Two separate web payloads were found to contain heavily obfuscated JavaScript, and in one case WebAssembly, designed to collect detailed browser and device telemetry from visitors. The scripts gathered data such as canvas and WebGL fingerprints, browser and platform characteristics, storage and service worker status, permissions, performance metrics, WebRTC-derived local IP information, geolocation status, and error telemetry, then packaged the results into structured records for later processing or transmission.
Embedded logic also pointed to anti-fraud and anti-automation use cases, including anti-debugging checks, bot-detection routines, URL interception, cookie and session handling, hashing with SHA-1 and SHA-256, and checks for incognito mode or tampering. One payload included strings associated with DataDome and a Rust-to-WASM build pipeline, while the other contained anti-fraud checks such as canvas-noise detection and a Buhtrap-related detector, indicating sophisticated client-side tracking and detection capabilities rather than a clearly documented breach or vulnerability event.

See the reporting duties and controls this puts on the clock.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.