#elf — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #elf, aggregated by home.social.
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
Striking gold: Inside the GoldDigger Android malware
GoldDigger is a sophisticated Android banking trojan that primarily targets mobile banking users in South Africa and across Europe, with evidence suggesting plans for global expansion. The malware employs advanced evasion techniques including a custom packer called 'dpt-shell', anti-debugging mechanisms, and Frida detection. It disguises itself as legitimate airline and shopping applications to deceive victims. GoldDigger exploits Android Accessibility services to perform on-device fraud, steal credentials, intercept SMS-based two-factor authentication, and execute unauthorized transactions. A unique feature is its ability to run targeted banking applications in a virtual environment, allowing complete interception of API calls and runtime behavior. The malware maintains communication with command-and-control servers via encrypted WebSocket protocol, enabling capabilities including screen recording, audio capture, phishing overlays, and remote device manipulation.
Pulse ID: 6a7c732c803c76b919db7963
Pulse Link: https://otx.alienvault.com/pulse/6a7c732c803c76b919db7963
Pulse Author: AlienVault
Created: 2026-08-12 13:20:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #Android #Bank #BankingTrojan #CyberSecurity #ELF #Europe #GoldDigger #InfoSec #Malware #MobileBanking #OTX #OpenThreatExchange #Phishing #RCE #SMS #Trojan #bot #AlienVault
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
Tracking Shai-Hulud: Inside the ChainDrop NPM Worm
On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.
Pulse ID: 6a7bdb4167c384aad06f1253
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb4167c384aad06f1253
Pulse Author: AlienVault
Created: 2026-08-12 02:32:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Pulse ID: 6a7bf84d462efb3893c6dd40
Pulse Link: https://otx.alienvault.com/pulse/6a7bf84d462efb3893c6dd40
Pulse Author: Tr1sa111
Created: 2026-08-12 04:36:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Pulse ID: 6a7bf84d462efb3893c6dd40
Pulse Link: https://otx.alienvault.com/pulse/6a7bf84d462efb3893c6dd40
Pulse Author: Tr1sa111
Created: 2026-08-12 04:36:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #SupplyChain #Worm #bot #Tr1sa111
-
Ice like Petals
More style experimentation stuff.
#MakioArt #MastoArt #ocArt #OC #OriginalCharacter #digitalArt #Elf #Eladrin #FantasyArt #TTRPGCharacter #TTRPGArt
-
Ice like Petals
More style experimentation stuff.
#MakioArt #MastoArt #ocArt #OC #OriginalCharacter #digitalArt #Elf #Eladrin #FantasyArt #TTRPGCharacter #TTRPGArt
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
Pulse ID: 6a7b39b0e4765559a182c347
Pulse Link: https://otx.alienvault.com/pulse/6a7b39b0e4765559a182c347
Pulse Author: AlienVault
Created: 2026-08-11 15:03:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault
-
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
A large-scale software supply chain attack compromised over 400 npm packages through a self-propagating worm called ChainDrop, a new variant of Mini Shai-Hulud. The campaign exploits stolen npm publishing credentials to automatically modify and republish legitimate software releases. ChainDrop targets developer workstations and CI/CD environments, harvesting credentials from npm, GitHub, AWS, Kubernetes, and HashiCorp Vault before validating access and enumerating resources. The malware uses preinstall lifecycle scripts for automatic execution, establishes persistence through repository configuration modifications, and abuses GitHub Actions OIDC trusted publishing workflows. After stealing credentials, it autonomously propagates by downloading packages, inserting malicious payloads, and republishing them with incremented versions, demonstrating how compromised developer identities can enable widespread ecosystem compromise.
Pulse ID: 6a7b39b0e4765559a182c347
Pulse Link: https://otx.alienvault.com/pulse/6a7b39b0e4765559a182c347
Pulse Author: AlienVault
Created: 2026-08-11 15:03:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #RCE #Rust #SupplyChain #Worm #bot #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
Inside a Self-Propagating npm Worm
Pulse ID: 6a7951d7e4e9679263bf13be
Pulse Link: https://otx.alienvault.com/pulse/6a7951d7e4e9679263bf13be
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
Inside a Self-Propagating npm Worm
Pulse ID: 6a7951d7e4e9679263bf13be
Pulse Link: https://otx.alienvault.com/pulse/6a7951d7e4e9679263bf13be
Pulse Author: Tr1sa111
Created: 2026-08-10 04:21:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #InfoSec #NPM #OTX #OpenThreatExchange #Worm #bot #Tr1sa111
-
CW: Sexually suggestive
-
В заголовке моего ELF есть точка входа. Оказалось, её никто не читает
Три статьи я собирал файл и отдавал его эмулятору, ни разу в него не заглянув. Заглянул. Внутри два разных описания одних и тех же байтов, ответ на вопрос, откуда взялся адрес 0x80000000, и поле, которое я заполнял зря. Ну, открываем!
https://habr.com/ru/articles/1068276/
#RISCV #QEMU #bare_metal #ассембле #ELF #компоновщик #линкерскрипт #точка_входа #сегменты_и_секци
-
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Pulse ID: 6a75b2f415506d0a2374398b
Pulse Link: https://otx.alienvault.com/pulse/6a75b2f415506d0a2374398b
Pulse Author: AlienVault
Created: 2026-08-07 10:27:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault
-
Inside a Self-Propagating npm Worm
A self-propagating npm worm dubbed ChainDrop infected over 400 packages downloaded hundreds of millions of times weekly, including popular packages like keyv and cacheable-request. The worm steals cloud credentials, npm and GitHub tokens, SSH keys, and sensitive developer data while extracting temporary credentials from GitHub Actions runner memory. It uses stolen npm publishing tokens to infect additional packages while maintaining their legitimate functionality. The attackers established persistence through VS Code and Claude Code configurations, employed blockchain-based command-and-control resolution via Ethereum smart contracts, and can execute attacker-supplied code. The operator demonstrated ability to silently reconfigure C2 infrastructure through Ethereum transactions without updating deployed instances. ChainDrop employs three layers of obfuscation and encryption, exfiltrates data through encrypted channels, and publishes stolen tokens in public commit messages.
Pulse ID: 6a75b2f415506d0a2374398b
Pulse Link: https://otx.alienvault.com/pulse/6a75b2f415506d0a2374398b
Pulse Author: AlienVault
Created: 2026-08-07 10:27:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #Encryption #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #RAT #SSH #Worm #bot #AlienVault
-
ChainDrop: Inside a Self-Propagating npm Worm
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a751f2c22e68481012c2e2d
Pulse Link: https://otx.alienvault.com/pulse/6a751f2c22e68481012c2e2d
Pulse Author: CyberHunter_NL
Created: 2026-08-06 23:56:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
ChainDrop: Inside a Self-Propagating npm Worm
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Pulse ID: 6a751f2c22e68481012c2e2d
Pulse Link: https://otx.alienvault.com/pulse/6a751f2c22e68481012c2e2d
Pulse Author: CyberHunter_NL
Created: 2026-08-06 23:56:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #NPM #OTX #OpenThreatExchange #RCE #Worm #bot #CyberHunter_NL
-
ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Pulse ID: 6a7484b807f5882281629fae
Pulse Link: https://otx.alienvault.com/pulse/6a7484b807f5882281629fae
Pulse Author: AlienVault
Created: 2026-08-06 12:57:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault
-
ChainDrop npm Attack Compromises Hundreds of Packages
A sophisticated software supply chain attack named ChainDrop has infected hundreds of npm packages, including popular caching libraries with millions of weekly downloads. Beginning August 4, 2026, attackers compromised a GitHub account of a keyv package maintainer, injecting malicious code into legitimate repositories. The malware executes credential-stealing payloads targeting developer workstations and CI/CD runners, harvesting npm tokens, GitHub credentials, cloud access keys, SSH keys, and database credentials. Using stolen credentials, the worm self-propagates by compromising additional repositories and publishing poisoned packages with valid provenance attestations. ChainDrop employs Bun runtime for execution, establishes persistence through developer tool configurations, and exfiltrates encrypted data using blockchain-based command-and-control infrastructure. This campaign represents an evolution of the Shai-Hulud npm worm.
Pulse ID: 6a7484b807f5882281629fae
Pulse Link: https://otx.alienvault.com/pulse/6a7484b807f5882281629fae
Pulse Author: AlienVault
Created: 2026-08-06 12:57:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SSH #SupplyChain #Worm #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Major Shai Hulud campaign strikes npm again, affecting keyv and 400+ packages
A sophisticated supply-chain attack campaign named Shai-Hulud has compromised over 400 npm packages across 1700+ versions, beginning with keyv and cacheable libraries. The malware operates as a self-propagating worm that collects credentials from local filesystems, CI/CD environments, cloud platforms, Kubernetes clusters, and HashiCorp Vault. It exfiltrates stolen data through dynamic HTTPS endpoints or public GitHub repositories, then uses compromised npm tokens to publish infected versions of all writable packages. The campaign also injects execution hooks into GitHub repositories via VS Code and Claude configuration files, harvests GitHub Actions secrets through injected workflows, and includes a targeted attack against npm trusted publishing flows. Command and control infrastructure leverages Ethereum smart contracts and GitHub commit messages for resilience.
Pulse ID: 6a74570cf5cc7a08cd8e9903
Pulse Link: https://otx.alienvault.com/pulse/6a74570cf5cc7a08cd8e9903
Pulse Author: AlienVault
Created: 2026-08-06 09:42:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #ELF #Endpoint #GitHub #HTTP #HTTPS #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Rust #Worm #bot #AlienVault
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
Pulse ID: 6a73cac4902afff959b758aa
Pulse Link: https://otx.alienvault.com/pulse/6a73cac4902afff959b758aa
Pulse Author: AlienVault
Created: 2026-08-05 23:44:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault
-
Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages
On August 4, 2026, a sophisticated supply chain attack compromised the keyv npm package maintainer, deploying CHAINDROP, a self-propagating worm that automatically backdoors packages using stolen npm credentials. Over 400 npm packages were infected, affecting more than 1.3 billion monthly downloads. The worm executes via preinstall hooks, deploys across Linux, macOS, and Windows platforms, and harvests credentials from over 300 patterns targeting AI tooling, cloud providers, GitHub tokens, and npm credentials. CHAINDROP uses Ethereum smart contracts for C2 resolution and propagates by publishing trojanized versions of packages the compromised maintainer can access. The payload is heavily obfuscated and contains Dune-themed references consistent with previous Shai-Hulud campaigns.
Pulse ID: 6a73cac4902afff959b758aa
Pulse Link: https://otx.alienvault.com/pulse/6a73cac4902afff959b758aa
Pulse Author: AlienVault
Created: 2026-08-05 23:44:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Linux #Mac #MacOS #NPM #OTX #OpenThreatExchange #SupplyChain #Trojan #Windows #Worm #bot #AlienVault
-
CW: Sexually suggestive
How to see Zelda uncensored
👇👇👇👇👇👇👇👇👇
Ca$happ: jennalovely77
Venm0: caterwauler333
#zelda #loz #elf #elflover #elvesgonewild #fantasy #nsfw #eatitfromtheback
RE: https://bsky.app/profile/did:plc:f3dcsz365o4zyt7uuqyliwgt/post/3mseukf3u322u -
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.
Pulse ID: 6a72f10a39d4c128ee7e2fa8
Pulse Link: https://otx.alienvault.com/pulse/6a72f10a39d4c128ee7e2fa8
Pulse Author: AlienVault
Created: 2026-08-05 08:15:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault
-
Supply Chain Compromise Affecting keyv and cacheable npm Packages
An active supply chain attack has compromised the keyv and cacheable npm packages, affecting tens of millions of weekly downloads. On August 4, 2026, at least ten packages were published with malicious preinstall hooks that download a Bun runtime and execute obfuscated payloads. The attack began with the compromise of maintainer account Jaredwray, enabling the threat actor to inject malicious code across multiple package families. The malware harvests cloud and CI credentials from AWS, GCP, Azure, HashiCorp Vault, Kubernetes, GitHub Actions, and npm tokens. It self-propagates by repackaging other npm packages with the same malicious hook and republishing them using stolen npm tokens. Stolen credentials are exfiltrated to threat actor-controlled GitHub repositories, with persistence mechanisms planted in developer directories.
Pulse ID: 6a72f10a39d4c128ee7e2fa8
Pulse Link: https://otx.alienvault.com/pulse/6a72f10a39d4c128ee7e2fa8
Pulse Author: AlienVault
Created: 2026-08-05 08:15:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #ELF #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #SMS #SupplyChain #Troll #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
ChainDrop: The Mini Shai Hulud npm worm's latest wave hits keyv and cacheable
Attackers compromised a GitHub maintainer account controlling keyv, cacheable, flat-cache, and file-entry-cache Node.js packages that collectively receive over a billion downloads monthly. Malicious code was pushed directly to the main branch and automatically published to npm with valid signatures. A hidden preinstall script downloads a Bun runtime to execute an obfuscated payload that harvests npm, GitHub, AWS, Kubernetes, and Vault credentials, scans for SSH keys and environment files, and exfiltrates data to attacker-controlled GitHub repositories and Ethereum smart contracts. The worm then uses stolen npm tokens to infect additional packages autonomously. This self-propagating attack, tracked as ChainDrop, belongs to the Shai Hulud family responsible for previous campaigns targeting TanStack, Mistral AI, and OpenSearch packages in May 2026.
Pulse ID: 6a72f4367f010bc9d645f5d1
Pulse Link: https://otx.alienvault.com/pulse/6a72f4367f010bc9d645f5d1
Pulse Author: AlienVault
Created: 2026-08-05 08:28:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #ELF #GitHub #InfoSec #NPM #Nodejs #OTX #OpenThreatExchange #RAT #SSH #Troll #Worm #bot #AlienVault
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Indicators extracted from public reporting. Source: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Pulse ID: 6a729920ce4597d7b978f0b1
Pulse Link: https://otx.alienvault.com/pulse/6a729920ce4597d7b978f0b1
Pulse Author: CyberHunter_NL
Created: 2026-08-05 02:00:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL
-
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
Indicators extracted from public reporting. Source: https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Pulse ID: 6a729920ce4597d7b978f0b1
Pulse Link: https://otx.alienvault.com/pulse/6a729920ce4597d7b978f0b1
Pulse Author: CyberHunter_NL
Created: 2026-08-05 02:00:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ELF #HTTP #HTTPS #InfoSec #Microsoft #NATO #OTX #OpenThreatExchange #RCE #SupplyChain #Worm #bot #CyberHunter_NL
-
CW: Suggestive, sexy, partial nudity
I heard it's Bunny Day!
More bunny fun for sale here:
https://lustycomic.itch.io/lusty-easter-pack#BunnyDay #バニーの日 #AuntyBolga #Bolga #elf #bunnysuit #bunnygirl #fantasy
-
CW: Suggestive, sexy, partial nudity
I heard it's Bunny Day!
More bunny fun for sale here:
https://lustycomic.itch.io/lusty-easter-pack#BunnyDay #バニーの日 #AuntyBolga #Bolga #elf #bunnysuit #bunnygirl #fantasy
-
CW: NSFW, GenAI
“Night Elf”
#magic #elf #bigboobs #bigbreasts #boobs #breasts #caption #cleavage #nightelf #nighttime #nightelffemale #elfgirl #elfears #dickgirl #futanari #shemale #stockings #fantasy #warrior #leatherarmor #leather #violetskin #purpleskin #purple #bikini #underwear #xenobiology #fantasybiology #fantasycharacter #horny
-
CW: NSFW, GenAI
“Night Elf”
#magic #elf #bigboobs #bigbreasts #boobs #breasts #caption #cleavage #nightelf #nighttime #nightelffemale #elfgirl #elfears #dickgirl #futanari #shemale #stockings #fantasy #warrior #leatherarmor #leather #violetskin #purpleskin #purple #bikini #underwear #xenobiology #fantasybiology #fantasycharacter #horny
-
CW: 🔞-♂️Character, 🍆Genitals
-
Princesse elfe : aquarelle en cours !
Si vous aimez, aidez (et ne tardez pas, il ne reste que jusqu'à ce soir) : https://fr.tipeee.com/bruno-bellamy !
#art #illustration #bellaminette #aquarelle #cosplay #costume #elf #WIP @tipeee_officiel -
Princesse elfe : aquarelle en cours !
Si vous aimez, aidez (et ne tardez pas, il ne reste que jusqu'à ce soir) : https://fr.tipeee.com/bruno-bellamy !
#art #illustration #bellaminette #aquarelle #cosplay #costume #elf #WIP @tipeee_officiel -
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens
In May 2026, a sophisticated Monero cryptomining campaign was identified targeting Linux environments. Attackers gained initial access through trusted third-party relationships, then escalated to root privileges. Rather than operating openly as root, they weaponized Linux Pluggable Authentication Modules (PAM) to impersonate multiple low-privileged users, creating a forensic smokescreen and establishing redundant persistence through cronjobs. The operators suppressed system logging and deployed a customized XMRig 6.25.0 implant that self-unlinks after execution, running entirely in memory. The binary uses XOR encryption for configuration obfuscation and employs process masquerading to blend with legitimate processes. Campaign tracking revealed operations linked to the V25 Generation 26 family, connecting to the domain unable.download for mining pool communication.
Pulse ID: 6a6b24fc4e9307c078956d75
Pulse Link: https://otx.alienvault.com/pulse/6a6b24fc4e9307c078956d75
Pulse Author: AlienVault
Created: 2026-07-30 10:18:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CryptoMining #CyberSecurity #ELF #Encryption #InfoSec #Linux #OTX #OpenThreatExchange #RAT #Rust #bot #AlienVault
-
Princesse elfe, préparatifs pour l'#aquarelle : recherches de teintes de peau, et application de masque au drawing gum sur des zones à protéger.
Vous aimez ? Aidez : https://fr.tipeee.com/bruno-bellamy !
#art #illustration #WIP #bellaminette #elf #costume #cosplay @tipeee_officiel -
Shai-Hulud-Style npm Worm Hits
Multiple npm packages across @tanstack, @mistralai, @uipath, @squawk, and safe-action namespaces were compromised in a worm-like attack affecting over 50 packages. The malicious code executes during installation, downloading the Bun runtime and running a payload that harvests GitHub credentials and cloud secrets. The attack specifically targets AWS environments by querying the IMDS and attempting privilege escalation through STS and SSM endpoints across multiple regions. Stolen credentials are automatically used to publish additional malicious package versions across different maintainer accounts, creating a self-propagating infection chain. The attack patterns mirror previous Shai-Hulud compromises, using a drop-and-execute technique and command-and-control infrastructure at git-tanstack.com, a domain designed to mimic legitimate tanstack.com traffic. Organizations should rotate GitHub credentials, audit AWS credentials, and check for suspicious activity.
Pulse ID: 6a69c0698ac8620efa23e8f6
Pulse Link: https://otx.alienvault.com/pulse/6a69c0698ac8620efa23e8f6
Pulse Author: AlienVault
Created: 2026-07-29 08:57:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Cloud #CyberSecurity #ELF #Endpoint #GitHub #InfoSec #Mimic #NPM #OTX #OpenThreatExchange #Worm #bot #AlienVault
-
PATRON UDPATE
Lusty and Badru's Date - Some progress!
https://www.patreon.com/danmappart/posts/lusty-and-badrus-165157043