Fallout

The latest malware caught across open-source registries and marketplaces — evidence included.

SECTOR SURVEY since Aug 1 ⚛ feed
TODAY Tue Aug 4 · 34 catches · 0 waves · 21 singles
windows-bindgen 0.65.0 biggest blast radius kernel-hide.rootkitdegrade.calculation 5,639,623 installs crates 1 hour ago
25616:thebrain reflection.invokestaging.memory macos 9 hours ago
IObit.DriverBooster brand.productstaging.embedded windows 11 hours ago
IObit Driver Booster contains spyware components
VovSoft.FilenameLister keylog.capture windows 12 hours ago
Embedded spyware with keylogger and exfiltration
SC-816720-PDF1.js script.wshscript.dropper javascript 7 hours ago
Obfuscated PowerShell dropper downloading malicious payload
mips rival-bot.competitorshell.tasking linux 7 hours ago
Satori botnet malware binary
titanjr.arm5 init.bootbotnet.iot linux 7 hours ago
IoT botnet malware with persistence
x86 malformed.elf-headerDirtyfragshellcode.May26 linux 7 hours ago
Contains exploits, persistence, and C2 strings
bingo-ai 7.2.1 reverse-shell.ptyllm.override python 8 hours ago
AI-powered red teaming and exploitation toolkit
bingo-ai 7.2.2 reverse-shell.dupllm.override python 9 hours ago
AI-powered red teaming and exploitation framework
YESTERDAY Mon Aug 3 · 207 catches · 2 waves · 34 singles
🌊 extension-fix-9X2OY8.hta and 10 siblings activex.comhidden.execution 1 day ago
Obfuscated HTA downloader using ActiveX
🌊 extension-fix-RLDATX.hta and 8 siblings activex.comhidden.execution 1 day ago
Obfuscated HTA downloader using ActiveX
gitlab-labkit 4.0.0 first seen anywhere credential-theft.registry 51,416,192 installs ruby 1 day ago
GemBox.Pdf 2026.8.101 staging.memoryreflection.invoke 4,646,704 installs dotnet 18 hours ago
Unsigned DLL with reflection-based resource loader
windows 0.46.0 biggest blast radius keylog.hookfirewall.wfp 283,825,870 installs crates 1 day ago
ntapi 0.4.1 anti-av.syscall 101,191,106 installs crates 1 day ago
VA Autofill 0.9.3 va-autofill 6 installs firefox 20 hours ago
Extension contacts external auth server
Facilita 1.2.313 facilita http.reportexfiltration.sensitive-data 5 installs firefox 1 day ago
Extension exfiltrates credentials and browsing data
MyShield 1.0.0 myshield crypto-manipulation.clipboard 1 installs firefox 20 hours ago
Clipboard hijacking with hardcoded crypto address
v1.9.21.tar.gz binary-metrics.shapedebugger-detect.check arch 1 day ago
koru 0.1.445 python 1 day ago
Automation tool executes arbitrary code
atlispcc 0.1.8 obfuscation.decoderspack.runtime python 1 day ago
Notion.Notion package.direct-urlrat.config windows 16 hours ago
lJqsG delivery.stegoinfrastructure.ip-port 16 hours ago
textgen reverse-shell.pty 19 hours ago
Embedded PTY backdoor in Python binary
846bb7ba9ca2… payload.self-readpayload.encoded 20 hours ago
Malicious DLLs with anti-debug loaders
arm7 mirai.corebotnet.iot linux 18 hours ago
lkxstress.arm5 mirai.corebotnet.iot linux 18 hours ago
Mirai botnet malware binary
SUNDAY Sun Aug 2 · 229 catches · 7 waves · 41 singles
🌊 sensi_hk.sh and 3 siblings botnet.iotdelivery.download-execute linux 2 days ago
IoT botnet dropper script
🌊 View Memo 5.11.21 and 3 siblings firefox 1 day ago
Obfuscated API key in browser extension
🌊 Guard Plus 6.19.1 and 2 siblings firefox 1 day ago
Fake ad blocker, basketball data stealer
🌊 tinkoff-component-page-loader 20.8.2 and 2 siblings execution.native-binarydns.tunneling javascript 1 day ago
Trojanized library downloads and executes native payload
tracy/tracy v2.11.0 first seen anywhere script.dropperexecution.wsh 25,810,817 installs composer 1 day ago
petgraph 0.8.3 biggest blast radius trojanized.build-pipeline 443,963,343 installs crates 2 days ago
windows 0.48.0 keylog.hookfirewall.wfp 283,825,870 installs crates 2 days ago
zip 6.0.0 encrypt.native-locker 228,140,556 installs crates 2 days ago
dqkis.jar dropper.staged-loadercredential.token java 2 days ago
Minecraft token stealer with encrypted dropper
KryptonPlus-LIISTA.jar credential.tokendropper.staged-loader java 2 days ago
Minecraft token stealer with encrypted dropper
Extension Z 9.8.8 extension-z domain.brand-impersonationhttp.report 5 installs firefox 1 day ago
Exfiltrates data to external domain
firefox 154.0b1 domain.brand-impersonationip.spoof arch 1 day ago
file obfuscator.garble windows 2 days ago
Go shellcode loader with evasion
ws-Setup-Complete.exe obfuscator.garbleinjection.shellcode windows 2 days ago
Go loader with shellcode injection and obfuscation
file payload.sectionpack.section-anomaly windows 2 days ago
Packed PE with obfuscated loader
boatnet.arm7 linux.generic_threatMirai.Mar13 linux 2 days ago
Mddos.arm5 process.renameminer.runtime linux 2 days ago
XMRig cryptojacking malware payload
k.php account.createurl.external-ip linux 2 days ago
SATURDAY Sat Aug 1 · 30 catches · 0 waves · 21 singles
windows-sys 0.60.2 biggest blast radius firewall.wfp 1,344,061,720 installs crates 2 days ago
adv 3.3.9-alpha.0.4787 pack.runtimebuild.github-actions 63,159 installs dotnet 2 days ago
Contains embedded malware dropper scripts
net/py-boto3 account.createwallet.desktop openbsd 2 days ago
guardianhub 0.1.577 remote-command.dispatchenv.token python 2 days ago
Embedded private keys and admin remote control
vibefoundry 0.4.4 cmd.injection python 2 days ago
Web endpoint executes arbitrary shell commands
pyouro 1.1.12 payload.loaderdebugger-detect.check python 2 days ago
DRM framework with anti-debug and obfuscation
the-sz.Trion screenshot.capture windows 2 days ago
Trion RAT malware with exfiltration
fsevents 1.1.3 hidden-payload.encodingwallet.desktop javascript 2 days ago
v3.0.0.6 execution.download-execexecution.wsh 2 days ago
That's every sector reporting. The full stream lives in the index →