Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'mal-2026-12402'

View all threats tagged with 'mal-2026-12402'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: mal-2026-12402

Threats Tagged 'mal-2026-12402'

Click on any threat for detailed analysis and mitigation recommendations

Malicious code in new-native-tools-linux-x64-gnu (npm)
0

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c713b56fdb956dbd0caaa24969878e04aba9374f65d5fcfb8139771a012ff7cc) The package's only shipped artifact is a 10 MB Linux x86_64 ELF Node addon set as `main` (tools.linux-x64-gnu.node), so it is loaded automatically on `require()`. Extracted strings from the binary contain the exact Chromium Cookies SQLite schema (`FROM cookies`, `DROP INDEX IF EXISTS cookies_unique_index`, `CREATE UNIQUE INDEX cookies_unique_index ON cookies(host_key, top_frame_site_key,...)`) and password-store log lines (`Found login for`, `failed to read:`), consistent with reading Chromium/Chrome/Chromium-derivative Cookies and Login Data stores on the installer host. The same binary embeds a full outbound HTTPS stack (rustls, hyper/ureq) with proxy-environment support (`HTTPS_PROXY`, `HTTP_PROXY`, `ALL_PROXY`) and host-fingerprinting primitives (`gethostname`, `getifaddrs`, `/etc/lsb-release`, `/dev/disk/by-id/`, CPU info, `network_adapters`), plus ZIP + zstd packaging routines suitable for bundling collected data before upload. The exfiltration destination is not present as a plain string and is reconstructed at runtime. Package name mimics the `@napi-rs/*` / `@next/swc-*` platform-binary convention; the README states only "the x86_64-unknown-linux-gnu binary for new-native-tools" and does not disclose any browser-data access or network activity. The version tag `3.1.40-browser-release-151-380-1785161758` includes a unix-epoch-like suffix consistent with automated mass-publication.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: mal-2026-12402
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses