npm Package Caught Stealing Crypto Browser Extension Data
Tags
Common Information
Type | Value |
---|---|
UUID | 007a9ddc-6b1b-448e-a8a2-6aedeabd0d8e |
Fingerprint | 2604be63a9a506d4 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 5, 2024, midnight |
Added to db | Aug. 31, 2024, 1:12 a.m. |
Last updated | Nov. 17, 2024, 5:55 p.m. |
Headline | npm Package Caught Stealing Crypto Browser Extension Data |
Title | npm Package Caught Stealing Crypto Browser Extension Data |
Detected Hints/Tags/Attributes | 41/1/17 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.phylum.io/npm-package-caught-exfiltrating-crypto/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 46 | ✔ | Phylum | https://blog.phylum.io/rss/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 28 | date.now |
|
Details | Domain | 70 | crypto.com |
|
Details | Domain | 1 | dfeb-66-154-105-3.ngrok-free.app |
|
Details | Domain | 1 | couchdb.dev.dataunion.app |
|
Details | File | 156 | package.json |
|
Details | File | 174 | index.js |
|
Details | File | 1 | launch.js |
|
Details | File | 1 | 'setup-script.js |
|
Details | File | 1 | setup-script.js |
|
Details | File | 2 | filepath.inc |
|
Details | File | 2 | id.json |
|
Details | File | 65 | python.exe |
|
Details | File | 1 | setup-scripts.js |
|
Details | File | 1 | setup-setup.js |
|
Details | File | 1 | dev.dat |
|
Details | Url | 1 | https://dfeb-66-154-105-3.ngrok-free.app/api/upload |
|
Details | Url | 1 | https://dfeb-66-154-105-3.ngrok-free.app/api/node |