Threats Tagged 'mal-2026-16138'
View all threats tagged with 'mal-2026-16138'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-16138'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (dd840e550f39e1f29f7a50b0cd121c3fa5e78e99954f22009f03b5ac775f91ec) [email protected] declares a postinstall script ("node lib/greensaver.js") that runs automatically on `npm install`. The script decodes two files masquerading as TypeScript sourcemaps (lib/parse.ts.map and lib/init.ts.map) from base64 into sibling JavaScript files (lib/parsetmp.js and lib/config.js), requires the loader, and then unlinks all four files to erase evidence. The loader fetches an AES-CBC-encrypted blob from https://www.jsonkeeper.com/b/V6NBX (an anonymous JSON paste host), decrypts it with the hardcoded password 'myPassword123', and passes the resulting plaintext directly to eval(). The endpoint URL and auth header values are additionally base64-wrapped for a second obfuscation layer. The remainder of the package (scan.js, parse.js, constants.js, utils.js, and the exported makeRe/scan/parse API) is a rename of the picomatch glob-matcher library, providing a cover story for the dropper. The package name and 'Blazing fast and accurate glob matcher' description resemble picomatch. Join the discussion | GCVE Database | 09/11/2026, 22:40:11 UTC Added: 09/12/2026, 00:42:13 UTC |
Showing 1 to 1 of 1 result