Threats Tagged 'mal-2026-15901'
View all threats tagged with 'mal-2026-15901'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-15901'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in net-util-y8 (npm) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (d1e81ce327647324756e0ea15d1016d45cd5bb092dd0099418ba2db59eca98a7) The package has no real functionality: index.js contains only an empty comment and package.json declares no exports or lifecycle scripts. The `description` field in package.json is a ~56KB base64 blob that decodes to a ~42KB POSIX shell script implementing an XMRig Monero miner dropper. The decoded script preflights curl/wget/openssl and perl (installing them via the system package manager with root privileges if missing), fetches XMRig binaries from gitlab.com/albertotrindade131/al and a ghfast.top proxy in front of github.com/lucas77335/xmrig-amd releases, points the miner at the pool xmr.kryptex.network:8029 with a hardcoded Monero wallet address (883kAB7Ufo...gBCFH), and includes routines to kill competing miners and mask its process name. The script also references a sibling package `net-util-x7` and a registry-latest lookup at registry.npmjs.org/cbc97b7a/latest, indicating this is a staging component of a multi-package cryptomining campaign. Encoding an executable payload inside the manifest `description` field is a smuggling technique to keep the payload off code-scanning paths while still shipping it in the published tarball. Join the discussion | GCVE Database | 09/04/2026, 03:46:33 UTC Added: 09/04/2026, 14:25:49 UTC |
Showing 1 to 1 of 1 result