Open-source atomic malware analysis

Analyze another

stealer.ts

JAVASCRIPT
Verdict: HOSTILE
Mal-ecule
KO₉(AlCa₃S₆C₅EuCo₂Dy₃AsI)H₄(CmPo₃F₃Db)Md₂(Pa)
Size 3.5 KB download
First seen 118 days ago
Analyzed 118 days ago
Ecosystem malcontent-samples

Well-known

suspicious severity, 99% confident.
malware/supply-chain Exact Start Menu Startup tail

Objectives

hostile severity, 100% confident.
anti-analysis Self-termination via SIGSEGV for evasion combined with other suspicious activity
hostile severity, 100% confident.
credential-access/discord/token CursedGrabber Discord token stealer family
hostile severity, 95% confident.
supply-chain/trojanized Node.js package targets credentials for HTTP exfiltration
suspicious severity, 100% confident.
command-and-control Hardcoded Discord webhook URL
suspicious severity, 70% confident.
credential-access/browser Yandex browser profile path
suspicious severity, 98% confident.
credential-access/discord Discord token stealer detected
suspicious severity, 90% confident.
exfiltration Discord webhook URL
suspicious severity, 88% confident.
supply-chain/hidden-payload Token storage with postinstall tracking
notable severity, 85% confident.
collection/stealer Brave profile path target
notable severity, 90% confident.
command-and-control/channel Discord API URL
notable severity, 80% confident.
discovery os.homedir() user home directory
notable severity, 85% confident.
discovery/host Opera browser data
notable severity, 85% confident.
discovery/system/fingerprint Collects user home directory path
notable severity, 85% confident.
supply-chain/install-hook Chrome Windows User Data path

Micro-behaviors

suspicious severity, 100% confident.
communications/http Discord webhook API endpoint
suspicious severity, 80% confident.
process/fd Empty buffer stdout write
suspicious severity, 95% confident.
process/terminate Terminate process with SIGSEGV (anti-analysis/evasion)
notable severity, 100% confident.
fs Reference to .cmd file extension
notable severity, 80% confident.
fs/write Writes to file asynchronously

20 of 34 traits shown

Identity

SHA-256 9af37b5973ee1e683d9708591cbe31b8a1044aab88b92b5883bdd74bcf8d807b
Filename stealer.ts

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 24 Apr 2026 21:12 UTC
Last updated 24 Apr 2026 21:12 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61