Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Fake AI Tools Deliver Infostealer

0
Medium
Published: 08/04/2026 (08/04/2026, 18:21:01 UTC)
Source: AlienVault OTX General

Description

In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 11:29:05 UTC

Technical Analysis

In April 2026, a NodeJS infostealer campaign evolved its delivery by cloning legitimate AI-related GitHub repositories and embedding malicious payloads targeting developers and AI users. The campaign uses SmartLoader in a redundant two-stage loader chain, with both stages employing EtherHiding to resolve C2 addresses dynamically from Polygon blockchain smart contracts, allowing operators to update implant targets without modifying code. The first stage loader uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers, including previously documented NodeJS variants, targeting developers' elevated privileges.

Potential Impact

The campaign enables attackers to steal sensitive information from targeted developers and AI users, potentially compromising credentials and other data with elevated privileges. The use of blockchain-based dynamic C2 resolution complicates detection and mitigation. The targeting of financial services, banking, and technology sectors increases the risk of significant data breaches and operational disruptions in critical industries.

Defensive Guidance

No official patch or remediation is indicated for this campaign. Organizations should be aware of the threat of malicious payloads embedded in cloned GitHub repositories, especially those related to AI tools. Mitigation should focus on verifying the authenticity of repositories and tools before use, employing runtime detection for obfuscated loaders, and monitoring for suspicious network activity related to blockchain-based C2 communications. Since this is a Malware-as-a-Service campaign, ongoing vigilance and threat intelligence updates are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.netskope.com/blog/developers-in-the-crosshairs-fake-ai-tools-deliver-infostealer"]
Adversary
null
Pulse Id
6a722d8d66f65b167764ad69
Threat Score
null

Indicators of Compromise

Ip

ValueDescriptionCopy
ip83.97.20.150
CC=RO ASN=AS9009 m247 ltd
ip94.156.154.48
CC=BG ASN=AS8866 bulgarian telecommunications company plc.
ip213.176.72.223
CC=IR ASN=AS1239 sprint

Domain

ValueDescriptionCopy
domainreviewassignment.in
domainyuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion

Hash

ValueDescriptionCopy
hash673570abcb54b368b9521bdff8f331d4
MD5 of 4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875
hash6f2e3a9ec6914209bf85be0677aadf9e
MD5 of b3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65
hash82e81158366a953c33d0720dfe34b95b
MD5 of 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58
hashab5cdef0cde09c4bb0cab33ab0d2f92e
MD5 of 4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb
hashc2a7f19ba96dc460d591d37d664fe6aa
MD5 of 7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9
hash09c42a82aa43d639f519c000123d28409c281c4d
SHA1 of 4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb
hash2e930eb7072ac6f8906c5df11e041d88aaea1fcd
SHA1 of 7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9
hash4b5eee1d2ba5bf3ca0389c0415626634c640a4bd
SHA1 of 04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58
hash6b62b776acccf2316247b31e78804b7ee0999cd0
SHA1 of 4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875
hasheb34adba2c6119def77f408f4e1f7ec6c4cfb783
SHA1 of b3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65
hash04d3c82782927330d56827ff551697666dbab4b3abf5b86bde492efdd142bc58
hash2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4
hash4e0d3da33f13e6440ecbdf4f0b838a164c73ad375c4788c4c205d87f5d2c1875
hash4f4cefa348ed856f075b71449c39ed7734bb21e116186fc4a8f03bea1279e6eb
hash57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b
hash7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9
hashad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc
hashb3a9d5283f982f19979689af2f4416b3e0e57cbf469c71b6275b12fcba358b65
hashf513e3e510970cfec0020d955df8d738a427d471bde49e483d55131826ba8706
hashfc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206
hash0e3d182f6fd64f4b10910d3a19af738e
MD5 of fc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206
hash5ae98c92fdb96b216d628ec633f65281
MD5 of 57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b
hash721a0b232b5456d8c40ef8f850f5be70
MD5 of 2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4
hashd1f0e502ea4e81805ace4fd4cac2447a
MD5 of ad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc
hash777439faf46d5120401e9474a94282de532c8693
SHA1 of ad9da27f72bb7abbfcba92f9302d3467f5487814bb34bbf4b1573abcb56e4efc
hash90b7336963d5ec15ffc86489bed4d6eb18f516d6
SHA1 of fc4494011c094e1046b22489004e5471b766baf51ed9c2c88a431bdecea84206
hashb9f8b42be79c20b34e08fae7b80548d821824617
SHA1 of 2da227ce38dbf8881fe0f6c4f864fcbb7b55dc861d4daf040312cba7e612dac4
hashddefa54547b45c7fc0859fe05a35aa84d2215453
SHA1 of 57646c00b1fab68a1e7205a2b3963ce4a6dc85f1c559b63d02449a51db2c461b

Url

ValueDescriptionCopy
urlhttp://yuhvgbzsa66biqeatbmdvfo5b5jjefcmz5t2vjuvco5qtdkshfpabyid.onion:50051

Threat ID: 6a72fe44bf8831d5399b17ac

Added to database: 08/05/2026, 09:11:32 UTC

Last enriched: 08/05/2026, 11:29:05 UTC

Last updated: 08/05/2026, 18:24:51 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses