Objectives
hostile severity, 99% confident.
command-and-control/backdoor/dispatch
Profile exfiltration with remote execution
hostile severity, 95% confident.
supply-chain/recon-exfil
npm supply chain attack with CI/CD targeting
suspicious severity, 93% confident.
anti-analysis/self-modify
TS reads own script
suspicious severity, 90% confident.
anti-analysis/vm-detect
Node VM vendor string set
suspicious severity, 92% confident.
anti-static/obfuscation
Generic PEB+PE walk with multiplicative hash resolver (x64)
suspicious severity, 93% confident.
anti-static/obfuscation/encoding
Encoded file download pattern
suspicious severity, 100% confident.
anti-static/obfuscation/eval
Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/string
Python rolling-key XOR loop
suspicious severity, 94% confident.
command-and-control/backdoor/tasking
JS execSync command call
suspicious severity, 92% confident.
command-and-control/trigger
JS import-time / first-touch C2 hook installation
suspicious severity, 94% confident.
evasion/hijack-execution-flow
Node hidden module inject
suspicious severity, 94% confident.
impact/wipe
QNX Node process kill loop
suspicious severity, 100% confident.
lateral-movement/brute-force
SSH authentication methods
suspicious severity, 100% confident.
supply-chain/hidden-payload
Executes npm owner add command
suspicious severity, 94% confident.
supply-chain/install-hook
Node writes npm preinstall hook
suspicious severity, 92% confident.
supply-chain/install-hook/scripts
npm install with --save flag from code
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast
Node encodes host profile JSON as base64
Micro-behaviors
suspicious severity, 90% confident.
communications/http/url
Encoded URL targets .php endpoint
suspicious severity, 92% confident.
process/control
NtSuspendProcess and NtResumeProcess runtime resolution
Metadata
suspicious severity, 90% confident.
binary
Metasploit related PDB path
20 of 370 traits shown
Identity
| SHA-256 | a3353ab91c8eca2c56948488c9785651541fa1211955eba07502b73ecf94f033 |
|---|---|
| Canonical SHA-256 | 0001bb02621131da25449520dcc7da954e247cca6d1c6b08894d01a01643ef40 |
| Filename | tabby-1.0.234-portable-arm64.zip |
| Package | tabby |
Origin
| Source | forager |
|---|---|
| Feed | tabby |
| Ecosystem | vendor |
| Domain | tabby.sh |
| URL | https://github.com/Eugeny/tabby/releases/download/v1.0.234/tabby-1.0.234-portable-arm64.zip |
Timeline
| First seen | 30 May 2026 00:25 UTC |
|---|---|
| First analyzed | 14 Jun 2026 11:19 UTC |
| Last analyzed | 14 Jun 2026 11:19 UTC |
| Last updated | 20 Jun 2026 11:25 UTC |
Labeling
| Label | good |
|---|---|
| Label source | forager |
| Traits version | c7b65 |
Not seeing what you expected? Let us know