A compromised Jscrambler npm package containing infostealer malware was distributed by attackers in the npm registry and downloaded nearly 1,500 times.
GigaWiper is a modular backdoor with espionage and data destruction capabilities that abuses legitimate enterprise protocols for command and control communication, making it difficult to detect in typical corporate environments.
GigaWiper combines three known malware families (Crucio, FlockWiper) in a modular backdoor with 20 commands to delete or encrypt data after reconnaissance objectives are achieved.
TencShell backdoor obfuscates C2 traffic as Tencent API requests to evade detection and enables remote access, data theft, and lateral network movement.