#cyberhunter_nl — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
Pulse ID: 6ab699862ec3e91c17fbcb55
Pulse Link: https://otx.alienvault.com/pulse/6ab699862ec3e91c17fbcb55
Pulse Author: CyberHunter_NL
Created: 2026-09-25 15:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Indicators extracted from public reporting. Source: https://safedep.io/memtensor-sckit-worm-npm-pypi/
Pulse ID: 6ab3e8809565240cb05279eb
Pulse Link: https://otx.alienvault.com/pulse/6ab3e8809565240cb05279eb
Pulse Author: CyberHunter_NL
Created: 2026-09-23 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Indicators extracted from public reporting. Source: https://safedep.io/memtensor-sckit-worm-npm-pypi/
Pulse ID: 6ab3e8809565240cb05279eb
Pulse Link: https://otx.alienvault.com/pulse/6ab3e8809565240cb05279eb
Pulse Author: CyberHunter_NL
Created: 2026-09-23 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Indicators extracted from public reporting. Source: https://safedep.io/memtensor-sckit-worm-npm-pypi/
Pulse ID: 6ab3e8809565240cb05279eb
Pulse Link: https://otx.alienvault.com/pulse/6ab3e8809565240cb05279eb
Pulse Author: CyberHunter_NL
Created: 2026-09-23 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Indicators extracted from public reporting. Source: https://safedep.io/memtensor-sckit-worm-npm-pypi/
Pulse ID: 6ab3e8809565240cb05279eb
Pulse Link: https://otx.alienvault.com/pulse/6ab3e8809565240cb05279eb
Pulse Author: CyberHunter_NL
Created: 2026-09-23 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Indicators extracted from public reporting. Source: https://safedep.io/memtensor-sckit-worm-npm-pypi/
Pulse ID: 6ab3e8809565240cb05279eb
Pulse Link: https://otx.alienvault.com/pulse/6ab3e8809565240cb05279eb
Pulse Author: CyberHunter_NL
Created: 2026-09-23 14:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.