logo

DangerousPassword attacks targeting developers’ Windows, macOS, and Linux environments

ID: 4eba504b-ed62-580c-b198-866ebeecd672

STIX ID: report--4eba504b-ed62-580c-b198-866ebeecd672

Feed Name: JPCERT Blog

Threat Score
78/100

Date Published: 2023-07-19

Date Updated: 2026-04-19

Author: 増渕 維摩(Yuma Masubuchi)

...
...

JPCERT/CC reports a targeted campaign by the DangerousPassword (aka CryptoMimic / SnatchCrypto) group that injects malicious code into developer libraries (a Python pyqrcode module and Node.js express files) to deploy downloader/backdoor malware across Windows, macOS, and Linux; the campaign uses obfuscation (ROT13/BASE64), scheduled execution, MSI-based droppers, DLL sideloading, and backdoors (PythonHTTPBackdoor, JokerSpy), and the report provides C2 domains and numerous malware hashes as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.