s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868514 high

📛 Threat Title

Unknown malware: Domain that is used for botnet Command&control (C&C) npm-cache.com

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain npm-cache.com UrlVoid 0 / 35

IOC database

Type
domain
Value
npm-cache.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.

  • External reference ThreatFox IOCs

Remediations (10)

  • web:github.com

    This project aims to provide a resource for malicious domain intelligence gathered from various sources, focusing on threats like malware , ransomware, phishing, spyware, and botnets . The goal is to simplify the process of accessing and utilizing this information for users, without the need to manually search for and maintain these lists themselves. By incorporating these blocklists into your ...

  • web:securityboulevard.com

    Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.

  • web:success.trendmicro.com

    Summary Some malware communicate with their C&C server to send and receive information. If a C&C callback is detected by the product, there is a high possibility that the host is infected. This article will tell you what to do in case of C&C callback detection. Identify the Callback Address, C&C List Source, and Process.

  • web:threatfox.abuse.ch

    ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware , with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries.

  • web:urlhaus.abuse.ch

    Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.

  • web:www.geeksforgeeks.org

    At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?

  • web:www.rescana.com

    Active Exploitation Alert: 148 Malicious npm Packages Masquerading as Student Proxies Turn Browsers Into DDoS Botnet Executive Summary A sophisticated and highly opportunistic campaign has been uncovered involving 148 malicious npm packages masquerading as student proxy tools.

  • web:www.secureblink.com

    A newly deobfuscated npm malware campaign called Lucide Proxy is enlisting the browsers of students and everyday users into a coordinated denial-of-service botnet , and it is doing so without ever touching a developer's machine.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening?

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.