G_Wagon NPM Package Exploits Users to Steal Browser Credentials with Obfuscated Payload
ID: 6808ed60-f1b2-534e-9e8b-2ce7bdfe40b9
STIX ID: report--6808ed60-f1b2-534e-9e8b-2ce7bdfe40b9
Feed Name: GBHackers
The report documents a sophisticated supply-chain malware campaign in which an npm package named ansi-universal-ui delivers a Python-based infostealer called G_Wagon; the malware evolved across multiple versions to add anti-forensics, memory-only base64 payload execution, a self-dependency double-run trick, and DLL injection, and it targets browsers, over 100 crypto wallet extensions, cloud credentials, SSH/Kubernetes configs, and messaging tokens, exfiltrating compressed data to Appwrite storage buckets—recommended actions include removing the package, rotating passwords and keys, and invalidating sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
