“G_Wagon” Malware Hides in Fake NPM UI Library to Steal Cloud Keys
ID: f4a250b9-f57a-59ac-ac9b-dd439dffeada
STIX ID: report--f4a250b9-f57a-59ac-ac9b-dd439dffeada
Feed Name: securityonline.info
**Executive Summary:** The report describes discovery of a malicious npm package, ansi-universal-ui, which distributes a sophisticated infostealer called G_Wagon that downloads its own Python runtime, decrypts and injects a Windows DLL into browsers, and exfiltrates browser-stored passwords, crypto wallets, cloud credentials, and Discord tokens to an Appwrite bucket; the actors published 10 versions across two days while rapidly adding C2 and full payload functionality, and the report urges immediate remediation (remove package/node_modules, check for a .agwagon_status file, and rotate credentials).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
