Researchers reported that threat actors are distributing the Rust-based infostealer NWHStealer through a new infection chain built around the Bun JavaScript runtime, using fake game cheats, software cracks, and installers packaged in ZIP archives. The lures have been hosted on legitimate services including GitHub, GitLab, SourceForge, and Itch.io, helping the malware blend in with normal downloads and increasing the likelihood of user execution.
The Bun-based loader contains obfuscated JavaScript, performs anti-virtualization checks, gathers host and public IP data, captures screenshots, and communicates with encrypted command-and-control infrastructure before retrieving an encrypted next-stage payload. In some cases, a fallback loader named dw.exe is included to preserve delivery if the primary chain fails. The final payload observed was NWHStealer, which can steal browser credentials, cryptocurrency wallet data, Discord and Steam information, FTP client data, and other system details, while also establishing persistence, bypassing UAC, and obtaining updated C2 addresses through Telegram.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes published analysis describing the Bun-based loader, fallback loader behavior, host reconnaissance, screenshot capture, C2 communications, and final deployment of NWHStealer. The report also noted hosting on legitimate platforms such as GitHub, GitLab, SourceForge, and Itch.io and detailed the stealer's ability to exfiltrate browser, wallet, messaging, and FTP data.
Researchers reported that attackers began distributing the Rust-based infostealer NWHStealer through fake software downloads, game cheats, cracks, and installers in ZIP archives. The new infection chain uses the Bun JavaScript runtime to package and execute an obfuscated loader with anti-VM checks, encrypted C2 communications, and in-memory deployment of the next-stage payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.