s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80 high

📛 Threat Title

Unknown: Order 9uyd6rg.JS

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: js. Size: 3414441 bytes. Tags: exe, js. Reporter: James_inthe_box. First seen: 2026-05-14 11:14:35.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain 9uyd6rg.js VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/9uyd6rg.js

IOC database

Type
domain
Value
9uyd6rg.js
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/9uyd6rg.js

hash_sha256 c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80 1 feed

IOC database

Type
hash_sha256
Value
c54a5569fe7cc95554e343f5ac829389fccbf6417000bf6573c4b64bd48c7d80
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 f4f166cc65e2cb7fb02b7a4a855b85a1 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f4f166cc65e2cb7fb02b7a4a855b85a1
2 feeds

IOC database

Type
hash_md5
Value
f4f166cc65e2cb7fb02b7a4a855b85a1
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f4f166cc65e2cb7fb02b7a4a855b85a1

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: js. Size: 3414441 bytes. Tags: exe, js. Reporter: James_inthe_box. First seen: 2026-05-14 11:14:35.

Remediations (8)

  • web:alicebob.posthaven.com

    There are a few ways to include Javascript code into a web site. Depending on who writes the code and where it is hosted, there are different supply chain security considerations and mitigation methods. I will briefly cover each case and discuss what I think are gaps in current solutions.

  • web:blog.qualys.com

    Find out how to detect and remediate vulnerabilities in popular JavaScript libraries like jQuery and Bootstrap to protect your web applications from exploits.

  • web:cheatsheetseries.owasp.org

    Predefined Request Data: Another mitigation technique is to store a list of predefined, safe request data in the JavaScript code (e.g., combinations of endpoints, request methods and other parameters that are safe to be replayed).

  • web:cstromblad.com

    More comprehensive detection scripts were shared, including bash scripts for enterprise deployment through MDM systems and JavaScript utilities for auditing package-lock.json files 3. Immediate Mitigation Measures Security experts recommended immediate removal of affected packages and careful monitoring of accounts 3.

  • web:layerlogix.com

    North Korean hackers compromised the Axios npm package (100M+ weekly downloads) with a cross-platform RAT. Step-by-step detection commands for Windows, macOS, and Linux plus complete remediation guide.

  • web:snyk.io

    Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.

  • web:www.microsoft.com

    On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...

  • web:www.sisainfosec.com

    A phishing-led npm supply chain attack briefly compromised 18 popular packages (~2.6B weekly downloads), injecting code to hijack crypto wallet transactions. Malicious versions were live for ~2.5 hours on Sept 8, 2025, before removal. Learn the impact, affected packages, IoCs, and steps to secure builds, dependencies, and developer accounts.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.