G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload
ID: c599d79f-019d-5f5d-8286-8343206ec800
STIX ID: report--c599d79f-019d-5f5d-8286-8343206ec800
Feed Name: cybersecurityNews.com
Security researchers discovered that the npm package "ansi-universal-ui" was a malicious supply-chain dropper for G_Wagon, a multi-stage Python information stealer that uses postinstall hooks to fetch and execute obfuscated payloads in memory, injects a DLL into browser processes to harvest credentials, crypto wallets, cloud tokens and messaging tokens, and exfiltrates data to attacker-controlled Appwrite buckets; the actor rapidly published multiple package versions (1.3.5–1.4.1) with increasing obfuscation and anti-forensics to evade detection, and victims are advised to remove affected package versions and rotate/revoke credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
