059.006 Command and Scripting Interpreter: Pythonuses
- ttp T1027 Obfuscated Files or Informationuses
- ttp T1203 Exploitation for Client Executionuses
