logo

SmartApeSG Supply Chain Attack Targets Okendo

ID: 778dcac6-743b-5245-9017-f379a89fe616

STIX ID: report--778dcac6-743b-5245-9017-f379a89fe616

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2026-06-25

Date Updated: 2026-07-04

...
...

This technical analysis details SmartApeSG's malicious JavaScript loader injected into a third-party Okendo Reviews script: the loader uses localStorage and User-Agent checks to control execution, reconstructs obfuscated next-stage URLs via XOR decoding of split fragments, generates randomized tokens, and dynamically injects script tags to retrieve follow-on content that leads to fake CAPTCHA/social-engineering prompts, PowerShell/HTA downloaders, and deployment of RATs and information stealers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.