Fake AI Tools Deliver Infostealer
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
AI Analysis
Technical Summary
In April 2026, a NodeJS infostealer campaign evolved its delivery by cloning legitimate AI-related GitHub repositories and embedding malicious payloads targeting developers and AI users. The campaign uses SmartLoader in a redundant two-stage loader chain, with both stages employing EtherHiding to resolve C2 addresses dynamically from Polygon blockchain smart contracts, allowing operators to update implant targets without modifying code. The first stage loader uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers, including previously documented NodeJS variants, targeting developers' elevated privileges.
Potential Impact
The campaign enables attackers to steal sensitive information from targeted developers and AI users, potentially compromising credentials and other data with elevated privileges. The use of blockchain-based dynamic C2 resolution complicates detection and mitigation. The targeting of financial services, banking, and technology sectors increases the risk of significant data breaches and operational disruptions in critical industries.
Mitigation Recommendations
No official patch or remediation is indicated for this campaign. Organizations should be aware of the threat of malicious payloads embedded in cloned GitHub repositories, especially those related to AI tools. Mitigation should focus on verifying the authenticity of repositories and tools before use, employing runtime detection for obfuscated loaders, and monitoring for suspicious network activity related to blockchain-based C2 communications. Since this is a Malware-as-a-Service campaign, ongoing vigilance and threat intelligence updates are recommended.
Indicators of Compromise
- ip: 83.97.20.150
- domain: reviewassignment.in
- domain: yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion
- ip: 94.156.154.48
- hash: 673570abcb54b368b9521bdff8f331d4
- hash: 6f2e3a9ec6914209bf85be0677aadf9e
- hash: 82e81158366a953c33d0720dfe34b95b
- hash: ab5cdef0cde09c4bb0cab33ab0d2f92e
- hash: c2a7f19ba96dc460d591d37d664fe6aa
- hash: 09c42a82aa43d639f519c000123d28409c281c4d
- hash: 2e930eb7072ac6f8906c5df11e041d88aaea1fcd
- hash: 4b5eee1d2ba5bf3ca0389c0415626634c640a4bd
- hash: 6b62b776acccf2316247b31e78804b7ee0999cd0
- hash: eb34adba2c6119def77f408f4e1f7ec6c4cfb783
- hash: 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58
- hash: 2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4
- hash: 4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875
- hash: 4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb
- hash: 57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b
- hash: 7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9
- hash: ad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc
- hash: b3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65
- hash: f513e3e510970cfec0020d955df8d738a427d471bde49e483d55131826ba8706
- hash: fc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206
- ip: 213.176.72.223
- hash: 0e3d182f6fd64f4b10910d3a19af738e
- hash: 5ae98c92fdb96b216d628ec633f65281
- hash: 721a0b232b5456d8c40ef8f850f5be70
- hash: d1f0e502ea4e81805ace4fd4cac2447a
- hash: 777439faf46d5120401e9474a94282de532c8693
- hash: 90b7336963d5ec15ffc86489bed4d6eb18f516d6
- hash: b9f8b42be79c20b34e08fae7b80548d821824617
- hash: ddefa54547b45c7fc0859fe05a35aa84d2215453
- url: http://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051
Fake AI Tools Deliver Infostealer
Description
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In April 2026, a NodeJS infostealer campaign evolved its delivery by cloning legitimate AI-related GitHub repositories and embedding malicious payloads targeting developers and AI users. The campaign uses SmartLoader in a redundant two-stage loader chain, with both stages employing EtherHiding to resolve C2 addresses dynamically from Polygon blockchain smart contracts, allowing operators to update implant targets without modifying code. The first stage loader uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers, including previously documented NodeJS variants, targeting developers' elevated privileges.
Potential Impact
The campaign enables attackers to steal sensitive information from targeted developers and AI users, potentially compromising credentials and other data with elevated privileges. The use of blockchain-based dynamic C2 resolution complicates detection and mitigation. The targeting of financial services, banking, and technology sectors increases the risk of significant data breaches and operational disruptions in critical industries.
Defensive Guidance
No official patch or remediation is indicated for this campaign. Organizations should be aware of the threat of malicious payloads embedded in cloned GitHub repositories, especially those related to AI tools. Mitigation should focus on verifying the authenticity of repositories and tools before use, employing runtime detection for obfuscated loaders, and monitoring for suspicious network activity related to blockchain-based C2 communications. Since this is a Malware-as-a-Service campaign, ongoing vigilance and threat intelligence updates are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer"]
- Adversary
- null
- Pulse Id
- 6a722d8d66f65b167764ad69
- Threat Score
- null
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip83.97.20.150 | CC=RO ASN=AS9009 m247 ltd | |
ip94.156.154.48 | CC=BG ASN=AS8866 bulgarian telecommunications company plc. | |
ip213.176.72.223 | CC=IR ASN=AS1239 sprint |
Domain
| Value | Description | Copy |
|---|---|---|
domainreviewassignment.in | — | |
domainyuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash673570abcb54b368b9521bdff8f331d4 | MD5 of 4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875 | |
hash6f2e3a9ec6914209bf85be0677aadf9e | MD5 of b3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65 | |
hash82e81158366a953c33d0720dfe34b95b | MD5 of 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58 | |
hashab5cdef0cde09c4bb0cab33ab0d2f92e | MD5 of 4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb | |
hashc2a7f19ba96dc460d591d37d664fe6aa | MD5 of 7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9 | |
hash09c42a82aa43d639f519c000123d28409c281c4d | SHA1 of 4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb | |
hash2e930eb7072ac6f8906c5df11e041d88aaea1fcd | SHA1 of 7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9 | |
hash4b5eee1d2ba5bf3ca0389c0415626634c640a4bd | SHA1 of 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58 | |
hash6b62b776acccf2316247b31e78804b7ee0999cd0 | SHA1 of 4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875 | |
hasheb34adba2c6119def77f408f4e1f7ec6c4cfb783 | SHA1 of b3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65 | |
hash04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58 | — | |
hash2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4 | — | |
hash4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875 | — | |
hash4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb | — | |
hash57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b | — | |
hash7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9 | — | |
hashad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc | — | |
hashb3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65 | — | |
hashf513e3e510970cfec0020d955df8d738a427d471bde49e483d55131826ba8706 | — | |
hashfc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206 | — | |
hash0e3d182f6fd64f4b10910d3a19af738e | MD5 of fc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206 | |
hash5ae98c92fdb96b216d628ec633f65281 | MD5 of 57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b | |
hash721a0b232b5456d8c40ef8f850f5be70 | MD5 of 2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4 | |
hashd1f0e502ea4e81805ace4fd4cac2447a | MD5 of ad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc | |
hash777439faf46d5120401e9474a94282de532c8693 | SHA1 of ad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc | |
hash90b7336963d5ec15ffc86489bed4d6eb18f516d6 | SHA1 of fc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206 | |
hashb9f8b42be79c20b34e08fae7b80548d821824617 | SHA1 of 2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4 | |
hashddefa54547b45c7fc0859fe05a35aa84d2215453 | SHA1 of 57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051 | — |
Threat ID: 6a72fe44bf8831d5399b17ac
Added to database: 08/05/2026, 09:11:32 UTC
Last enriched: 08/05/2026, 11:29:05 UTC
Last updated: 08/05/2026, 18:24:51 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.