MALICIOUS (1) campaign cataloged at 2025-08-14(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2025-08-browser-run¶
Package uses the name as popular NPM package (https://www.npmjs.com/package/browser-run), but the only thing it does is adding a hardcoded public SSH key and then calling back. This may allow the threat actor to remotely access the machine.
Abuse categories¶
action-hidden-in-lib-usage
Campaign uses action-hidden-in-lib-usage.
backdoor
Campaign uses backdoor.
dependency-confusion
Campaign uses dependency-confusion.
IoCs & related URLs¶
URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.
-
hxxp://18.144.73.108:3000/add-sshkey
-
18.144.73.108