Skip to content

MALICIOUS (1) campaign cataloged at 2026-07-21(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-07-colorstack

The package hides code to download and execute a remote executable from a newly created fastsyncapi[.]com domain. It is disguised as a remote 'fast color helper,' as opposed to the local helper, also included in the code, that only mimics any functionality. The malicious part is not immediately active: to download the binary, a key is required, which was not included in the analyzed versions. The downloaded binary is executed, and at least in one case disguised as 'AppHostRegistrationVerifier'. The package is likely prepared for multi-stage infection, but the trigger code using it was not identified.

Abuse categories

action-hidden-in-lib-usage

The malicious action is hidden in the code and starts when user interacts with it (e.g. during class initialization or by exfiltrating given credentials).

remote_executable

Downloads and executes a remote executable.

URLs with payloads, characteristic domains, C&C IPs, repositories with malicious code, etc.

  • hxxps://www.fastsyncapi.com/v1/update

  • hxxps://www.fastsyncapi.com/v1/colors

  • fastsyncapi.com

Packages in the campaign

campaign:2026-07-colorstack