Threats Tagged 'mal-2026-6723'
View all threats tagged with 'mal-2026-6723'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-6723'
Click on any threat for detailed analysis and mitigation recommendations
The electron-orbit npm package contains malicious code that activates when required in Node.js environments. It establishes a covert network connection using a custom TLS 1.3 implementation to an Azure blob storage endpoint, bypassing standard TLS interception and static inspection. The package collects environment variables related to PATH and the current working directory, sending this data encoded in the request URL to the attacker-controlled server. Activation is conditional, triggered only when a specific environment variable's SHA-256 hash matches a hardcoded value, allowing targeted execution in chosen environments such as CI pipelines. The package's advertised functionality is a pretext; it does not perform legitimate icon fetching or SVG rendering as claimed. Join the discussion | GCVE Database | 07/01/2026, 21:15:10 UTC Added: 07/02/2026, 22:58:30 UTC |
Showing 1 to 1 of 1 result