TF-1868514
high
📛 Threat Title
Unknown malware: Domain that is used for botnet Command&control (C&C) npm-cache.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
npm-cache.com
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
npm-cache.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.
- External reference ThreatFox IOCs
Remediations (10)
-
web:github.com
This project aims to provide a resource for malicious domain intelligence gathered from various sources, focusing on threats like malware , ransomware, phishing, spyware, and botnets . The goal is to simplify the process of accessing and utilizing this information for users, without the need to manually search for and maintain these lists themselves. By incorporating these blocklists into your ...
-
web:securityboulevard.com
Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.
-
web:success.trendmicro.com
Summary Some malware communicate with their C&C server to send and receive information. If a C&C callback is detected by the product, there is a high possibility that the host is infected. This article will tell you what to do in case of C&C callback detection. Identify the Callback Address, C&C List Source, and Process.
-
web:threatfox.abuse.ch
ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware , with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries.
-
web:urlhaus.abuse.ch
Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.rescana.com
Active Exploitation Alert: 148 Malicious npm Packages Masquerading as Student Proxies Turn Browsers Into DDoS Botnet Executive Summary A sophisticated and highly opportunistic campaign has been uncovered involving 148 malicious npm packages masquerading as student proxy tools.
-
web:www.secureblink.com
A newly deobfuscated npm malware campaign called Lucide Proxy is enlisting the browsers of students and everyday users into a coordinated denial-of-service botnet , and it is doing so without ever touching a developer's machine.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening?
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.