Cross-Platform NPM Stealer, (Fri, May 22nd)

This post was originally published on this site

I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as “extracted-decoded.js” (and reformated). The SHA256 is 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9[1]. It did not run properly in a sandbox so only a static analysis was performed.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.