Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
If the current process has not already set the environment variable __ntw=1, the code attempts to fork the current module in a detached child process, passes __ntw=1 to that child, removes NODE_OPTIONS, ignores standard I/O, and returns control to the parent.
Based on the location, a CLI log is left using post-install script with a message of support for Ukraine...
The archive data path is more layered. The payload builds the tar archive, gzip-compresses it, converts the gzip bytes to base64 text, XORs that text with a SHA-256-derived keystream ... re-encodes the XORed bytes as base64, substitutes the base64 alphabet with a keyed shuffled alphabet, slices the transformed string into 31-character chunks, and hex-encodes each chunk before placing it into DNS labels.
This code that has been added to node-ipc@10.1.1 sets a timer, so that on every pre-configured random interval, of which a node-ipc related code is being called, it also executes a function, to what seems to be, making file system operations.
Examples include ... ~/.azure/accessTokens.json ... ~/.config/gh/hosts.yml ... Microsoft Teams LevelDB files
Local desktop credential stores macOS Keychain databases, Firefox key databases, Linux keyrings, KWallet files, and Microsoft Teams LevelDB files
It collects environment variables, host information, /etc/hosts ... The archive contains: uname.txt: Output from uname -a, when available. etc/hosts: A copy of /etc/hosts, when readable. envs.txt: Sorted environment variables from the process.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.