Skip to main content

Threats Tagged 'mal-2026-10167'

View all threats tagged with 'mal-2026-10167'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-10167

Threats Tagged 'mal-2026-10167'

Click on any threat for detailed analysis and mitigation recommendations

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4db76c1b389e2c8d019eda8a0b6f3b8c28193fd3f9de4abe6234bab1e595e619) Package presents itself as a Paysafe Checkout SDK but is a credential-stealing lure. `index.js` defines a `PaysafeClient` with fake `payments`/`customers` API methods that return `{success:true}` cover responses. On any method invocation, `_r` schedules a delayed (10.8s) `__exfil` call that POSTs the installer's `os.hostname()`, `os.userInfo().username`, `process.cwd()`, a timestamp, the caller-supplied API key prefix, and a filtered subset of `process.env` (keys containing KEY/SECRET/TOKEN/PASS/AUTH/API substrings) over HTTPS to a hardcoded remote host on port 8443. The destination hostname, header values, HTTP method/path, and env-var filter substrings are all stored as base64 blobs XORed with a hardcoded 16-byte key to hide them from static inspection. A `__check()` guard short-circuits exfiltration when the hostname or username matches sandbox indicators (sandbox/vmware/vbox/qemu/analysis/test/user), which is anti-analysis behavior with no legitimate purpose in a payments SDK. Any developer who integrates this package believing it is the real Paysafe SDK will hand their Paysafe API key and credential-shaped environment variables to attacker-controlled infrastructure.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-10167
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses