Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Search: cscript.exe

Search Results: "cscript.exe"

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in multer-orm (npm)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (7fb45c09aa7a237b2b9ff18ccf6426b76a4f46e5ea665c7747f35a345940e161) multer-orm is a typosquat of the widely used `multer` middleware. Its README is copied from multer, but the package adds a load-time dropper in lib/feature.js that fires as soon as any consumer runs `require('multer-orm')`. On Windows the module IIFE auto-invokes a handler that fetches JSON from https://hilbert-self.vercel.app/, extracts a `downloader_url`, downloads the referenced binary into the Chrome User Data directory as `chrome.exe`, marks it executable, and runs it. When the current Node process is not elevated, the code re-spawns itself via `powershell Start-Process node -Verb RunAs -WindowStyle Hidden` to obtain admin rights, then writes a temporary PowerShell script that calls `Add-MpPreference -ExclusionPath` against roughly twenty existing directories (including the Chrome/Edge User Data paths where the payload is dropped), executed via cscript.exe, to disable Windows Defender scanning of the dropper's staging locations. The URLs, PowerShell commands, exclusion strings, and filesystem paths are hidden behind obfuscator.io-style string-array + rotation obfuscation in lib/feature.js. package.json also declares a self-referential dependency on `multer-orm`. Installing or requiring this package results in arbitrary remote code execution on the installer's Windows machine with attempted elevation to admin and antivirus tampering.

Join the discussion

Showing 1 to 1 of 1 result

Filters:cscript.exe
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses