Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "mshta.exe"
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in gptlite (npm) 0 The npm package 'gptlite' version 4.0.8 contains malicious code in its preinstall lifecycle script. This script executes a Windows command that uses mshta.exe to fetch and run attacker-controlled code from an unauthenticated HTTP source (fixars.top) during installation. This results in arbitrary code execution on the installer's machine without user review. Join the discussion | GCVE Database | 07/13/2026, 17:38:10 UTC Added: 07/14/2026, 09:22:00 UTC |
Update on Attacks by Threat Group APT-C-60 in 2026 0 APT-C-60 continues targeting organizations in Japan with evolved tactics observed throughout 2026. The threat group employs spear-phishing emails containing Proton Drive links or direct attachments with RAR archives. Victims extract LNK files that execute JavaScript via mshta.exe, leading to multi-stage payload delivery. The attackers abuse legitimate services including GitHub, GitLab, jsDelivr, and Codeberg as infrastructure for hosting malicious components. Git.exe is leveraged to execute scripts that deploy downloaders and loaders, ultimately delivering SpyGlace malware versions 3.1.15 through 3.1.18. The attack chain involves multiple obfuscated JavaScript files and persistence mechanisms similar to previous campaigns. By utilizing developer-oriented services and CDNs commonly allowed in corporate environments, the threat actor attempts to evade detection and blend malicious traffic with legitimate communications. Join the discussion | AlienVault OTX General | 07/13/2026, 12:54:54 UTC Added: 07/13/2026, 21:02:35 UTC |
Malicious code in gptcore (npm) 0 The gptcore npm package versions 4.0.6, 4.0.7, and 4.0.8 include a malicious preinstall script that executes a Windows command to launch mshta.exe and fetch code from an untrusted remote HTTP URL. This causes arbitrary HTA/JScript content from the remote host to run on the installer's machine during npm install. The remote content is unrelated to the package's documented purpose and is fetched without integrity verification or publisher trust. Join the discussion | GCVE Database | 07/12/2026, 20:45:48 UTC Added: 07/13/2026, 09:21:11 UTC |
Malicious code in minigptcore (npm) 0 The minigptcore npm package version 4.0.8 contains malicious code that executes during installation. Its preinstall script runs a Windows command to invoke mshta.exe, which fetches and executes an unverified HTA script from an external HTTP domain. This behavior allows remote code execution with the privileges of the user running npm install. The package metadata is minimal and generic, indicating a likely throwaway malicious upload. Join the discussion | GCVE Database | 07/13/2026, 06:54:44 UTC Added: 07/13/2026, 09:19:24 UTC |
Malicious code in testpgagent (PyPI) 0 The TestPGAgent PyPI package versions 0.1 and 0.2 contain malicious code that executes during installation. The setup.py script uses base64-encoded obfuscated code to launch Windows mshta.exe to fetch and run a remote HTML application from an attacker-controlled HTTP server. This allows arbitrary code execution on any Windows machine installing these package versions. The malicious payload is unpinned, mutable, and unrelated to the declared publisher, indicating clear malicious intent. Join the discussion | GCVE Database | 06/15/2026, 17:24:46 UTC Added: 07/09/2026, 09:39:43 UTC |
Showing 1 to 5 of 5 results