logo

The Ultimate Validation: Making a Hacker’s “Do Not Engage” List

ID: e45ca175-3ffa-5b0b-8789-b657df4aaa9d

STIX ID: report--e45ca175-3ffa-5b0b-8789-b657df4aaa9d

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-03-24

Date Updated: 2026-04-28

...
...

Celestial Stealer is a JavaScript infostealer offered as Malware‑as‑a‑Service on Telegram that exfiltrates browser credentials, cookies, saved payment data, and crypto wallets. Trellix's analysis shows the malware uses heavy obfuscation, can be packaged as Electron/NodeJS apps, and employs anti-VM and anti-analysis checks—including a hardcoded list of usernames and computer names (notably Huntress researcher Jai Minton) that cause the malware to self-terminate to avoid analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.