Threats Tagged 'mal-2026-15811'
View all threats tagged with 'mal-2026-15811'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-15811'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in syswatch (PyPI) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (740c9125f18d68081f742b3316d07c54727fb4aab5555a398c0c04e31ba9bb54) Importing syswatch starts a background thread that, on Windows, fetches a JSON manifest from https://github-repo.up.railway.app/vbv_a8F3kL92xQ/manifest.json, downloads the executable referenced by manifest.update_url to a temp path, and runs it silently with NSIS-style flags (/S /NCRC). The endpoint URL is stored as base64 fragments concatenated at runtime (_FRAGMENTS + _decode in _monitor.py), and TLS verification is explicitly disabled for both manifest and payload fetches (check_hostname=False, verify_mode=CERT_NONE). After execution the code launches a ServiceHelperUtility.exe helper and calls `wevtutil cl Application` and `wevtutil cl System` from _cleanup() to erase Windows event logs. The host github-repo.up.railway.app is a Railway-hosted lookalike of GitHub, not a GitHub-owned domain. The package advertises itself as a system-monitoring library; none of the fetch, execute, or event-log clearing behavior is disclosed. ## Source: kam193 (e01fd8b85a9d6bdfbefb70261f49496f8a6c224d98da6400ef0ca06f18404d27) During import, malicious code is started in the background. On Windows, it downloads and installs a malicious executable, and disguises it as a system utility. After installation, the code attempts to cover its tracks by cleaning logs and removing downloaded files. The installed executable is a heavily obfuscated malware with multiple sandbox evasion techniques, finally running an infostealer identifying itself as "Snow Stealer". It collects at least browser data and modifies cryptowallet applications. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-envprovision Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable. - obfuscation - action-hidden-in-lib-usage - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment. - exfiltration-crypto - malware - covering-tracks - persistence Join the discussion | GCVE Database | 09/01/2026, 21:27:36 UTC Added: 09/02/2026, 15:48:51 UTC |
Showing 1 to 1 of 1 result