Obfuscated PowerShell dropper downloading malicious payload
javascript Fallout
The latest malware caught across open-source registries and marketplaces — evidence included.
Hostile catches · since Aug 1
500
TODAY
Tue Aug 4 · 7 catches · 0 waves · 3 singles
@ruffle-rs/ruffle 0.5.0
javascript
14 hours ago
Purchase Order PO K 0158.js
✓
javascript
8 hours ago
Obfuscated code with dynamic function construction
YESTERDAY
Mon Aug 3 · 26 catches · 0 waves · 3 singles
SUNDAY
Sun Aug 2 · 42 catches · 2 waves · 3 singles
🌊
statist-browser-typed-client-hra.workplacer.events 20.9.1 and 6 siblings
dns.tunnelingdelivery.download-execute
✓
javascript
1 day ago
Dropper downloads and executes native payload
🌊
tinkoff-component-page-loader 20.8.2 and 2 siblings
execution.native-binarydns.tunneling
✓
javascript
1 day ago
Trojanized library downloads and executes native payload
google-closure-compiler-windows 20260730.0.0
loader.native-reflectstaging.encrypted
javascript
2 days ago
SATURDAY
Sat Aug 1 · 4 catches · 0 waves · 3 singles
That's every sector reporting.
The full stream lives in the index →