G_Wagon is a multi-stage information stealer delivered via malicious npm packages (notably "ansi-universal-ui") identified by researchers on January 23, 2026. The campaign abuses npm’s postinstall lifecycle hook to execute a Node.js dropper during installation, which downloads a portable Python runtime and then retrieves/executes heavily obfuscated Python payloads from attacker infrastructure hosted on Appwrite. Later iterations reduced disk artifacts by piping the Python payload via stdin and added anti-forensics/cleanup behavior.
Capabilities and targeting (as described):
Platform-specific behavior noted:
Exfiltration and infrastructure:
Infection/affected versions:
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical pre-authentication remote code execution vulnerability, CVE-2025-15467 (CVSS 9.8), affects OpenSSL versions 3.0, 3.3, 3.4, 3.5, and 3.6.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CVE-2025-15467... Threat Details and IOCs Malware: CoolClient, G_Wagon
Python-based information stealer delivered via a malicious npm package; exfiltrates browser credentials, cryptocurrency wallet data, cloud credentials, and Discord tokens to attacker-controlled storage (Appwrite bucket).
A multi-stage, cross-platform infostealer delivered via a malicious npm package (ansi-universal-ui) using a Node.js postinstall dropper to fetch/execute obfuscated Python payloads. It steals browser credentials/cookies/autofill, cryptocurrency wallet extension data, cloud/provider credentials (AWS/Azure/GCP), SSH keys, Kubernetes configs, and various communication/auth tokens, then compresses and exfiltrates the data to attacker-controlled storage. Later variants add Windows in-memory injection using NT native APIs (NtAllocateVirtualMemory, NtCreateThreadEx) and encrypted DLL payloads, and may pipe Python payloads via stdin to reduce disk artifacts.
Multi-stage information stealer delivered via a malicious npm package (ansi-universal-ui). It downloads its own Python runtime, executes heavily obfuscated in-memory Python payloads, injects an embedded Windows DLL into browser processes via native NT APIs, steals browser credentials, crypto wallet data, cloud credentials, and messaging tokens, and exfiltrates data to attacker-controlled Appwrite storage buckets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.