home.social

#elf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #elf, aggregated by home.social.

fetched live
  1. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  2. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  3. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  4. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  5. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  6. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  7. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  8. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  9. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  10. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  11. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.

    Pulse ID: 6a7b39b0e4765559a182c347
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:03:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault

  12. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.

    Pulse ID: 6a7b39b0e4765559a182c347
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:03:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault

  13. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  14. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  15. Inside a Self-Propagating npm Worm

    Pulse ID: 6a7951d7e4e9679263bf13be
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  16. Inside a Self-Propagating npm Worm

    Pulse ID: 6a7951d7e4e9679263bf13be
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:21:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111

  17. В заголовке моего ELF есть точка входа. Оказалось, её никто не читает

    Три статьи я собирал файл и отдавал его эмулятору, ни разу в него не заглянув. Заглянул. Внутри два разных описания одних и тех же байтов, ответ на вопрос, откуда взялся адрес 0x80000000, и поле, которое я заполнял зря. Ну, открываем!

    habr.com/ru/articles/1068276/

    #RISCV #QEMU #bare_metal #ассембле #ELF #компоновщик #линкерскрипт #точка_входа #сегменты_и_секци

  18. Inside a Self-Propagating npm Worm

    A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.

    Pulse ID: 6a75b2f415506d0a2374398b
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:27:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault

  19. Inside a Self-Propagating npm Worm

    A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.

    Pulse ID: 6a75b2f415506d0a2374398b
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:27:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault

  20. ChainDrop: Inside a Self-Propagating npm Worm

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ch

    Pulse ID: 6a751f2c22e68481012c2e2d
    Pulse Link: otx.alienvault.com/pulse/6a751
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 23:56:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL

  21. ChainDrop: Inside a Self-Propagating npm Worm

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ch

    Pulse ID: 6a751f2c22e68481012c2e2d
    Pulse Link: otx.alienvault.com/pulse/6a751
    Pulse Author: CyberHunter_NL
    Created: 2026-08-06 23:56:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL

  22. ChainDrop npm Attack Compromises Hundreds of Packages

    A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.

    Pulse ID: 6a7484b807f5882281629fae
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:57:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault

  23. ChainDrop npm Attack Compromises Hundreds of Packages

    A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.

    Pulse ID: 6a7484b807f5882281629fae
    Pulse Link: otx.alienvault.com/pulse/6a748
    Pulse Author: AlienVault
    Created: 2026-08-06 12:57:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault

  24. Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages

    A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.

    Pulse ID: 6a74570cf5cc7a08cd8e9903
    Pulse Link: otx.alienvault.com/pulse/6a745
    Pulse Author: AlienVault
    Created: 2026-08-06 09:42:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault

  25. Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages

    A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.

    Pulse ID: 6a74570cf5cc7a08cd8e9903
    Pulse Link: otx.alienvault.com/pulse/6a745
    Pulse Author: AlienVault
    Created: 2026-08-06 09:42:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault

  26. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

    On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

    Pulse ID: 6a73cac4902afff959b758aa
    Pulse Link: otx.alienvault.com/pulse/6a73c
    Pulse Author: AlienVault
    Created: 2026-08-05 23:44:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault

  27. Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages

    On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.

    Pulse ID: 6a73cac4902afff959b758aa
    Pulse Link: otx.alienvault.com/pulse/6a73c
    Pulse Author: AlienVault
    Created: 2026-08-05 23:44:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault

  28. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.

    Pulse ID: 6a72f10a39d4c128ee7e2fa8
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:15:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault

  29. Supply Chain Compromise Affecting keyv and cacheable npm Packages

    An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.

    Pulse ID: 6a72f10a39d4c128ee7e2fa8
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:15:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault

  30. ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable

    Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.

    Pulse ID: 6a72f4367f010bc9d645f5d1
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:28:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault

  31. ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable

    Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.

    Pulse ID: 6a72f4367f010bc9d645f5d1
    Pulse Link: otx.alienvault.com/pulse/6a72f
    Pulse Author: AlienVault
    Created: 2026-08-05 08:28:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault

  32. ChainDrop supply chain compromise: Anatomy of a self-propagating worm

    Indicators extracted from public reporting. Source: microsoft.com/en-us/security/b

    Pulse ID: 6a729920ce4597d7b978f0b1
    Pulse Link: otx.alienvault.com/pulse/6a729
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 02:00:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL

  33. ChainDrop supply chain compromise: Anatomy of a self-propagating worm

    Indicators extracted from public reporting. Source: microsoft.com/en-us/security/b

    Pulse ID: 6a729920ce4597d7b978f0b1
    Pulse Link: otx.alienvault.com/pulse/6a729
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 02:00:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL

  34. CW: 🔞-♂️Character, 🍆Genitals

    Modeling gig for an out of season elf!
    When it's not Christmas, Chris has to fill his time with different jobs 🫪

    #NSFW #NSFWart #Lewd #LewdArt #OC #OriginalCharacter #Elf #Cute #Anime #Hentai #Nudity #MastoArt #ArtistOnMasto #FediArt #ArtOnFedi #drawing #Erotic #PinUp

  35. Toy Ghouls’ new toy: the GenieLocker ransomware

    GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

    Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
    Pulse Link: otx.alienvault.com/pulse/6a6b1
    Pulse Author: AlienVault
    Created: 2026-07-30 09:41:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault

  36. Toy Ghouls’ new toy: the GenieLocker ransomware

    GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

    Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
    Pulse Link: otx.alienvault.com/pulse/6a6b1
    Pulse Author: AlienVault
    Created: 2026-07-30 09:41:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault

  37. XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens

    In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication.

    Pulse ID: 6a6b24fc4e9307c078956d75
    Pulse Link: otx.alienvault.com/pulse/6a6b2
    Pulse Author: AlienVault
    Created: 2026-07-30 10:18:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoMining #CyberSecurity #ELF #Encryption #InfoSec #Linux #OTX #OpenThreatExchange #RAT #Rust #bot #AlienVault

  38. Princesse elfe, préparatifs pour l'#aquarelle : recherches de teintes de peau, et application de masque au drawing gum sur des zones à protéger.
    Vous aimez ? Aidez : fr.tipeee.com/bruno-bellamy !
    #art #illustration #WIP #bellaminette #elf #costume #cosplay @tipeee_officiel

  39. Shai-Hulud-Style npm Worm Hits

    Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.

    Pulse ID: 6a69c0698ac8620efa23e8f6
    Pulse Link: otx.alienvault.com/pulse/6a69c
    Pulse Author: AlienVault
    Created: 2026-07-29 08:57:13

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Cloud #CyberSecurity #ELF #Endpoint #GitHub #InfoSec #Mimic #NPM #OTX #OpenThreatExchange #Worm #bot #AlienVault