Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign delivered DEV#POPPER.js (a cross-platform Node.js RAT). The /init bundle's body loader launches the DEV#POPPER RAT and spawns the HashHiding _Z module alongside it.
These were all the Remote Access Trojan (RAT) DEV#POPPER.JS variants which we found in our prior investigation.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“Victim receives a fake job offer via Telegram, pointing to a GitHub repo or trojanized NPM package.”
novel tradecraft such as Cross-Chain TxDataHiding techniques combined with the subsequent creation of a takedown-proof Command and control (C2) infrastructure
a multi-layered attack leveraging novel blockchain-based command-and-control infrastructure
“Chain 1 calls /init on port 443. Chain 2 calls /$/boot on port 80,” while the Ethereum-decoded endpoint is used to “fetches /boot from the decoded C2.”
Mitre ATT&CK Tactic... Command and Control TA0011 Non-Application Layer Protocol T1095
“The malware queries a TRON wallet ... with Aptos as a fallback,” retrieves encrypted JavaScript from BSC transaction calldata, and “_Z scans Ethereum mainnet” through public RPC services.
“The BSC transaction chain ... calls a new /init endpoint on the C2 server,” “/boot returns the dropper,” and the dropper “used [Python] to fetch ... the OmniStealer payload.”
These were all the Remote Access Trojan (RAT) DEV#POPPER.JS variants which we found in our prior investigation.
76 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform Node.js remote-access trojan with full remote-code-execution capability. It includes persistence through VSCode/Cursor IDE injection and is launched by the _B body-loader component.
A JavaScript-based remote access trojan delivered via blockchain transaction data hiding, with multiple variants and rotating C2 IPs used in the campaign.
A cross-platform Node.js/JavaScript remote access trojan and loader that uses cross-chain blockchain transaction data hiding for payload retrieval, provides remote code execution, persistence via VSCode/Cursor IDE injection, telemetry and environment-variable exfiltration, and can fetch additional payloads including a Python stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.