logo

Say hello to Nextron’s RuneAI

ID: 463b7ec2-5177-587b-bc3f-abd040ad3ac7

STIX ID: report--463b7ec2-5177-587b-bc3f-abd040ad3ac7

Feed Name: Nextron Systems

Threat Score
85/100

Date Published: 2025-12-16

Date Updated: 2026-04-28

Author: Nextron Threat Research Team

...
...

This report analyzes a malicious Node.js package found in an artifact-scanning pipeline that installs a weaponized sqlite DLL, extracts an encrypted stage from an appended JPEG, decrypts and loads a Cobalt Strike beacon, and uses Dropbox links for payload staging and command-and-control (C2) with persistence via the Windows Startup folder; the report provides hashes, active Dropbox URLs, a C2 IP (34.203.197.60:443), and a YARA detection to aid remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.