Threats Tagged 'mal-2026-17322'
View all threats tagged with 'mal-2026-17322'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-17322'
Click on any threat for detailed analysis and mitigation recommendations
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (062ce76699c91a883d24e3ad609bb04faa3f52cbeaecfb24c1c3bcde8b496a5c) Package ships a single ~138 KB browser script whose entire body is an RC4-encrypted base64 blob decoded at runtime by an inline RC4 routine (`_zc`) with a DJB2 helper (`_zh`) and a key reconstructed by XORing a numeric array with 1410^714. Before decryption the script performs anti-analysis guards: a devtools-size heuristic (`if(_gz>160||_gp>160)return;`) that aborts execution when developer tools are open, and a block that overwrites `console.log/info/warn/debug/error` to no-ops to suppress runtime tracing. The package name `contoso-login-sim-loader` self-describes as a 'login sim(ulator) loader' while the published description reframes it as a generic 'Client-side asset loader that renders a self-contained UI component when included via a script tag.' The tarball ships no source, no exports, no dependencies, and no documentation - only the opaque encrypted payload. Any site that follows the include-via-script-tag guidance embeds attacker-controlled JavaScript, decrypted only in end-user browsers, into its own pages; the concealed payload cannot be audited without executing it, and the name plus cover-story description are consistent with a fake-login/credential-harvest overlay served to that site's visitors. Join the discussion | GCVE Database | 09/30/2026, 04:40:31 UTC Added: 09/30/2026, 10:01:01 UTC |
Showing 1 to 1 of 1 result