Recent research details a sophisticated NodeJS malware campaign distributing proxyware apps such as Infatica, Honeygain, earnFM, and PacketLab. The malware leverages obfuscated scripts, scheduled tasks, and malicious Chrome extensions to establish persistence, evade detection, and monetize infected systems by sharing network resources. Command-and-control infrastructure, registry modifications, and credential theft mechanisms are also documented, with extensive IOCs provided for defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
SC Media reported that Formbook malware was being distributed through separate phishing campaigns. This appears to be a distinct development from the Eurasian ComicForm and SectorJ149 activity because the provided content does not indicate they are the same campaign.
Walmart Global Tech researchers published analysis of NodeJS backdoors used to deliver proxyware and other monetization schemes. No separate discovery or campaign date is given in the provided content.
SC Media reported that True World Group was allegedly breached by the Lynx ransomware operation. The available content does not provide a more specific incident date than the article publication date.
The Hacker News reported that ComicForm and SectorJ149 were deploying Formbook malware in cyberattacks targeting Eurasian entities. With no earlier event date stated in the provided content, the report date is used.
SC Media reported a new North Korean ClickFix campaign distributing an updated BeaverTail malware payload. No additional timing details are provided beyond the publication date.
PolySwarm published research on a threat or malware variant it called "HybridPetya." The provided reference includes no further incident details, so the publication itself is the only distinct event that can be established from the content.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemedium.com
Open sourceblog.polyswarm.io
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.