home.social

#elf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #elf, aggregated by home.social.

fetched live
  1. Does this look Elven to you? I’m making my own version of Elves for my fantasy world Persevera, and I’m starting with their environments.

    #art #illustration #drawing #mastoart #fantasy #conceptart #elf #elves #forest

  2. Does this look Elven to you? I’m making my own version of Elves for my fantasy world Persevera, and I’m starting with their environments.

    #art #illustration #drawing #mastoart #fantasy #conceptart #elf #elves #forest

  3. Does this look Elven to you? I’m making my own version of Elves for my fantasy world Persevera, and I’m starting with their environments.

    #art #illustration #drawing #mastoart #fantasy #conceptart #elf #elves #forest

  4. Does this look Elven to you? I’m making my own version of Elves for my fantasy world Persevera, and I’m starting with their environments.

    #art #illustration #drawing #mastoart #fantasy #conceptart #elf #elves #forest

  5. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  6. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  7. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  8. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  9. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  10. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  11. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  12. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  13. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  14. Striking gold: Inside the GoldDigger Android malware

    GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.

    Pulse ID: 6a7c732c803c76b919db7963
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: AlienVault
    Created: 2026-08-12 13:20:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault

  15. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  16. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  17. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  18. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  19. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  20. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  21. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  22. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  23. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  24. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  25. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  26. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  27. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  28. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111

  29. Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack

    Pulse ID: 6a7bf84d462efb3893c6dd40
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:36:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111