logo

“G_Wagon” Malware Hides in Fake NPM UI Library to Steal Cloud Keys

ID: f4a250b9-f57a-59ac-ac9b-dd439dffeada

STIX ID: report--f4a250b9-f57a-59ac-ac9b-dd439dffeada

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** The report describes discovery of a malicious npm package, ansi-universal-ui, which distributes a sophisticated infostealer called G_Wagon that downloads its own Python runtime, decrypts and injects a Windows DLL into browsers, and exfiltrates browser-stored passwords, crypto wallets, cloud credentials, and Discord tokens to an Appwrite bucket; the actors published 10 versions across two days while rapidly adding C2 and full payload functionality, and the report urges immediate remediation (remove package/node_modules, check for a .agwagon_status file, and rotate credentials).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.