Threats Tagged 'mal-2026-13413'
View all threats tagged with 'mal-2026-13413'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-13413'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in @astralcore/aura-wb (npm) 0 The npm package @astralcore/aura-wb is a WhatsApp bot that contains malicious code which exfiltrates sensitive WhatsApp session credentials to a hardcoded, author-controlled MongoDB Atlas cluster. The package writes full WhatsApp credentials and signal keys to this shared database, allowing the author or anyone with access to the database to fully control the installer's WhatsApp account. Additionally, the package polls the shared database to receive commands that can manipulate the installer's WhatsApp session to follow, react to, or read arbitrary channels. The package also sends host environment information to a hardcoded Telegram chat ID, providing the author with deployment notifications. A Google Tenor API key is embedded as well. The affected versions are 1.0.0, 1.0.1, and 1.0.4. No patch or remediation information is provided. Join the discussion | GCVE Database | 08/06/2026, 13:41:12 UTC Added: 08/06/2026, 18:16:44 UTC |
Showing 1 to 1 of 1 result