Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
HackBrowserData
Malware
HackBrowserData
Browser information stealer, written in Go.
Indicators of Compromise
1
Filename
NodeJS/sync.js
MITRE ATT&CK TTPs
6
T1027
Obfuscated Files or Information
Defense Evasion
T1059.001
PowerShell
Execution
T1071
Application Layer Protocol
Command And Control
T1195.001
Compromise Software Dependencies and Development Tools
Initial Access
T1496
Resource Hijacking
Impact
T1566
Phishing
Initial Access
Source Articles
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI npm packages were published in a supply-chain attack that delivered a credential-stealing remote access trojan. The attacker compromised GitHub repositories via a misconfigured CI/CD pipeline, leveraging legitimate workflows to publish trojanized packages with valid SLSA attestations. The malware, which resembles the Miasma backdoor, steals credentials, tokens, browser data, and other sensitive information, and communicates via HTTP, Nostr, Ethereum smart contracts, and libp2p. The exposure window lasted about four hours on July 14, 2026, and although the packages have been removed, existing installations may still be compromised.
bleeping-computer
·
1w ago