Skip to content

MALICIOUS (1) campaign cataloged at 2026-09-25(2).

  1. The campaign has clearly malicious intent, like infostealers.
  2. This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.

2026-09-sherpy

When used, the package exfiltrates Chrome extension files (likely targeting cryptocurrency wallets) and sensitive Telegram files.

Abuse categories

exfiltration_crypto

The package attempts to steal sensitive cryptocurrency-related data, like wallet keys.

infostealer

Activity is typical for information stealers, i.e. by exfiltrate various sensitive data from the victim's environment.

native-extension

The suspicious activity is performed in a native module extension

target:telegram

The package is designed to target Telegram users or the Telegram platform.

Packages in the campaign

campaign:2026-09-sherpy