You're Invited: Delivering malware via Google Calendar invites and PUAs
ID: b53f763b-dc3f-531d-b0e5-670a8b74495a
STIX ID: report--b53f763b-dc3f-531d-b0e5-670a8b74495a
Feed Name: Aikido Security's Blog
This report analyzes a malicious npm package, os-info-checker-es6, that concealed an eval-based staged loader using Unicode Private Use Area characters and a small native Rust binary; the loader fetched a base64 payload via a Google Calendar event URL and could execute attacker-supplied code during installation. Several dependent packages were identified that included the malicious package as a dependency, and the author used novel obfuscation techniques that were ultimately decoded to reveal the fetch-and-eval logic; the report provides package IOCs and the Google Calendar bootstrap URL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
