news.mlab.sh
Back to the feed
malware

Cross-Platform NPM Stealer, (Fri, May 22nd)

High
Summary

A cross-platform Node.js stealer has been discovered targeting Windows, macOS, and Linux systems. The malware, obfuscated to avoid detection, extracts sensitive data from various browsers and applications, including Chrome, Brave, and Edge. It utilizes Base64-encoded strings and low-level decoders to achieve its functionality, exfiltrating data to port 8085. The tool also includes a recursive file exfiltration scanner searching for sensitive files.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.