Skip to content

MALICIOUS (1) campaign cataloged at 2025-06-15(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2025-06-browser-history-analytics

When starting the server with expected functionality with potentially sensitive content, the package silently sends the location (external IP) to a remote location. If the computer is directly exposed to the Internet, it allows the uploader to get access to the data.

Abuse categories

action-hidden-in-lib-usage

Campaign uses action-hidden-in-lib-usage.

obfuscation

Campaign uses obfuscation.

other

Campaign uses other.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://arpy8-bha-dubious-backend.hf.space/set

  • arpy8-bha-dubious-backend.hf.space

Packages in the campaign

campaign:2025-06-browser-history-analytics