MB-c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80
high
📛 Threat Title
Unknown: Order 9uyd6rg.JS
Description
File type: js. Size: 3414441 bytes. Tags: exe, js. Reporter: James_inthe_box. First seen: 2026-05-14 11:14:35.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
9uyd6rg.js
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/9uyd6rg.js
IOC database
- Type
- domain
- Value
9uyd6rg.js- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/9uyd6rg.js
hash_sha256
c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80
1 feed
IOC database
- Type
- hash_sha256
- Value
c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
f4f166cc65e2cb7fb02b7a4a855b85a1
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f4f166cc65e2cb7fb02b7a4a855b85a1
2 feeds
IOC database
- Type
- hash_md5
- Value
f4f166cc65e2cb7fb02b7a4a855b85a1- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f4f166cc65e2cb7fb02b7a4a855b85a1
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: js. Size: 3414441 bytes. Tags: exe, js. Reporter: James_inthe_box. First seen: 2026-05-14 11:14:35.
Remediations (8)
-
web:alicebob.posthaven.com
There are a few ways to include Javascript code into a web site. Depending on who writes the code and where it is hosted, there are different supply chain security considerations and mitigation methods. I will briefly cover each case and discuss what I think are gaps in current solutions.
-
web:blog.qualys.com
Find out how to detect and remediate vulnerabilities in popular JavaScript libraries like jQuery and Bootstrap to protect your web applications from exploits.
-
web:cheatsheetseries.owasp.org
Predefined Request Data: Another mitigation technique is to store a list of predefined, safe request data in the JavaScript code (e.g., combinations of endpoints, request methods and other parameters that are safe to be replayed).
-
web:cstromblad.com
More comprehensive detection scripts were shared, including bash scripts for enterprise deployment through MDM systems and JavaScript utilities for auditing package-lock.json files 3. Immediate Mitigation Measures Security experts recommended immediate removal of affected packages and careful monitoring of accounts 3.
-
web:layerlogix.com
North Korean hackers compromised the Axios npm package (100M+ weekly downloads) with a cross-platform RAT. Step-by-step detection commands for Windows, macOS, and Linux plus complete remediation guide.
-
web:snyk.io
Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.
-
web:www.microsoft.com
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...
-
web:www.sisainfosec.com
A phishing-led npm supply chain attack briefly compromised 18 popular packages (~2.6B weekly downloads), injecting code to hijack crypto wallet transactions. Malicious versions were live for ~2.5 hours on Sept 8, 2025, before removal. Learn the impact, affected packages, IoCs, and steps to secure builds, dependencies, and developer accounts.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.