Noodlophile Stealer is a newly identified information-stealing malware. Reported activity indicates it is designed to exfiltrate sensitive data from infected systems. Mentioned distribution methods include phishing emails posing as copyright strikes, described as an evolution from earlier campaigns that abused generative-AI-themed applications. The available content does not provide further high-confidence technical details on payload behavior, persistence, specific data types targeted, victimology, associated threat actors, or indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CTI Roundup: Malicious Python Packages, PipeMagic, Noodlophile Stealer | Tanium
Noodlophile Stealer is an information-stealing malware distributed via phishing emails, designed to steal sensitive data from infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.