MALICIOUS (1) campaign cataloged at 2026-09-25(2).
- The campaign has clearly malicious intent, like infostealers.
- This is just the date of creating the catalog entry. It may not reflect the date of creation of the campaign itself.
2026-09-sherpy¶
When used, the package exfiltrates Chrome extension files (likely targeting cryptocurrency wallets) and sensitive Telegram files.
Abuse categories¶
exfiltration_crypto
The package attempts to steal sensitive cryptocurrency-related data, like wallet keys.
infostealer
Activity is typical for information stealers, i.e. by exfiltrate various sensitive data from the victim's environment.
native-extension
The suspicious activity is performed in a native module extension
target:telegram
The package is designed to target Telegram users or the Telegram platform.