Datadog Security Labs · Crawled Jul 25, 2026
MUT-8694: An NPM and PyPI Malicious Campaign Targeting Windows Users | Datadog Security Labs
12 IoCs
Read original article ↗
AI Summary
MUT-8694 is a persistent threat actor conducting a supply chain attack across both npm and PyPI ecosystems, distributing malicious packages that deliver infostealer malware to Windows users. The campaign uses typosquatting and obfuscated code to distribute Blank Grabber and Skuld Stealer, both open-source infostealers targeting credentials, cryptocurrency wallets, and gaming data. The threat actor leverages legitimate services like GitHub and Replit to host payloads and employs PowerShell-based execution and evasion techniques, including disabling Windows Defender and exfiltrating data via Telegram and Discord.
AI-extracted · verify before operational use
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | worf[.]replit[.]dev | Details → |
| Domain | api[.]telegram[.]org | Details → |
| Domain | discord[.]com | Details → |
| GitHub Repo | holdthatcode/e | Details → |
| Filename | CBLines.exe | Details → |
| Filename | RobloxPlayerLauncher.exe | Details → |
| Filename | cmd.exe | Details → |
| SHA-256 | 9247039186ec01688d19be3ade8e18fa086301145b7c00cc24465147764c63b8 | Details → |
| SHA-256 | 5c4c6ef3aed460f7ea15025bc160768e00c988747b943c99faf9f09b73f86e18 | Details → |
| SHA-256 | b3ce55c72f4e23252235f9698bd6078880ceaca310ba16ee859a5a2d6cc39a92 | Details → |
| Package | larpexodus | Details → |
| Package | nodelogic | Details → |