windows-bindgen 0.65.0
biggest blast radius
kernel-hide.rootkitdegrade.calculation
5,639,623 installs
crates
1 hour ago
Fallout
The latest malware caught across open-source registries and marketplaces — evidence included.
Hostile catches · since Aug 1
500
TODAY
Tue Aug 4 · 34 catches · 0 waves · 21 singles
C2 beacon exfiltrating host reconnaissance data
ihldefkgpnceoelikkacpffhabnhfdpm
chrome
12 hours ago
Impersonates Proton VPN with fake servers
IObit Driver Booster contains spyware components
Embedded spyware with keylogger and exfiltration
Obfuscated PowerShell dropper downloading malicious payload
@ruffle-rs/ruffle 0.5.0
javascript
13 hours ago
Satori botnet malware binary
IoT botnet malware with persistence
Contains exploits, persistence, and C2 strings
AI-powered red teaming and exploitation toolkit
AI-powered red teaming and exploitation framework
Purchase Order PO K 0158.js
✓
javascript
7 hours ago
Obfuscated code with dynamic function construction
YESTERDAY
Mon Aug 3 · 207 catches · 2 waves · 34 singles
Obfuscated HTA downloader using ActiveX
Obfuscated HTA downloader using ActiveX
gitlab-labkit 4.0.0
first seen anywhere
credential-theft.registry
51,416,192 installs
ruby
1 day ago
Unsigned DLL with reflection-based resource loader
Extension contacts external auth server
Extension exfiltrates credentials and browsing data
Clipboard hijacking with hardcoded crypto address
pkg:github/retrovibed/retrovibed
trigger.activationdebugger-detect.combined-checks
arch
17 hours ago
Exfiltrates WhatsApp session credentials
ljgghpflkpcigblfoaiclhhebjgpiamj
chrome
19 hours ago
Steals Etsy cookies and CSRF tokens
ahlpigmipbpdeljbnamlkelakjbneijp
chrome
21 hours ago
Automated credential stuffing and login bypass
koru 0.1.445
python
1 day ago
Automation tool executes arbitrary code
Sandbox bypass flags in agent runner
github.com/codyswanngt/lisa v2.323.2-0.20260804004420-2e5f04f9499c+incompatible
install-hook.remote-binaryvalidation.check
go
18 hours ago
npm postinstall fetches remote native executable
github.com/adbc-drivers/driverbase-go/testutil v0.0.0-20260803160758-8f4d5c91c894
credential-theft.env
go
1 day ago
github.com/kdlbs/kandev v0.84.2-0.20260803141219-cc6eb4dd5f62
trojanized.build-pipeline
go
1 day ago
Hostile embedded resource loader detected
Embedded PTY backdoor in Python binary
Malicious DLLs with anti-debug loaders
Mirai botnet malware binary
SUNDAY
Sun Aug 2 · 229 catches · 7 waves · 41 singles
🌊
statist-browser-typed-client-hra.workplacer.events 20.9.1 and 6 siblings
dns.tunnelingdelivery.download-execute
✓
javascript
1 day ago
Dropper downloads and executes native payload
🌊
virussign.com_b51901b8f26384e40cfe0a80ae210fd0.vir and 5 siblings
shellobject.hijackpayload.encrypted
2 days ago
Kawaii-Unicorn VB6 dropper with .die hijack
IoT botnet dropper script
Obfuscated API key in browser extension
Kawaii-Unicorn VB6 dropper with shell hijack
Fake ad blocker, basketball data stealer
🌊
tinkoff-component-page-loader 20.8.2 and 2 siblings
execution.native-binarydns.tunneling
✓
javascript
1 day ago
Trojanized library downloads and executes native payload
tracy/tracy v2.11.0
first seen anywhere
script.dropperexecution.wsh
25,810,817 installs
composer
1 day ago
petgraph 0.8.3
biggest blast radius
trojanized.build-pipeline
443,963,343 installs
crates
2 days ago
Meow Mailer – Free SMTP, Everything Included 0.1.9
meow-mailer
domain.brand-impersonation
2,664 installs
wordpress
2 days ago
Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) 1.1.0
clink-gateway-for-woocommerce
credential-theft.env
163 installs
wordpress
2 days ago
docker.io/longhornio/longhorn-engine v1.11.2-amd64
trojanized.backdoorinterpreter.command
container
2 days ago
Trojanized systemd library with backdoor
Minecraft token stealer with encrypted dropper
Minecraft token stealer with encrypted dropper
Undercat037/aura-emerge v1.32.0
undercat037/aura-emerge
delivery.pipeobfuscation.multi-layer
github
2 days ago
clash-verge-rev/clash-verge-rev v2.5.2-Clash.Verge_2.5.2_aarch64.app
tunnel.proxyload.runtime
github
2 days ago
Exfiltrates data to external domain
Extension downloads and executes native malware
https://github.com/ouijit/ouijit/releases/download/v1.5.0/ouijit-linux-x64.zip
credential-theft.packagetheft.multi-store
arch
1 day ago
Steals crypto seed phrases via exfiltration
Hollow package impersonates legitimate project
Extension exfiltrates browsing data and credentials
CI pipeline fetches and executes remote code
github.com/DataDog/datadog-agent/pkg/util/winutil v0.79.0
trojanize.system-utilitiesregistry.run-key
go
2 days ago
Go shellcode loader with evasion
Go loader with shellcode injection and obfuscation
Packed PE with obfuscated loader
google-closure-compiler-windows 20260730.0.0
loader.native-reflectstaging.encrypted
javascript
2 days ago
Packed PE loader with dynamic API resolution
virussign.com_d8d8d42928290d036a50bc79039b6ae0.vir
shellobject.hijackpe-tampering.corrupted-header
2 days ago
Kawaii-Unicorn trojan with file extension hijack
XMRig cryptojacking malware payload
SATURDAY
Sat Aug 1 · 30 catches · 0 waves · 21 singles
Contains embedded malware dropper scripts
reqwest 0.12.20
615,136,944 installs
crates
2 days ago
https://download.jetbrains.com/toolbox/jetbrains-toolbox-3.6.3.86383.tar.gz
credential.keyloggerformat.structured
arch
2 days ago
https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_150.0.7871.181-1_amd64.deb
domain.brand-impersonationformat.structured
arch
2 days ago
kebafpphjokgalmnacbpokgodbnobbij
chrome
2 days ago
Credential exfiltration to external server
peblippohhgkomkndbnpgbnpfpgolnel
chrome
2 days ago
Embedded archive in extension
Embedded private keys and admin remote control
Web endpoint executes arbitrary shell commands
github.com/DataDog/datadog-agent/pkg/util/winutil v0.82.0-rc.9
trojanize.system-utilitiesregistry.run-key
go
2 days ago
github.com/jomcgi/homelab v0.0.0-20260802011128-98a51c1d7942
reverse-shell.dupautomation.agent
go
2 days ago
DRM framework with anti-debug and obfuscation
Trion RAT malware with exfiltration
That's every sector reporting.
The full stream lives in the index →