Datadog Security Labs · Crawled Jul 25, 2026

MUT-8694: An NPM and PyPI Malicious Campaign Targeting Windows Users | Datadog Security Labs

12 IoCs
Read original article ↗

AI Summary

MUT-8694 is a persistent threat actor conducting a supply chain attack across both npm and PyPI ecosystems, distributing malicious packages that deliver infostealer malware to Windows users. The campaign uses typosquatting and obfuscated code to distribute Blank Grabber and Skuld Stealer, both open-source infostealers targeting credentials, cryptocurrency wallets, and gaming data. The threat actor leverages legitimate services like GitHub and Replit to host payloads and employs PowerShell-based execution and evasion techniques, including disabling Windows Defender and exfiltrating data via Telegram and Discord.

AI-extracted · verify before operational use

Indicators of Compromise 12 extracted

Type Value Detail
Domain worf[.]replit[.]dev Details →
Domain api[.]telegram[.]org Details →
Domain discord[.]com Details →
GitHub Repo holdthatcode/e Details →
Filename CBLines.exe Details →
Filename RobloxPlayerLauncher.exe Details →
Filename cmd.exe Details →
SHA-256 9247039186ec01688d19be3ade8e18fa086301145b7c00cc24465147764c63b8 Details →
SHA-256 5c4c6ef3aed460f7ea15025bc160768e00c988747b943c99faf9f09b73f86e18 Details →
SHA-256 b3ce55c72f4e23252235f9698bd6078880ceaca310ba16ee859a5a2d6cc39a92 Details →
Package larpexodus Details →
Package nodelogic Details →