[
  {
    "kind": "sha256",
    "value": "54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668",
    "context": "setup.mjs Variant A (29,918 bytes, jaredwray npm tarballs only)",
    "href": "/ti/ioc/sha256/54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "sha256",
    "value": "9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc",
    "context": "Math_Symbol.js / math_init.js stage-two payload (727,680 bytes, byte-identical across both variants)",
    "href": "/ti/ioc/sha256/9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "sha256",
    "value": "fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb",
    "context": "setup.mjs Variant B (11,017 bytes, all non-jaredwray orgs + jaredwray repo IDE hooks)",
    "href": "/ti/ioc/sha256/fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb",
    "campaigns": [],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "wallet",
    "value": "0xE1f2395ee43e45A1556EC6438a88c31B83493103",
    "context": "Ethereum mainnet smart contract storing C2 domain configuration (EtherHiding). 5,196 bytes deployed code. Function selector 0x53ed5143 for domain retrieval. Owner wallet: 0x55f9780e1492344b7417fa723aedc4d0b97f31cd.",
    "href": "/ti/ioc/wallet/0xE1f2395ee43e45A1556EC6438a88c31B83493103",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "wallet",
    "value": "0x55f9780e1492344b7417fa723aedc4d0b97f31cd",
    "context": "Ethereum wallet that deployed and owns the EtherHiding C2 smart contract 0xE1f2395...3103. Controls domain rotation via on-chain transactions.",
    "href": "/ti/ioc/wallet/0x55f9780e1492344b7417fa723aedc4d0b97f31cd",
    "campaigns": [],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "domain",
    "value": "npm-cache.com",
    "context": "Active C2 domain retrieved from Ethereum smart contract state (slot at keccak256(1)). Impersonates npm cache infrastructure. Used for encrypted exfiltration via DomainSender (RSA-OAEP + AES-GCM).",
    "href": "/ti/ioc/domain/npm-cache.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "domain",
    "value": "js-mirror.com",
    "context": "Previously active C2 domain (external reporting). Impersonates JavaScript CDN mirror. Rotated out via on-chain contract update.",
    "href": "/ti/ioc/domain/js-mirror.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "domain",
    "value": "pypi-get.com",
    "context": "Previously active C2 domain (external reporting). Impersonates PyPI package mirror. Rotated out via on-chain contract update.",
    "href": "/ti/ioc/domain/pypi-get.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-08-04"
  },
  {
    "kind": "sha256",
    "value": "adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6",
    "context": "npm tarball hash for @joyfill/layouts@0.1.2-2773.beta.0 (PolinRider blockchain C2 loader)",
    "href": "/ti/ioc/sha256/adc4af90540d33cd1e98f44b51482ae9250fbeb97d6f8d7841c81b618cb2c6e6",
    "campaigns": [],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "sha256",
    "value": "bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17",
    "context": "npm tarball hash for @joyfill/components@4.0.0-rc24-2773-beta.4 (dependency chain to PolinRider layouts)",
    "href": "/ti/ioc/sha256/bcc93dc55bc7daedf4ca57254f0e7a7f1c40e09851eab98fe10cde801982db17",
    "campaigns": [],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "wallet",
    "value": "TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP",
    "context": "Primary Tron C2 address for PolinRider campaign. Stores encrypted C2 URL in smart contract data. Shared across @joyfill/layouts and astro.config.mjs attacks.",
    "href": "/ti/ioc/wallet/TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP",
    "campaigns": [
      "PolinRider"
    ],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "wallet",
    "value": "TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG",
    "context": "Fallback Tron C2 address for PolinRider campaign. Used when primary address TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP is unavailable.",
    "href": "/ti/ioc/wallet/TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG",
    "campaigns": [
      "PolinRider"
    ],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "wallet",
    "value": "0x9bc1355344b54dedf3e44296916ed15653844509",
    "context": "BSC (Binance Smart Chain) attacker wallet for PolinRider campaign. Transaction data from this wallet carries XOR-encrypted JavaScript payload.",
    "href": "/ti/ioc/wallet/0x9bc1355344b54dedf3e44296916ed15653844509",
    "campaigns": [
      "PolinRider"
    ],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "wallet",
    "value": "TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v",
    "context": "Stage 2 Tron C2 address for PolinRider campaign. Second blockchain fetch uses this address after campaign routing selects HTTP C2 server.",
    "href": "/ti/ioc/wallet/TA48dct6rFW8BXsiLAtjFaVFoSuryMjD3v",
    "campaigns": [
      "PolinRider"
    ],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "ipv4",
    "value": "166.88.134.62",
    "context": "HTTP C2 server for PolinRider campaign, selected when campaign marker starts with 'A' (joyfill incident). Set by stage 2 campaign routing.",
    "href": "/ti/ioc/ipv4/166.88.134.62",
    "campaigns": [
      "PolinRider"
    ],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "ipv4",
    "value": "198.105.127.210",
    "context": "HTTP C2 server for PolinRider campaign, selected for numeric campaign markers. Set by stage 2 campaign routing.",
    "href": "/ti/ioc/ipv4/198.105.127.210",
    "campaigns": [],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "ipv4",
    "value": "23.27.202.27",
    "context": "HTTP C2 server for PolinRider campaign (default fallback, port 27017). Set by stage 2 campaign routing.",
    "href": "/ti/ioc/ipv4/23.27.202.27",
    "campaigns": [],
    "discovered_at": "2026-07-28"
  },
  {
    "kind": "url",
    "value": "https://metrics.femboy.energy/v1/collect",
    "context": "Import-time credential-stealer C2 / exfil endpoint (HTTP POST). Statically decoded from a base64-then-XOR (key 'tf_compat_v2') constant at mrmustard/__init__.py:33. Attacker-controlled; do not contact.",
    "href": "/ti/ioc/url/url-ef55a2539727",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "domain",
    "value": "metrics.femboy.energy",
    "context": "C2 / exfil host for the mrmustard 0.7.4 credential stealer.",
    "href": "/ti/ioc/domain/metrics.femboy.energy",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "url",
    "value": "https://webhook.site/710babde-6ace-47fe-83f4-9688e6548df9",
    "context": "Dead-drop for CI secrets (PIPY_TOKEN, CODECOV_TOKEN) exfiltrated by the poisoned GitHub Actions workflow ci-mrmustard-check.yml at commit 80aba72. webhook.site is a legitimate request-inspection service abused as a dead drop; the unique token path is the indicator.",
    "href": "/ti/ioc/url/url-4b24f17dd196",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "file_path",
    "value": "~/.cache/.tf_cache/hw_probe.pyc",
    "context": "Compiled-only (source-less) persistent copy of the stealer. Sibling artifacts in ~/.cache/.tf_cache: .lock_<machineid> guard and .ts_<machineid> timestamp files.",
    "href": "/ti/ioc/file_path/file_path-fa98f9a9d37f",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "file_path",
    "value": "mmcompat.pth",
    "context": "Persistence launcher dropped into the first writable site-packages dir; runs hw_probe.pyc on every Python interpreter startup.",
    "href": "/ti/ioc/file_path/file_path-91bf460d0f75",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "sha256",
    "value": "81f0d1291a975d012d1b892cf9967557fdbb1ad4e1ac0545702ad235ace1cac5",
    "context": "SHA256 of mrmustard-0.7.4-py3-none-any.whl. sdist SHA256 (0404f8...) is recorded on the package version.",
    "href": "/ti/ioc/sha256/81f0d1291a975d012d1b892cf9967557fdbb1ad4e1ac0545702ad235ace1cac5",
    "campaigns": [],
    "discovered_at": "2026-07-24"
  },
  {
    "kind": "domain",
    "value": "oob.sl4x0.xyz",
    "context": "Campaign DNS-exfiltration endpoint. Loader encodes username/hostname/cwd/timestamp plus a per-package tag as subdomain labels and resolves them via dns.resolve4(). Shared across all sl4x0 packages and ecosystems (reused, not new infrastructure, in this untargeted uploader-frontend wave).",
    "href": "/ti/ioc/domain/oob.sl4x0.xyz",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "email",
    "value": "goldmanachspoc@sl4x0.xyz",
    "context": "New npm publisher account for the Goldman Sachs wave. Follows the campaign's <targetco>poc@sl4x0.xyz naming convention.",
    "href": "/ti/ioc/email/goldmanachspoc@sl4x0.xyz",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "email",
    "value": "research@sl4x0.xyz",
    "context": "Author identity ('Enterprise Tools Team <research@sl4x0.xyz>') on the uploader-frontend npm packages. Now confirmed across THREE clusters in this campaign: Anduril-targeting PyPI packages, the Goldman Sachs gs-uitk-* npm wave, and this untargeted uploader-frontend npm pair. The third confirmed literal-identity reuse strengthens the high-confidence single-actor overlap across ecosystems and target types (defense, finance, and untargeted).",
    "href": "/ti/ioc/email/research@sl4x0.xyz",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "file_path",
    "value": "lib/6ad264.js",
    "context": "Hex-array-obfuscated loader shipped by both gs-uitk packages (byte-identical between them). Reaches require('os')/require('dns') via module.constructor._load() plus String.fromCharCode indirection to evade static require() scanning.",
    "href": "/ti/ioc/file_path/file_path-03d9a03da518",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "file_path",
    "value": "lib/b02e30.js",
    "context": "Per-package config file; hex-decodes to the exfil domain oob.sl4x0.xyz plus a per-package DNS tag (goldman1 for gs-uitk-object-utils, goldman2 for gs-uitk-testing-utils) used to correlate DNS beacons back to a specific package.",
    "href": "/ti/ioc/file_path/file_path-79624caf26ba",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "email",
    "value": "dialoguepoc@sl4x0.xyz",
    "context": "NEW npm publisher account for the untargeted uploader-frontend / uploader-frontend-legacy wave (2026-07-20). Follows the campaign's *poc@sl4x0.xyz account convention but without a target-organization prefix, consistent with an untargeted/generic publish rather than a named-target wave.",
    "href": "/ti/ioc/email/dialoguepoc@sl4x0.xyz",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "file_path",
    "value": "lib/core.js",
    "context": "Hex-obfuscated harvesting core loaded by index.js (require('./lib/core') in try/catch). Reads os.userInfo().username, os.hostname(), basename(process.cwd()), sanitizes each via clean(), then dns.resolve4()s <tag>.<user>.<host>.<cwd>.<unix-ts>.oob.sl4x0.xyz. Adds setTimeout(()=>{},500).unref() after the DNS call (refinement not seen in earlier oc-aa-module-client/gs-uitk samples).",
    "href": "/ti/ioc/file_path/file_path-826e5ed9069c",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "sha256",
    "value": "ce42880a5be86ce5b7db2e4ce47b04b233308f6e0c0ffff9c9da7a8b39ca5a3f",
    "context": "SHA256 of index.js in uploader-frontend@9.9.11 (install entrypoint; require('./lib/core') in try/catch, exports version 9.9.11).",
    "href": "/ti/ioc/sha256/ce42880a5be86ce5b7db2e4ce47b04b233308f6e0c0ffff9c9da7a8b39ca5a3f",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "sha256",
    "value": "397d1435e7291ed6b02b8627033a110124d250a54290b3a8f9f248573fd6a2d4",
    "context": "SHA256 of lib/core.js in uploader-frontend@9.9.11 (hex-obfuscated harvesting core + dns.resolve4() beacon with setTimeout unref refinement).",
    "href": "/ti/ioc/sha256/397d1435e7291ed6b02b8627033a110124d250a54290b3a8f9f248573fd6a2d4",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "sha256",
    "value": "7e5dffc0070dfd23371f2f41227b1e3b0f81b85bfaf4fe87e35c5c64e5ddd748",
    "context": "SHA256 of lib/b02e30.js in uploader-frontend@9.9.11 (per-package config; hex-decodes to oob.sl4x0.xyz + DNS tag 'uploadfe'). uploader-frontend-legacy's copy differs (tag 'uploadfele') and therefore has a different, unprovided hash.",
    "href": "/ti/ioc/sha256/7e5dffc0070dfd23371f2f41227b1e3b0f81b85bfaf4fe87e35c5c64e5ddd748",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "sha256",
    "value": "95ed14077ba3da5517e8b1816a38f3961cebd6f6fb84c86b1bd77ab0a4dcdff4",
    "context": "SHA256 of lib/6ad264.js in uploader-frontend@9.9.11 (utility wrapper { os, dns, proc: global.process, clean }).",
    "href": "/ti/ioc/sha256/95ed14077ba3da5517e8b1816a38f3961cebd6f6fb84c86b1bd77ab0a4dcdff4",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "sha256",
    "value": "0247cc50a0a57a241e6eda6714516e5864f23389977049c30052cfb3a69abd2f",
    "context": "SHA256 of package.json in uploader-frontend@9.9.11 (scripts.install 'node index.js'; author 'Enterprise Tools Team <research@sl4x0.xyz>'; fabricated repo github.com/slaxorg/nms-dashboard-js).",
    "href": "/ti/ioc/sha256/0247cc50a0a57a241e6eda6714516e5864f23389977049c30052cfb3a69abd2f",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-23"
  },
  {
    "kind": "domain",
    "value": "update.apex-arena-router.com",
    "context": "Primary C2 / exfil host. Resolves to 172.93.185.150 (xTom GmbH, AS3214, Frankfurt). Caddy reverse proxy in front of Uvicorn/FastAPI, wildcard Let's Encrypt cert for *.apex-arena-router.com, /openapi.json exposed unauthenticated. Serves loader.sh + payload.enc, receives exfil uploads, and answers the 60s persistence ping.",
    "href": "/ti/ioc/domain/update.apex-arena-router.com",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "domain",
    "value": "apex-arena-router.com",
    "context": "C2 base domain / wildcard cert *.apex-arena-router.com. Multi-tenant panel provisions per-campaign subdomains under this apex.",
    "href": "/ti/ioc/domain/apex-arena-router.com",
    "campaigns": [],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "domain",
    "value": "apexfdn.xyz",
    "context": "Operator brand domain ('Apex Foundation'). Anchors the npm scope @apexfdn and maintainer emails.",
    "href": "/ti/ioc/domain/apexfdn.xyz",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "domain",
    "value": "arena.apexfdn.xyz",
    "context": "Operator front/dashboard host (arena.apexfdn.xyz/dashboard/copilot). Hosts the remote-MCP endpoint and receives the @apexfdn/copilot-mcp front package's forwarded tokens and document excerpts.",
    "href": "/ti/ioc/domain/arena.apexfdn.xyz",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "domain",
    "value": "docs.apexfdn.xyz",
    "context": "Operator documentation host in the apexfdn.xyz family.",
    "href": "/ti/ioc/domain/docs.apexfdn.xyz",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "url",
    "value": "https://arena.apexfdn.xyz/api/copilot/mcp",
    "context": "Hosted remote-MCP endpoint reached with a Bearer token. No-install infection vector that sends tokens to attacker infrastructure without any package install.",
    "href": "/ti/ioc/url/url-f5ee173a3d2a",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "url",
    "value": "https://update.apex-arena-router.com/payload.enc",
    "context": "AES-256-CBC encrypted macOS stealer payload fetched by loader.sh, decrypted in memory (key = upload token) and piped to osascript. Never written to disk as a separate file.",
    "href": "/ti/ioc/url/url-b22340527fd2",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "ipv4",
    "value": "172.93.185.150",
    "context": "C2 server IP. xTom GmbH (AS3214), Frankfurt am Main, Germany.",
    "href": "/ti/ioc/ipv4/172.93.185.150",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "sha256",
    "value": "ecd1113fae1ede9869afd9d1af612bab7f1a2054e5c45a346e18c107c22b9164",
    "context": "payload.enc, the AES-256-CBC encrypted 707-line AMOS-family AppleScript stealer. Decrypts with the upload token 5c6f24c905ae3883355a26fceac3dda0d0dfe67ba8e1220ebe784a29544c6ee4 (SHA-256 key derivation); that same value doubles as the X-Upload-Token in every exfil request.",
    "href": "/ti/ioc/sha256/ecd1113fae1ede9869afd9d1af612bab7f1a2054e5c45a346e18c107c22b9164",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "sha1",
    "value": "233f90180b529aa32911901e5222e9ed9c3cd24c",
    "context": "npm tarball SHA1 for @copilot-mcp/apex@1.0.0 (inline curl|zsh launcher variant).",
    "href": "/ti/ioc/sha1/233f90180b529aa32911901e5222e9ed9c3cd24c",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "sha1",
    "value": "3b9a880ae4e1c5b7bbd68e118a1c3c8b592f7bfb",
    "context": "npm tarball SHA1 for @copilot-mcp/apex@1.0.19 (compiled apex-helper-darwin launcher variant).",
    "href": "/ti/ioc/sha1/3b9a880ae4e1c5b7bbd68e118a1c3c8b592f7bfb",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "email",
    "value": "chefkecharlie@gmail.com",
    "context": "Operator-associated email (ties to Telegram @charlereum).",
    "href": "/ti/ioc/email/chefkecharlie@gmail.com",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "email",
    "value": "arena@apexfdn.xyz",
    "context": "npm maintainer email for the dropper (@copilot-mcp/apex / @apexfdn/apex).",
    "href": "/ti/ioc/email/arena@apexfdn.xyz",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "email",
    "value": "contact@apexfdn.xyz",
    "context": "npm maintainer email for the front package @apexfdn/copilot-mcp. Same apexfdn.xyz domain as the dropper maintainer, linking the two scopes to one operator.",
    "href": "/ti/ioc/email/contact@apexfdn.xyz",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "file_path",
    "value": "/tmp/osalogging.zip",
    "context": "Staged stolen-data archive (ditto -c -k) uploaded over chunked HTTPS PUT, then rm -f'd for anti-forensics.",
    "href": "/ti/ioc/file_path/file_path-2b800a65a3b4",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "file_path",
    "value": "/tmp/sync<random>/",
    "context": "Stealer staging directory where browser data, wallets, keys, and Keychain are collected before archiving; cleared after upload.",
    "href": "/ti/ioc/file_path/file_path-17a6719b605a",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "file_path",
    "value": "~/Library/LaunchAgents/com.system.notifications.agent.plist",
    "context": "Persistence LaunchAgent (label com.system.notifications.agent, StartInterval 60s) that polls /v1/agent/ping on the C2 host every 60 seconds for follow-on commands.",
    "href": "/ti/ioc/file_path/file_path-3c9fd16e0017",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "file_path",
    "value": "~/Library/Application Support/System/System Notifications.app",
    "context": "Fake app bundle (bundle ID com.system.notifications.helper.bld013) dropped and registered via lsregister; masquerades as macOS 'System Notifications'.",
    "href": "/ti/ioc/file_path/file_path-ae14b1053584",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "github_repo",
    "value": "Apex-Foundation/copilot",
    "context": "Weaponized fork of can1357/oh-my-pi that hosts the downloaded release binaries (apex-linux-x64, apex-darwin-arm64/x64, apex-windows-x64, apex-helper-darwin, apex-auth-darwin, pi_natives.win32-x64-baseline.node). install.cjs fetches from its v1.0.0 release tag; assets are swappable server-side. Still live after both npm takedowns.",
    "href": "/ti/ioc/github_repo/github_repo-7bd1f158efc7",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "github_repo",
    "value": "Apex-Foundation/copilot-mcp",
    "context": "The advertised (clean) source in the dropper's repository field; benign TypeScript that misdirects reviewers away from the real binary source Apex-Foundation/copilot.",
    "href": "/ti/ioc/github_repo/github_repo-1ee17eff897b",
    "campaigns": [
      "Apex Foundation"
    ],
    "discovered_at": "2026-07-22"
  },
  {
    "kind": "domain",
    "value": "git.disroot.org",
    "context": "Legitimate public Forgejo instance. NOT attacker-owned; the attacker registered the username/namespace 'git-ecosystem' on it to look legitimate and host payload binaries. Only the git-ecosystem namespace is malicious. Treat the bare domain as a qualified indicator.",
    "href": "/ti/ioc/domain/git.disroot.org",
    "campaigns": [],
    "discovered_at": "2026-07-19"
  },
  {
    "kind": "url",
    "value": "https://git.disroot.org/git-ecosystem/",
    "context": "Attacker-controlled Forgejo namespace hosting the dropper payload binaries (some zipped, VirusTotal-flagged). Dropper builds fetch URLs of the form https://git.disroot.org/git-ecosystem/#{product}/raw/branch/main.",
    "href": "/ti/ioc/url/url-ed717ed4f441",
    "campaigns": [],
    "discovered_at": "2026-07-19"
  },
  {
    "kind": "ipv4",
    "value": "85.137.53.71",
    "context": "Primary HTTP C2 server. Command server on port 8080, data-exfiltration upload on port 8081 (SafeDep also observed proxy management on 8091). Attacker secp256k1 public key from the decrypted __RT_BAKED__ config: 0432fa4ba871877d94081fe83323fa24dfa1491e9de8725cbab7b734de9e9be3b233ef6742fd6264437c9532223d687b05fa540b70af6a516b8539af84d0eeb48e (beacon signing / encrypted C2).",
    "href": "/ti/ioc/ipv4/85.137.53.71",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "wallet",
    "value": "0x12c37A86a0Ed0beBe5d1d6a43E42f07860eAc710",
    "context": "Ethereum mainnet smart contract used as fallback C2 channel for address refresh / payload updates. Queried via public RPC (ethereum-rpc.publicnode.com).",
    "href": "/ti/ioc/wallet/0x12c37A86a0Ed0beBe5d1d6a43E42f07860eAc710",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "wallet",
    "value": "0x1969ab05d67b67fdcaa26240f738ccb077e1cd84",
    "context": "Ethereum backup C2 contract (Wiz IOC table).",
    "href": "/ti/ioc/wallet/0x1969ab05d67b67fdcaa26240f738ccb077e1cd84",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "wallet",
    "value": "0x92d4C5413e4F7B258a114964101F9e1C6d64C6Ba",
    "context": "Ethereum deployer wallet for the C2 contracts (Wiz IOC table).",
    "href": "/ti/ioc/wallet/0x92d4C5413e4F7B258a114964101F9e1C6d64C6Ba",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "rentry.co",
    "context": "Dead-drop used to exfiltrate the stolen asyncapi-bot PAT from the GitHub Actions runner. Slug 'elzotebo' matches naming patterns of the separate 'prt-scan' campaign (per Wiz, prt-scan is NOT linked to Miasma).",
    "href": "/ti/ioc/domain/rentry.co",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "ipfs.io",
    "context": "IPFS gateway used for Stage-2 payload delivery.",
    "href": "/ti/ioc/domain/ipfs.io",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "relay.damus.io",
    "context": "Nostr relay used as a fallback C2 channel (miasma-branded tags). From decrypted config nostrRelays array.",
    "href": "/ti/ioc/domain/relay.damus.io",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "relay.nostr.com",
    "context": "Nostr relay used as a fallback C2 channel. From decrypted config nostrRelays array.",
    "href": "/ti/ioc/domain/relay.nostr.com",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "url",
    "value": "ipfs://QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9",
    "context": "IPFS CID for the Stage-2 RAT payload delivered to the three generator packages. 8.25 MB AES-256-GCM encrypted JavaScript. SHA-256 of the downloaded file: 24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168.",
    "href": "/ti/ioc/url/url-53699d3467e8",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "url",
    "value": "ipfs://Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf",
    "context": "IPFS CID for the Stage-2 RAT payload delivered to @asyncapi/specs. 8.24 MB AES-256-GCM encrypted JavaScript. SHA-256 of downloaded file: e9544a648d8fbaccd01b8477cf68471d48b89bf93eeacbdf5bba20fd296ff7b5. Wiz labels this the 'react-sdk variant'.",
    "href": "/ti/ioc/url/url-337223c7cb7f",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha1",
    "value": "22bf76fe317ea6769bd38619bd440e42d119bd6b",
    "context": "Malicious validator.js in @asyncapi/generator (Wiz IOC table).",
    "href": "/ti/ioc/sha1/22bf76fe317ea6769bd38619bd440e42d119bd6b",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha1",
    "value": "a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2",
    "context": "Malicious utils.js in @asyncapi/generator-helpers (Wiz IOC table).",
    "href": "/ti/ioc/sha1/a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha1",
    "value": "9890950adcbc2478e7a080234f053214adbad44e",
    "context": "Malicious ErrorHandling.js in @asyncapi/generator-components (Wiz IOC table).",
    "href": "/ti/ioc/sha1/9890950adcbc2478e7a080234f053214adbad44e",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha1",
    "value": "c70e105e212ff3c1daa04bb2a62507717f296b0b",
    "context": "Malicious index.js in @asyncapi/specs (Wiz IOC table).",
    "href": "/ti/ioc/sha1/c70e105e212ff3c1daa04bb2a62507717f296b0b",
    "campaigns": [
      "Shai-Hulud",
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha1",
    "value": "c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5",
    "context": "sync.js Stage-2 persisted payload (Wiz IOC table).",
    "href": "/ti/ioc/sha1/c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5",
    "campaigns": [
      "miasma-train-p1"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4",
    "context": "SHA-256 of @asyncapi/generator-3.3.1.tgz (malicious npm tarball, SafeDep).",
    "href": "/ti/ioc/sha256/bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1",
    "context": "SHA-256 of @asyncapi/generator-helpers-1.1.1.tgz (malicious npm tarball, SafeDep).",
    "href": "/ti/ioc/sha256/34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab",
    "context": "SHA-256 of @asyncapi/generator-components-0.7.1.tgz (malicious npm tarball, SafeDep).",
    "href": "/ti/ioc/sha256/082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b",
    "context": "SHA-256 of @asyncapi/specs-6.11.2.tgz (malicious npm tarball, SafeDep).",
    "href": "/ti/ioc/sha256/9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "~/.local/share/NodeJS/sync.js",
    "context": "Linux drop path for the Stage-2 RAT persistence payload. macOS: ~/Library/Application Support/NodeJS/sync.js. Windows: %LOCALAPPDATA%\\NodeJS\\sync.js.",
    "href": "/ti/ioc/file_path/file_path-8214839d541f",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "~/.cache/.sys_cache/.diag.enc",
    "context": "Encrypted activity log written by the RAT payload (200 MB FIFO buffer per decrypted config, SafeDep).",
    "href": "/ti/ioc/file_path/file_path-dd047dd6b4b3",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609",
    "context": "SHA-256 of albion.dll first-stage NuGet downloader assembly (albion-x-x).",
    "href": "/ti/ioc/sha256/d5385526f2f3e52c7d96087611c6cd4e479bf61828400efdb3ca09406d981609",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "567952daf0ab7b36b017aac9963791188dea0fbf2e99c7cc6f6652ee540f4840",
    "context": "SHA-256 of gtaobus.pyc entry module (direct bytecode) inside pepesoft.exe for Albion Online.",
    "href": "/ti/ioc/sha256/567952daf0ab7b36b017aac9963791188dea0fbf2e99c7cc6f6652ee540f4840",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35b",
    "context": "SHA-256 of amazingrp.dll first-stage NuGet downloader assembly (amazing-x-x).",
    "href": "/ti/ioc/sha256/9a2091e6625fc11cfd8f39c17aa271604e66322ee045028946274b988103e35b",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "774e40046f353e3f916f39e3d13d6499da35705a479cfb89288c21017aaf5461",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for Amazing RP.",
    "href": "/ti/ioc/sha256/774e40046f353e3f916f39e3d13d6499da35705a479cfb89288c21017aaf5461",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "e8c2618565aa31d7ffe909ebc99040bafcc0ea8df7f5d92fa673bb7ffacb14c9",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for Amazing RP.",
    "href": "/ti/ioc/sha256/e8c2618565aa31d7ffe909ebc99040bafcc0ea8df7f5d92fa673bb7ffacb14c9",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49e",
    "context": "SHA-256 of calculator.dll first-stage NuGet downloader assembly (calc-x-x).",
    "href": "/ti/ioc/sha256/900ddb81d27e03967209fee4d17d13deb68eef0e1f10936eb520ca10575cb49e",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "cc853b3e4504c890d275ac2327f18acd7e4c5b99ca056181f3f5694781f2cf45",
    "context": "SHA-256 of gtaobus.pyc entry module (direct bytecode) inside pepesoft.exe for Calculator (GTA5RP calc).",
    "href": "/ti/ioc/sha256/cc853b3e4504c890d275ac2327f18acd7e4c5b99ca056181f3f5694781f2cf45",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1",
    "context": "SHA-256 of grandrp.dll first-stage NuGet downloader assembly (grandrp-x-x).",
    "href": "/ti/ioc/sha256/ab58a90eb3682c6dc3389cd700a64f68a19c0dac3d0fa8e3df97ae041f96d4e1",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "23e4d8af5425dae022793450190c8d30809b2986dd879eb4bff557cdacf49c86",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for GrandRP.",
    "href": "/ti/ioc/sha256/23e4d8af5425dae022793450190c8d30809b2986dd879eb4bff557cdacf49c86",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "6eefe9d5f030d403c72bd4e4caf5bbb9dbc2bd5e15ebb07de153494f458e5eb9",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for GrandRP.",
    "href": "/ti/ioc/sha256/6eefe9d5f030d403c72bd4e4caf5bbb9dbc2bd5e15ebb07de153494f458e5eb9",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0",
    "context": "SHA-256 of gta5rp.dll first-stage NuGet downloader assembly (gta5rp-x-x).",
    "href": "/ti/ioc/sha256/e6e1049158ceb1971c61388349c81fa6047a7aecb4ff2089ef54a50dcc35dbc0",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "95577498d23fe750221a5badfc25b5e9f020dcf4d80c79a019b090e3c3b0a32a",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for GTA5RP.",
    "href": "/ti/ioc/sha256/95577498d23fe750221a5badfc25b5e9f020dcf4d80c79a019b090e3c3b0a32a",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "8ab256dd839aec6638cd46374f4a6664e534b9341bbcdfd9b763e5a27c51ddb7",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for GTA5RP.",
    "href": "/ti/ioc/sha256/8ab256dd839aec6638cd46374f4a6664e534b9341bbcdfd9b763e5a27c51ddb7",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1",
    "context": "SHA-256 of lineage2.dll first-stage NuGet downloader assembly (l2-x-x).",
    "href": "/ti/ioc/sha256/d9f7ca9f93a7d188d51db308877b15d0beae932ca0bf4705384fbedf54b454c1",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "2a4fed04d792b9c2fdf9c1456a08ca23eda5fef50c0b409ab294ad489e12d801",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for Lineage 2.",
    "href": "/ti/ioc/sha256/2a4fed04d792b9c2fdf9c1456a08ca23eda5fef50c0b409ab294ad489e12d801",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "6c1f828e4d8395dde8293868c65ba8d86b3b9672ebbbb16e932624706d37d832",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for Lineage 2.",
    "href": "/ti/ioc/sha256/6c1f828e4d8395dde8293868c65ba8d86b3b9672ebbbb16e932624706d37d832",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305",
    "context": "SHA-256 of majestic.dll first-stage NuGet downloader assembly (majestic-x-x).",
    "href": "/ti/ioc/sha256/4d13f1136b13c871c65141b77ec7208488334ac4be511800196adcd328666305",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "7e42d25e707d29d5d185a4c5dc71019f744e88a30b66bbf06949194ff32dbc48",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for Majestic RP.",
    "href": "/ti/ioc/sha256/7e42d25e707d29d5d185a4c5dc71019f744e88a30b66bbf06949194ff32dbc48",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "6cbd4bc491deb11040e2b2f91b0b4e129af551a802fc78cb42e0e985297ef44c",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for Majestic RP.",
    "href": "/ti/ioc/sha256/6cbd4bc491deb11040e2b2f91b0b4e129af551a802fc78cb42e0e985297ef44c",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972",
    "context": "SHA-256 of rmrp.dll first-stage NuGet downloader assembly (rmrp-x-x).",
    "href": "/ti/ioc/sha256/011926de3d0cc2b970627b9bf0de003e731f8576602dff756d2ab54a9de61972",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "d59e1914d76499fa51bf861f418c84bda0b48913dc39bd2e73756e326e4ccbb0",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for RMRP.",
    "href": "/ti/ioc/sha256/d59e1914d76499fa51bf861f418c84bda0b48913dc39bd2e73756e326e4ccbb0",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "5d9843126db4223dc2a8a9cd4a627286fe1a6345e33b28e9c98b5fe56fe89da6",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for RMRP.",
    "href": "/ti/ioc/sha256/5d9843126db4223dc2a8a9cd4a627286fe1a6345e33b28e9c98b5fe56fe89da6",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76a",
    "context": "SHA-256 of rusfish4.dll first-stage NuGet downloader assembly (rusfish4-x-x).",
    "href": "/ti/ioc/sha256/79c09e1ffb4804c14ff27d41ec08d4390455c92d65717be0aeeec2697297d76a",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "17b1d836c2f15a97be0350879943b04e14bc076cf09e31df0d73258ee10f7e7c",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for Russian Fishing 4.",
    "href": "/ti/ioc/sha256/17b1d836c2f15a97be0350879943b04e14bc076cf09e31df0d73258ee10f7e7c",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "c9f3e7766dbe728d84a1243447faa5f5eba0645bf13089074d128ea7663e7f5b",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for Russian Fishing 4.",
    "href": "/ti/ioc/sha256/c9f3e7766dbe728d84a1243447faa5f5eba0645bf13089074d128ea7663e7f5b",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854",
    "context": "SHA-256 of setup.dll first-stage NuGet downloader assembly (throne-x-x).",
    "href": "/ti/ioc/sha256/5f3a9ebf7039097b3cdbca8609b5b68af07eeb1dbf716ba2817a97fc7c543854",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "476c6f36a22156e53548a87291989a21d6c905dcbd9e1bf68ff5bc12e5c8bb07",
    "context": "SHA-256 of gtaobus.pyc entry module (direct bytecode) inside pepesoft.exe for Throne and Liberty.",
    "href": "/ti/ioc/sha256/476c6f36a22156e53548a87291989a21d6c905dcbd9e1bf68ff5bc12e5c8bb07",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1e",
    "context": "SHA-256 of trigger.dll first-stage NuGet downloader assembly (trigger-x-x).",
    "href": "/ti/ioc/sha256/23808e7638f7a00b1ef9b9f4ca524f8a46cf63be6f6b79fec8e4a3fd1cc82a1e",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27c",
    "context": "SHA-256 of gtaobus.pyc entry module (PyArmor-protected) inside pepesoft.exe for generic trigger-bot.",
    "href": "/ti/ioc/sha256/01d2afea0f2201a3b59765a1a60ba324ff4b8fdd25f23a0e05824b97f195b27c",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "a2a5e473dba85959b21b7e8a184bc255d5f2dacdf7411b91d212fb1217d2518b",
    "context": "SHA-256 of second-stage pepesoft.exe PyInstaller payload for generic trigger-bot.",
    "href": "/ti/ioc/sha256/a2a5e473dba85959b21b7e8a184bc255d5f2dacdf7411b91d212fb1217d2518b",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "sha256",
    "value": "ba7fc544994f126cb7485ce52d265d2f32e93c4f1ea1fcd6fcdee3918f271979",
    "context": "SHA-256 of 81d243bd2c585b0f4821__mypyc.cp313-win_amd64.pyd, a compiled charset_normalizer dependency identical across the 3 direct-bytecode payloads. BENIGN shared dependency, not malicious itself; recorded for correlation only.",
    "href": "/ti/ioc/sha256/ba7fc544994f126cb7485ce52d265d2f32e93c4f1ea1fcd6fcdee3918f271979",
    "campaigns": [],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "github_repo",
    "value": "github.com/pepegit666/123f53y45ysdf34",
    "context": "Operator pepegit666 GitHub repo used to stage the pepesoft.exe payload on GitHub Releases.",
    "href": "/ti/ioc/github_repo/github_repo-f955b0204793",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "calm-voice-9797.888c888x888.workers.dev",
    "context": "Cloudflare Worker URL passed to the payload as AWS_CONFIG_KEY; serves service.json (Google service-account creds + S3 config).",
    "href": "/ti/ioc/domain/calm-voice-9797.888c888x888.workers.dev",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "s3.ru-3.storage.selcloud.ru",
    "context": "Selectel S3-compatible object storage (bucket \"zfile\") used as service.json fallback and full read/write client via aiobotocore.",
    "href": "/ti/ioc/domain/s3.ru-3.storage.selcloud.ru",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "bots.pepesoft.ru",
    "context": "Operator paid-cheat storefront (Pepesoft brand).",
    "href": "/ti/ioc/domain/bots.pepesoft.ru",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "dns.google",
    "context": "LEGITIMATE Google DNS-over-HTTPS resolver (dns.google/resolve) abused to resolve any host containing \"github\" and connect to the returned IP directly, bypassing hosts-file/local DNS sinkholes. Legit service, low IOC value.",
    "href": "/ti/ioc/domain/dns.google",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "url",
    "value": "https://github.com/pepegit666/123f53y45ysdf34/releases/download/<tag>/pepesoft.exe",
    "context": "GitHub Releases payload staging URL (per-game <tag>). Second fallback in the staging chain.",
    "href": "/ti/ioc/url/url-f1fbae80bd88",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "url",
    "value": "https://huggingface.co/buckets/pepegit666/<tag>/resolve/pepesoft.exe?download=true",
    "context": "Hugging Face payload staging URL (per-game <tag>). First choice in the staging chain.",
    "href": "/ti/ioc/url/url-da1ab19f1230",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "ipv4",
    "value": "196.16.3.71",
    "context": "Authenticated HTTP proxy (port 9528, user X1U0z7 / pass ZHcUHN) used by the 8 PyArmor payloads to reroute Google Sheets traffic when direct access fails.",
    "href": "/ti/ioc/ipv4/196.16.3.71",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "telegram_bot",
    "value": "t.me/pepesoft777",
    "context": "Operator Telegram channel (Pepesoft brand).",
    "href": "/ti/ioc/telegram_bot/t.me/pepesoft777",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "discord_webhook",
    "value": "discord.com/api/webhooks/1156474517871403078/zuHl6xQzdMcFjNrmm9jTiHvCzNbCiQhkYAIGWNUfj7X4KUIpEATekKlSNna6OvyCKaRw",
    "context": "Discord webhook constant present in direct-bytecode apps. CAVEAT: writeup did NOT confirm an active send path.",
    "href": "/ti/ioc/discord_webhook/discord_webhook-f5adb62dee12",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "discord_webhook",
    "value": "discord.com/api/webhooks/1156474527874818088/qS5cJuxEbyIA1s3tZX_A2u6YsKtLUARVPvN77_6fK5QHGdGFHb3JSuCUSDhtouEsyJgk",
    "context": "Discord webhook constant present in direct-bytecode apps. CAVEAT: writeup did NOT confirm an active send path.",
    "href": "/ti/ioc/discord_webhook/discord_webhook-56df74e06f53",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "./libgg/chat_ids.txt",
    "context": "Stores Telegram chat IDs after /start in direct-bytecode aiogram RAT builds.",
    "href": "/ti/ioc/file_path/file_path-20c24c9c7759",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "%LOCALAPPDATA%\\Windows Src\\key*.txt",
    "context": "Activation-key storage used by pepesoft.exe.",
    "href": "/ti/ioc/file_path/file_path-1459c5d7f08c",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "./token.txt",
    "context": "Payload artifact.",
    "href": "/ti/ioc/file_path/file_path-bf16d25ecaa6",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "credentials.txt",
    "context": "Payload artifact.",
    "href": "/ti/ioc/file_path/file_path-4e1b775ea971",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "%APPDATA%\\pepesoft",
    "context": "Payload working/state directory (Pepesoft brand).",
    "href": "/ti/ioc/file_path/file_path-5855e72fa99c",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "file_path",
    "value": "pepesoft.exe",
    "context": "Shared PyInstaller (Python 3.13) second-stage host-surveillance payload dropped by all 11 downloaders.",
    "href": "/ti/ioc/file_path/file_path-827e8c2c445f",
    "campaigns": [
      "Pepesoft"
    ],
    "discovered_at": "2026-07-14"
  },
  {
    "kind": "domain",
    "value": "o4510485815754752.ingest.us.sentry.io",
    "context": "Attacker Sentry organization ingest host (org id o4510485815754752, US region). Shared across all 17 click2ai packages; per-namespace project ids segregate beacons for victim attribution.",
    "href": "/ti/ioc/domain/o4510485815754752.ingest.us.sentry.io",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "email",
    "value": "privatek3m@protonmail.com",
    "context": "Maintainer email of npm user click2ai, publisher of all 17 dependency-confusion packages.",
    "href": "/ti/ioc/email/privatek3m@protonmail.com",
    "campaigns": [],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511632071262208/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511632071262208). @flex-ng namespace. DSN public key: f4e0634481690329cda8e1396ffac3bc.",
    "href": "/ti/ioc/url/url-51ab5fa0fe17",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511630867824640/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511630867824640). @idms-corp namespace. DSN key truncated in source render; project id exact.",
    "href": "/ti/ioc/url/url-c1d146b73895",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511632708141056/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511632708141056). @logdna-web namespace (LogDNA/Mezmo lookalike). DSN key truncated in source render; project id exact.",
    "href": "/ti/ioc/url/url-d1f7c565250a",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511630928838656/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511630928838656). tme-* namespace (tme-xca, tme-xca-react). DSN public key: fa678d7e7f5b484dffe4d063d75fae55.",
    "href": "/ti/ioc/url/url-264c5f0a7bbb",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511621197856768/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511621197856768). tme-* namespace (tme-error) — a SECOND, distinct project for the same tme namespace. DSN key not captured; project id only.",
    "href": "/ti/ioc/url/url-fa265304db5a",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511675212038149/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511675212038149). enbd-* namespace (Emirates NBD lookalike) AND box-react-uix — a SHARED project across two namespaces (flagged discrepancy). DSN key truncated (abbfc1...8f4b).",
    "href": "/ti/ioc/url/url-94cb5f69ff0b",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511664042999808/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511664042999808). sams-* namespace. DSN key not captured; project id only.",
    "href": "/ti/ioc/url/url-100f9725e207",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511709729914880/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511709729914880). chat-adapter-zoom (Zoom chat-adapter lookalike). DSN key truncated (ab3ba4...ee89).",
    "href": "/ti/ioc/url/url-29404e17a0ba",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "url",
    "value": "https://o4510485815754752.ingest.us.sentry.io/api/4511716882972672/envelope/",
    "context": "Per-namespace attacker Sentry envelope beacon endpoint (project id 4511716882972672). Salesforce SLDS namespace (salesforce-vscode-slds, slds-lsp-client). DSN key truncated in source render; project id exact.",
    "href": "/ti/ioc/url/url-49cd7c6e1533",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-07-13"
  },
  {
    "kind": "sha256",
    "value": "fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd",
    "context": "Linux ELF x86-64 payload extracted from dist/intro.js binary container. Rust-compiled infostealer, dynamically links libbpf.so.1. 4.31 MB decompressed.",
    "href": "/ti/ioc/sha256/fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "sha256",
    "value": "b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903",
    "context": "Windows PE x86-64 payload extracted from dist/intro.js binary container. Rust-compiled infostealer targeting Chrome, Chromium, Brave, Edge, Bitwarden extension, Steam sessions. Task Scheduler persistence. 4.92 MB decompressed.",
    "href": "/ti/ioc/sha256/b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "sha256",
    "value": "c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd",
    "context": "macOS Mach-O arm64 payload extracted from dist/intro.js binary container. Rust-compiled infostealer with LaunchAgent persistence (RunAtLoad, KeepAlive, 30s StartInterval). 3.04 MB decompressed.",
    "href": "/ti/ioc/sha256/c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "sha256",
    "value": "9eeffcb5c3445ef9512f7776045f99ea23f9ebed989f8570bc4634b4e340de5d",
    "context": "Hash embedded within the Windows PE payload binary. Purpose unknown from static analysis; possibly a configuration integrity check or payload identifier.",
    "href": "/ti/ioc/sha256/9eeffcb5c3445ef9512f7776045f99ea23f9ebed989f8570bc4634b4e340de5d",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "sha256",
    "value": "a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86",
    "context": "dist/intro.js binary payload container (7.8 MB). Byte-identical across all 5 compromised versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0). Custom binary format (magic \\x1bCSI\\x01) containing gzip-compressed Rust-compiled infostealers for Linux, Windows, and macOS.",
    "href": "/ti/ioc/sha256/a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "sha256",
    "value": "a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60",
    "context": "dist/setup.js preinstall dropper script. Byte-identical across 8.14.0, 8.16.0, and 8.17.0. Reads the binary container, decompresses platform-matched payload, spawns detached.",
    "href": "/ti/ioc/sha256/a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60",
    "campaigns": [],
    "discovered_at": "2026-07-11"
  },
  {
    "kind": "domain",
    "value": "api.348672-shakepay.com",
    "context": "C2 / exfiltration domain shared across all three exfil paths. Impersonates the 'Shakepay' brand name but is NOT registered infrastructure of the real Shakepay (shakepay.com). Passive DNS shows Cloudflare anycast (104.21.89.51, 172.67.188.32), consistent with attacker origin-hiding behind Cloudflare. All three endpoints use the shared header X-Api-Key: 2523-5235-8564-2683-2386.",
    "href": "/ti/ioc/domain/api.348672-shakepay.com",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://api.348672-shakepay.com/api/card",
    "context": "PAN/CVV/card-data exfiltration endpoint (Braintree.CardOperationLogger). Stored as a PLAINTEXT string constant in Braintree.dll (no obfuscation). POST manually-concatenated JSON with header X-Api-Key: 2523-5235-8564-2683-2386, in an empty catch.",
    "href": "/ti/ioc/url/url-179e8da96452",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://api.348672-shakepay.com/api/account",
    "context": "Braintree merchant-key exfiltration endpoint (GatewayInput.AddAccountAsync, fired from the PrivateKey setter). Stored as a PLAINTEXT string constant in Braintree.dll. POSTs MerchantId+PublicKey+PrivateKey as JSON with header X-Api-Key: 2523-5235-8564-2683-2386.",
    "href": "/ti/ioc/url/url-717e4a7c2cf2",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://api.348672-shakepay.com/api/analytics/report",
    "context": "Environment/config/cloud-secret exfiltration endpoint (DependencyInjector.Core AnalyticsReporter.ReportAsync). XOR-OBFUSCATED at rest: 52-byte ciphertext blob (hex 220F582D6DB51544FD7D3701497F24BB7D49012E76EE510EEC6C2701192471A22B0B45727FE15B07E579374C09646EE83A145E29) in AnalyticsOptions static ctor, decoded at runtime by EndpointObfuscator.Decode with repeating-key XOR key 4A7B2C5D1E8F3A6B9C0D5E2F7A4B1C8D (recovered from DependencyInjector.Core 1.4.1 net10.0 build). A naive strings/XOR scan of the DLL surfaces only the plaintext /api/card and /api/account endpoints, not this one.",
    "href": "/ti/ioc/url/url-8f26e0e66f1c",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "ipv4",
    "value": "104.21.89.51",
    "context": "Cloudflare anycast address in passive DNS for api.348672-shakepay.com. Source frames this as origin-hiding, NOT the true attacker origin IP. Low value in isolation.",
    "href": "/ti/ioc/ipv4/104.21.89.51",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "ipv4",
    "value": "172.67.188.32",
    "context": "Cloudflare anycast address in passive DNS for api.348672-shakepay.com. Source frames this as origin-hiding, NOT the true attacker origin IP. Low value in isolation.",
    "href": "/ti/ioc/ipv4/172.67.188.32",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "7a9f19ed663c1d4ee259ba0a10e93e1c9770812ce81f8c945140a452d17cb3c8",
    "context": "Braintree.dll malicious build (1 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/7a9f19ed663c1d4ee259ba0a10e93e1c9770812ce81f8c945140a452d17cb3c8",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "f181d57c29364aef01e3f72051ec2dc0da918d346e7e4d1377e13408afb8663a",
    "context": "Braintree.dll malicious build (2 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/f181d57c29364aef01e3f72051ec2dc0da918d346e7e4d1377e13408afb8663a",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "220908e8c23c2332266ba1e984f839b9914c2e40a946b172f6d9b8b36728f98a",
    "context": "Braintree.dll malicious build (3 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/220908e8c23c2332266ba1e984f839b9914c2e40a946b172f6d9b8b36728f98a",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "86d287eafecd542faec21a95522b3425000ae5d8650813a9987b7c10cf90fc7a",
    "context": "Braintree.dll malicious build (4 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/86d287eafecd542faec21a95522b3425000ae5d8650813a9987b7c10cf90fc7a",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "5cae5ec54f450ef7483e265d289edc3877c17e3ae508c06e1679371aa1c1306f",
    "context": "Braintree.dll malicious build (5 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/5cae5ec54f450ef7483e265d289edc3877c17e3ae508c06e1679371aa1c1306f",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "d6fbfada62639578b6a6e91786928705dd22bb14b0f030504ffbc974e23528bc",
    "context": "Braintree.dll malicious build (6 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/d6fbfada62639578b6a6e91786928705dd22bb14b0f030504ffbc974e23528bc",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "e0c7797e7dba2056bc95bfddb96d9f07afb93988f108bc417c40cd05f7ae49a4",
    "context": "Braintree.dll malicious build (7 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/e0c7797e7dba2056bc95bfddb96d9f07afb93988f108bc417c40cd05f7ae49a4",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "064653872c1b4c3d5b5242627cda259056fed7159fcd2cc5a448981c9f81aeda",
    "context": "Braintree.dll malicious build (8 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/064653872c1b4c3d5b5242627cda259056fed7159fcd2cc5a448981c9f81aeda",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "2547382cd5151e2210c6349f17230ae3d1a59935e3b8d1757d72d9abd30ac858",
    "context": "Braintree.dll malicious build (9 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/2547382cd5151e2210c6349f17230ae3d1a59935e3b8d1757d72d9abd30ac858",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "52aeb64f4199235704d0e4a6908c501c3b4bdd4a004a766a5ca55b9655b24775",
    "context": "Braintree.dll malicious build (10 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/52aeb64f4199235704d0e4a6908c501c3b4bdd4a004a766a5ca55b9655b24775",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "9dff477e6d30872669bb6186c67147a945d9de7e947eb7906afdb03c93901ead",
    "context": "Braintree.dll malicious build (11 of 11 hashes source labels for Braintree.dll).",
    "href": "/ti/ioc/sha256/9dff477e6d30872669bb6186c67147a945d9de7e947eb7906afdb03c93901ead",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "efec1e537445170a9aac11781c597cba5bd5d25b79ac3d65467d84f109d86fd4",
    "context": "DependencyInjector.Core.dll malicious build (1 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/efec1e537445170a9aac11781c597cba5bd5d25b79ac3d65467d84f109d86fd4",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "7c30f007af910886b46f6022dd724dd303ad2d5f983376d0547293f484d6ae71",
    "context": "DependencyInjector.Core.dll malicious build (2 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/7c30f007af910886b46f6022dd724dd303ad2d5f983376d0547293f484d6ae71",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "9d8d79000f6413668429d851f7d8ce94cd1b61c3a421939cf34cec8d668f5388",
    "context": "DependencyInjector.Core.dll malicious build (3 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/9d8d79000f6413668429d851f7d8ce94cd1b61c3a421939cf34cec8d668f5388",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "c9564621abec9bdb7ceb38bb1a2895a119772b7f830351272c13a3f4cd606b97",
    "context": "DependencyInjector.Core.dll malicious build (4 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/c9564621abec9bdb7ceb38bb1a2895a119772b7f830351272c13a3f4cd606b97",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "f53359313ce9a9433651202a7ffbf155dc1379103796a45492a50edbf044d59d",
    "context": "DependencyInjector.Core.dll malicious build (5 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/f53359313ce9a9433651202a7ffbf155dc1379103796a45492a50edbf044d59d",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "b4a5bcf4ce8c9cc844c06f436d4c26b28cb408f7e4fd8990681336445493acc1",
    "context": "DependencyInjector.Core.dll malicious build (6 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/b4a5bcf4ce8c9cc844c06f436d4c26b28cb408f7e4fd8990681336445493acc1",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "531302fe3b8a8624aa468ee83707448fbd1db2eaa3f8d587331db2b17890f8ad",
    "context": "DependencyInjector.Core.dll malicious build (7 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/531302fe3b8a8624aa468ee83707448fbd1db2eaa3f8d587331db2b17890f8ad",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "bfdaf869a3956b37bf416dcdafdad314e8de0215cfd8fd8b2bc7a4e5cd15a349",
    "context": "DependencyInjector.Core.dll malicious build (8 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/bfdaf869a3956b37bf416dcdafdad314e8de0215cfd8fd8b2bc7a4e5cd15a349",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "5138ea25563be4ae8143b7a46c6bc42af00344678e6d4451ac596b5b5587c70e",
    "context": "DependencyInjector.Core.dll malicious build (9 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/5138ea25563be4ae8143b7a46c6bc42af00344678e6d4451ac596b5b5587c70e",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "eceab1132aacd803962fa173d1b2c43e225fcfa8b5d26d3efadad1b4de33d8ec",
    "context": "DependencyInjector.Core.dll malicious build (10 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/eceab1132aacd803962fa173d1b2c43e225fcfa8b5d26d3efadad1b4de33d8ec",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "de6384e853dfc007205abb7b15b49eded2e3e977058600dece2c2e9190a5191a",
    "context": "DependencyInjector.Core.dll malicious build (11 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/de6384e853dfc007205abb7b15b49eded2e3e977058600dece2c2e9190a5191a",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "c3be125753aea85728a082823db77d833377d7e3eb199364aa49d1ff2535f53e",
    "context": "DependencyInjector.Core.dll malicious build (12 of 12 hashes source labels for DependencyInjector.Core.dll).",
    "href": "/ti/ioc/sha256/c3be125753aea85728a082823db77d833377d7e3eb199364aa49d1ff2535f53e",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "domain",
    "value": "testnet.archival.chain.grpc-web.injective.network",
    "context": "Exfiltration endpoint. A LEGITIMATE Injective Labs public infrastructure hostname abused so exfil traffic blends with normal SDK usage and evades network-based detection. Character-obfuscated in the on-disk payload, reconstructed at runtime. No backing IP given by source.",
    "href": "/ti/ioc/domain/testnet.archival.chain.grpc-web.injective.network",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://testnet.archival.chain.grpc-web.injective.network",
    "context": "HTTPS POST target. base64-encoded wallet mnemonic / private-key material sent here.",
    "href": "/ti/ioc/url/url-f4244828101d",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0",
    "context": "Bundled build output /dist/cjs/accounts-Cy0p4lLW.cjs inside @injectivelabs/sdk-ts@1.20.21 (CommonJS build of the stealer). Not the package tarball hash (source did not publish a tarball hash).",
    "href": "/ti/ioc/sha256/103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9",
    "context": "Bundled build output /dist/esm/accounts-jQ1GSgaW.js inside @injectivelabs/sdk-ts@1.20.21 (ESM build of the same stealer). Not the package tarball hash.",
    "href": "/ti/ioc/sha256/9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "file_path",
    "value": "/dist/cjs/accounts-Cy0p4lLW.cjs",
    "context": "CommonJS build output carrying the injected trackKeyDerivation stealer.",
    "href": "/ti/ioc/file_path/file_path-46e407dff05a",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "file_path",
    "value": "/dist/esm/accounts-jQ1GSgaW.js",
    "context": "ESM build output carrying the injected trackKeyDerivation stealer.",
    "href": "/ti/ioc/file_path/file_path-40027fa160ff",
    "campaigns": [],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "domain",
    "value": "peach-eligible-penguin-917.mypinata.cloud",
    "context": "Pinata IPFS gateway, stage-2 host fetched by tslint-conf lib/caller.js (same CID shared with first-pair nodemon-node per SafeDep)",
    "href": "/ti/ioc/domain/peach-eligible-penguin-917.mypinata.cloud",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://peach-eligible-penguin-917.mypinata.cloud/ipfs/bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu",
    "context": "Full stage-2 URL; IPFS CID bafkreigjnxn5vnn34rc5r43ajwwkmk4akqpm4awmq5gdhakgszpeqiffsu. GET with header x-secret-key: _, response .cookie eval'd via Function.constructor. Stage-2 deliberately NOT fetched.",
    "href": "/ti/ioc/url/url-bdd77572dddf",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://jsonkeeper.com/b/XRGF3",
    "context": "Active dead-drop in tslint-conf lib/caller.js; SafeDep: same dead-drop referenced by first-pair nodemon-node",
    "href": "/ti/ioc/url/url-701bed71dcb4",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "url",
    "value": "https://jsonkeeper.com/b/4NAKK",
    "context": "Orphaned base64 dead-drop in tslint-conf lib/const.js (unreferenced); reused tooling linking the new pair to the first pair",
    "href": "/ti/ioc/url/url-9f4fc969fe0b",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "domain",
    "value": "jsonspack.com",
    "context": "Forged-author domain on tslint-conf (author Alexus111 <hello@jsonspack.com>, bugs URL jsonspack.com/issues); campaign namesake",
    "href": "/ti/ioc/domain/jsonspack.com",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "email",
    "value": "coxhazelqja151@outlook.com",
    "context": "npm maintainer email for account conodeeth, publisher of all four packages",
    "href": "/ti/ioc/email/coxhazelqja151@outlook.com",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "email",
    "value": "hello@jsonspack.com",
    "context": "Forged author email (Alexus111) on tslint-conf@7.2.1",
    "href": "/ti/ioc/email/hello@jsonspack.com",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "aa9b9847e4ffd894a19ec9712848651882b0195de5f4953eef9b47791adddabf",
    "context": "nodemon-sudo@3.1.16 npm tarball (registry.npmjs.org/nodemon-sudo/-/nodemon-sudo-3.1.16.tgz)",
    "href": "/ti/ioc/sha256/aa9b9847e4ffd894a19ec9712848651882b0195de5f4953eef9b47791adddabf",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "d4b7add83e5c716b5e52082f713d71ec9d7bfd93e358d500d77c2393302dd004",
    "context": "tslint-conf@7.2.1 npm tarball (registry.npmjs.org/tslint-conf/-/tslint-conf-7.2.1.tgz)",
    "href": "/ti/ioc/sha256/d4b7add83e5c716b5e52082f713d71ec9d7bfd93e358d500d77c2393302dd004",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "2956b023858d706a5e241cd28b845088e5f414c5f70bd5d8cb73cb427d081065",
    "context": "tslint-conf index.js (fake pino/express middleware main)",
    "href": "/ti/ioc/sha256/2956b023858d706a5e241cd28b845088e5f414c5f70bd5d8cb73cb427d081065",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "541c35bd90653c9d7f93cdadb7f52c281d7a1375ffc9c0e118cf1d9df977dea7",
    "context": "tslint-conf lib/caller.js (stage-2 fetch + Function.constructor RCE)",
    "href": "/ti/ioc/sha256/541c35bd90653c9d7f93cdadb7f52c281d7a1375ffc9c0e118cf1d9df977dea7",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "sha256",
    "value": "d10853dde92fdc48d8cb5505d89e0030fd35e1416a16a820fe5ec4aceef01c4f",
    "context": "tslint-conf lib/const.js (orphaned; carries jsonkeeper b/4NAKK dead-drop)",
    "href": "/ti/ioc/sha256/d10853dde92fdc48d8cb5505d89e0030fd35e1416a16a820fe5ec4aceef01c4f",
    "campaigns": [
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-07-09"
  },
  {
    "kind": "domain",
    "value": "muckcoding.com",
    "context": "Initial hidden-PowerShell Invoke-WebRequest host (Api-Certificate) and dead-drop-adjacent Muck infrastructure.",
    "href": "/ti/ioc/domain/muckcoding.com",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "domain",
    "value": "muckdeveloper.com",
    "context": "Primary dead-drop payload-location source (LGTV/MicrosoftCur).",
    "href": "/ti/ioc/domain/muckdeveloper.com",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://muckcoding.com/LG-LW/Api-Certificate",
    "context": "First-stage: fetched by hidden PowerShell, saved to C:\\Users\\Public\\Pictures\\api.db then certutil-decoded to L.ps1.",
    "href": "/ti/ioc/url/url-370c53d0dee4",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://muckdeveloper.com/LGTV/MicrosoftCur",
    "context": "Primary dead-drop source read by the L.ps1 resolver.",
    "href": "/ti/ioc/url/url-74f777de7e38",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://pastebin.com/raw/xy32SJgf",
    "context": "Primary dead-drop source (Pastebin raw).",
    "href": "/ti/ioc/url/url-b64439034747",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://rlim.com/MicrosoftCur/raw",
    "context": "Primary dead-drop source (Rlim raw).",
    "href": "/ti/ioc/url/url-d8c288ccfede",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://youtu.be/GAS67zAOssc",
    "context": "Fallback dead-drop source (YouTube).",
    "href": "/ti/ioc/url/url-a272f868265d",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://www.instagram.com/p/DG20Zt9Mj4P/",
    "context": "Fallback dead-drop source (Instagram post).",
    "href": "/ti/ioc/url/url-1a5c2138801a",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://t.me/s/dwmic",
    "context": "Fallback dead-drop source (Telegram channel preview).",
    "href": "/ti/ioc/url/url-da059b7d1874",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://docs.google.com/document/d/1PnogKWvfa3ZcCnmKfnb3pJYXMBmcQe5k_6bBuPUailQ/export?format=txt",
    "context": "Fallback dead-drop source (Google Docs text export).",
    "href": "/ti/ioc/url/url-c5c8efd2f41a",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://gitcode.com/LastWer/MicrosoftCur/raw",
    "context": "Fallback dead-drop source (GitCode raw).",
    "href": "/ti/ioc/url/url-9570f249da5a",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "url",
    "value": "https://github.com/tb78/expresso/releases/download/Release/Quixo.7z",
    "context": "Resolved next-stage payload: password-protected 7z (r8NnX1b8Xn) hosted as a GitHub release asset.",
    "href": "/ti/ioc/url/url-44b413483f64",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "email",
    "value": "ischhfd83@rambler.ru",
    "context": "Threat-actor git commit email; constant across the 222 lure repos and the shared pivot with Sophos's prior ischhfd83 cluster.",
    "href": "/ti/ioc/email/ischhfd83@rambler.ru",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "file_path",
    "value": "C:\\Users\\Public\\Pictures\\api.db",
    "context": "certutil-encoded first-stage blob saved by the initial hidden PowerShell.",
    "href": "/ti/ioc/file_path/file_path-88d3ad3f9027",
    "campaigns": [],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "file_path",
    "value": "C:\\Users\\Public\\Pictures\\L.ps1",
    "context": "Decoded multi-layer PowerShell loader, executed with -ExecutionPolicy Bypass and a hidden window.",
    "href": "/ti/ioc/file_path/file_path-e58d1a1e8535",
    "campaigns": [],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "file_path",
    "value": "C:\\Users\\Public\\Documents\\umun\\",
    "context": "Download directory for the resolved Quixo.7z payload archive.",
    "href": "/ti/ioc/file_path/file_path-67e527b7db1f",
    "campaigns": [],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "file_path",
    "value": "C:\\ProgramData\\zipathh\\7zrr.exe",
    "context": "Staged 7-Zip extractor used to unpack the password-protected Quixo.7z.",
    "href": "/ti/ioc/file_path/file_path-f7cd19bf79b9",
    "campaigns": [],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "file_path",
    "value": "C:\\ProgramData\\Windows.Microsoft.Photos\\current\\Microsoft.exe",
    "context": "Electron/Squirrel masquerade launcher (reported signed 'Exodus Movement, Inc.') launched hidden from a Photos-app masquerade directory.",
    "href": "/ti/ioc/file_path/file_path-4a824e8ac12d",
    "campaigns": [],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff",
    "context": "Layer 1 encrypted PowerShell blob.",
    "href": "/ti/ioc/sha256/129de16fe69763f767d8249279a2c4a1a6deafadd1a84563bd84b258ea010bff",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c",
    "context": "Layer 1 decrypted PowerShell script.",
    "href": "/ti/ioc/sha256/86819efe7319b664920ba2e1fd4b079a4e6b5eaaebeeb1adb2c1c8dc3c81ee0c",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629",
    "context": "Layer 2 encrypted PowerShell blob.",
    "href": "/ti/ioc/sha256/57e0449fb13766b0b2f7c057b1f89911e9ed23cac7e71d5d69fde47571239629",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63",
    "context": "Final visible decoded PowerShell loader logic.",
    "href": "/ti/ioc/sha256/e576a61e1a2ba71e764647bb2f0883c2f8fa4d591799c60d21a84230ee7a5b63",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807",
    "context": "Encrypted payload-location blob (dead-drop, decrypted with key UIA14fogylw8ogL82FntOFGp6).",
    "href": "/ti/ioc/sha256/51cada347262d7b2bcde70552fcdae221625ad75435cee8a9c3e7b67cc47a807",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fe",
    "context": "Decoded PowerShell stage associated by Socket with AsyncRAT/Quasar detections + spyware/infostealer/trojan/persistence/defense-evasion/discovery/execution activity.",
    "href": "/ti/ioc/sha256/969b0bfd605aa2cddf353f3638b0dee26b1c2305600231e055fa6d7786a879fe",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "73c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2",
    "context": "Recovered Quixo.7z payload archive.",
    "href": "/ti/ioc/sha256/73c807df26427d6631088a822fa54c30975afbe681a9d83eff5d19e5b075d6c2",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4",
    "context": "Related GitHub-hosted Quixo.7z sample mapping to Remcos-style RAT activity.",
    "href": "/ti/ioc/sha256/a628ad47fe93ee7413cca90aeca8f9540bfcd5ccdbeb4d9914670b3ef66247f4",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4",
    "context": "Recovered current\\Microsoft.exe Electron masquerade launcher.",
    "href": "/ti/ioc/sha256/4ea1c577247b149489506b230e7aa203e1a2fa124109c6056d1986e944f520a4",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/235a64e3520b1c2c27763122b303f78aee8d7c083dfd9f1eb936cd5174383609",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "2f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7d",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/2f416aac027f19f563cc45e3b4b72e992aaafb63da27f968b9a76a391134dc7d",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "33497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/33497c69c21fa96bbc96f1d7f09608e462f8ab22555364977c0bd35fef27bc29",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/45126b353f1636103da356121cd00b229b635b41b99d91166e6d7d9037482242",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/810614290bdb14d2ddf10f65f8adc988a8272764f2a9e2c378e52fad162da344",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/938054c6bb7dc737fce16513b2882808f199c2f892f808d439525a1650d49089",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "9df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/9df11356c5ac61d2aa7b5425e6322fc016b0ed5790dacb201396500b3eee03f7",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7a",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/a2e7989742c6b6436ebb47507881946e4f662080dff71d104eb9a9554f38af7a",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "b27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005e",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/b27f694c974b44fe2f4a8a25680997db574fa35686c30fa4c4dc9dd4ec40005e",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/d7747e7a3c782009f4ceb6e9c106115876386853929563b509da5258e3968d15",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/d95bba20f04687b0b821d4fc0a17137db8b9eda5fe3fb34da319abefc45fe0d1",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acad",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/e73491065d86b1ad69229bb5d2019e08b947e11a2a57adf5c2d9a2b5d8f4acad",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783f",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/ec1cac2ada6726623b4bafb94c204c359ce7cdf5325909137fc0e6aef506783f",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "sha256",
    "value": "f245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4",
    "context": "Malware sample from a threat-actor-controlled GitHub lure repo.",
    "href": "/ti/ioc/sha256/f245956c930f220f0bedf355a751a5cd738b4ec6bb6c5d584199ab3fa6c0a1c4",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "github_repo",
    "value": "kaleidora/dnsub-scanning-tool",
    "context": "GitHub repo backing the malicious Go module; entry point of the operation.",
    "href": "/ti/ioc/github_repo/github_repo-1f5c4b929fcb",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "github_repo",
    "value": "tb78/expresso",
    "context": "Hosts the resolved Quixo.7z payload as a GitHub release asset.",
    "href": "/ti/ioc/github_repo/github_repo-86d9bbfa8ac6",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "github_repo",
    "value": "nrevv1lad/Pubg-DESYNC-Menu",
    "context": "Named example lure repo: fake external PUBG cheat hosting Loader.exe in source tree, associated with Vidar infostealer. One of 222 confirmed threat-actor-workflow repos.",
    "href": "/ti/ioc/github_repo/github_repo-dd5c50373c3a",
    "campaigns": [
      "Operation Muck and Load"
    ],
    "discovered_at": "2026-07-08"
  },
  {
    "kind": "domain",
    "value": "caliber-spinner-finishing.ngrok-free.dev",
    "context": "ngrok tunnel hostname used as C2 / exfiltration endpoint. Recovered at runtime via three-step decode (base64 XOR + per-char subtract-17 + string reverse). The backing IP (not published in source) reportedly carried prior reputation as C2 for other stealers including NjRAT (per Socket).",
    "href": "/ti/ioc/domain/caliber-spinner-finishing.ngrok-free.dev",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "url",
    "value": "https://caliber-spinner-finishing.ngrok-free.dev:443/",
    "context": "Full C2 URL. Harvested env vars + host metadata POSTed here as application/json over HTTPS.",
    "href": "/ti/ioc/url/url-5272b664daa9",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682c",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/ce09810adca70ebec87bc455380ef629ceaa2a0d926149d9115604060167682c",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57ea",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/b2ea8d69f6792a87327ffde2ee4551bb6b99617f53e1ba71bf9a70f45dbc57ea",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "8a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/8a70a5c1075f2dea4db94633ddc64b0d03d0385fdeda7c226acc944331febf43",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/c8b4d17c1f0aa7c50f2fa23d7c328482a4ad2c4da4d600f358ebdf200cbefd83",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "9fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cf",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/9fd06d823d54183cc91625fdc6decffe8db2863f6499a955656ebdcc089792cf",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/615805652b2f006e69512b90d0d63883d7ae1ede69d86384fd77bd46235b2369",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "6dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/6dc672e3bab8bcf80c66b2f95150067fb47429d4cf65eb95215e5f3abc7cade5",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "4a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/4a4b5c1bc1e948c853cb0978c07c7b8d1540c7b1ded95f8d5ad25c126cb6c7b0",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "9727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/9727c804c4354e481d2ff9d4934bd1b2518293a9ca34a14f5c7ae9d0cd30ce94",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/313853a82bce61052c00e6a6af85b5069e007a76122c727f31661bc636b12f14",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/2cbfc4e4b1de5e68ab81fba7e1b0c711b4d26197b48ea4db6819c9cea223b0ed",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120c",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/a0313822513f9b89479f666888a4784a3fc99b4cc4566213dcda66b03b47120c",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "3a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/3a0dd3479eaf85b65e5abd63d6451f98506faddee47cf4bebd9f91296abb29f0",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "39371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/39371ac7061168dd3d890061267b3875bc4b30dca5e28d40dbc27a4396439ff1",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/c51c0b6c7817443b021aff44d4416c09fd039849db81860b9b5144e789fa3987",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "6e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/6e251c3d2bde8fff0487c1eecd359c4a544a09fd708755020e4b1c53ad6b8dd1",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723ad",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/cd7255730b6a7a3895d622d37d0e8f984d2d280689acef56ff195d663e7723ad",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "5c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/5c4faef80c83c7ec0925a4aacb4bddabe82b91066ac41305907ba277cd7b3b85",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "50cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/50cb7550224d8d227a0625e7f53be86924d8e057e403b6b91b83ea20df834048",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "1bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bc",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/1bae9f2fb9866422f07345501fa2cb4c3a99f2652c8c9decdc27ffbf9714e7bc",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "1df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501b",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/1df8c579ffcbf5527b1856bd1774601a5188b380e442c5a0fbd400bd86a4501b",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aad",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/b29973eda4d0c090608c15a976688cad0b2114fdc0dcb89ad37515287ba13aad",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "9e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/9e9655f54bfac8a937d78ac506722bae1468ead4cc9ee95b35e0f8ef17ee13d9",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "67e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/67e4d6a4f53098e48bfa6ecceeaa754592bc249b83404bcfb8542977ae36dac4",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "1bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/1bfa32548676d32b7639d3171e2f9feefba5026dc336968c91f4ae2b152c5410",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "2bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bd",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/2bc8af4bd2f539630f7800f3491b64c7e2bffe12e955d0d4f03a4f6a4b0018bd",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bcc",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/eae055c5736366811d2a4b1f78ff206486e7f7445040122efbe023ecd2d20bcc",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/d4ed2d87942fbefa5d7b7f19fb6f2e9bc293c96bf577bb97ed3ca56185abcf25",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/447484c76a06918d7f6f6c6f95ee2bced6dd2e9b282c6f5b92b2b7c0976381d5",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/f43cb68850a2506805d60ff466f54eba331e1cc2a513b329f5121e0c39104418",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "1314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/1314fc888ca5b3ea91a04e1f5b63039ffc7fc3832b8d809a28ad549c6f9d4f23",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/af66bc2b516d1ef71af9b6ee9f8f5af0a99fed562b34809cd55071b94c2d1304",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/b157a66826d27512c3618817fee924e53d14cabb2c4c7f454affde37350f55f0",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "2303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/2303a74a5fac917279f1078e03a4bfd6afbb89462f97d7344ed10e6e9e9e92b7",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "5242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/5242c5086d75a492d14e474de7c8f34b18ec0a8a9ce6d77eec8675a9572d9d23",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "1d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/1d567795a366b9edcfef7f1fa2d398b7cb41890dd3b2f3f1f9803de0cdba0c89",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/c2e4483abea830ba8b8230540ace51788d0712bed9006697ddddb9cbf133c151",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/390bca9d70efa42cb792f7f677189821a24527cd4298ab2acb954df0abb5c1c3",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35ca",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/f7d9865ea3874d2b135eeee0aa0d12fc108d89e1dd706e4e40eb7605b76d35ca",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "2b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/2b7696575278e6e223cc44553c687e45afd04df7eb32efbf49b39da64b795982",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "2edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213d",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/2edb3f162f9676196e818d9b795d599ba119a961ffe98c4866351735980d213d",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/727fe9c1dfa39d6590012e0593c9837c628fc2cd22aa0f4e486b7ed1aec02697",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "8a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188b",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/8a58e3ed713c1c70f421ab56a18cfb6a120c960d227e495b511c2552f25f188b",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "67eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/67eb3bd505ebfffbd73fc3ef0b2976c375df732f0bd0496ed6653c3e2be5a0e5",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528e",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/616b41657e9afaa9354fc1a106393373dcbf8aac8455b7d2cbbb44463434528e",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "52a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/52a57c502e40b3f9897d0ca32bba6f844b4113f5c017627ea9eba660eb47f405",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/d1889d81cfa99d52017732da9dc52127d03893037874c8671943cede4b8d1bb2",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/a677c02e545941e43f8b21a5761b035e911b53e2c065fea219e0f3462f282fd8",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/e076e13a7e112d364f03bd1ead7abaa83249d544491621254860ab0a73adc9b9",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023de",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/c2a69a33b086364ca51b030b6b15e99be46ce8255ddf62839a4fc7f2b34023de",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "5cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/5cd62e708ae4393c99579ec1433571998299bf7e2fde9bafeb9a79f8bdf065e9",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "61b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63",
    "context": "npm index.js payload build variant (per-file rotated obfuscation key). Source published 50 index.js hashes across the 13 npm packages / ~4 versions each without a per-package/version mapping.",
    "href": "/ti/ioc/sha256/61b61dd25cd8dcc43cd78418f3e3eb3fd9002d9e49961eefb12c1022ce4c3b63",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2b",
    "context": "PyPI __init__.py payload (one per PyPI package). Source published 4 hashes without a per-package mapping.",
    "href": "/ti/ioc/sha256/c6af37a6739f0d919ab7049caf3a85831cab44bdbea27e0d9de7adec80334e2b",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785",
    "context": "PyPI __init__.py payload (one per PyPI package). Source published 4 hashes without a per-package mapping.",
    "href": "/ti/ioc/sha256/b04daeacd1d1c9020cce2a97fa7af83dbedf4e6d17dd12c0f337f32240399785",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5",
    "context": "PyPI __init__.py payload (one per PyPI package). Source published 4 hashes without a per-package mapping.",
    "href": "/ti/ioc/sha256/dabb47d75f2efa6a5540661484efa989ccb338f24938b23152f14f3e424b0cb5",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "sha256",
    "value": "c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1",
    "context": "PyPI __init__.py payload (one per PyPI package). Source published 4 hashes without a per-package mapping.",
    "href": "/ti/ioc/sha256/c2a361a7d8feb95be97c957fc7652d348f4fa9a987bde5f09883f46b65c460f1",
    "campaigns": [],
    "discovered_at": "2026-07-07"
  },
  {
    "kind": "domain",
    "value": "v3.jiathis.com",
    "context": "Payload server. Hijacked JiaThis social sharing service domain (Beijing, 2009). Re-registered through GoDaddy, routed via Cloudflare. Serves gambling redirect payload on jia.js path with Referer gating. art.js path returns 404 as of 2026-07-03. Shared Cloudflare nameservers (paislee/sean) with mki.mom.",
    "href": "/ti/ioc/domain/v3.jiathis.com",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "test.airsplu.cn",
    "context": "Gambling redirect destination. Chinese gambling/adult content portal (2026 World Cup Navigation). Huawei CDN (45.197.102.29). Beijing timezone-gated redirect: 7PM-6AM 100%, daytime 30%.",
    "href": "/ti/ioc/domain/test.airsplu.cn",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "s5gw.mki.mom",
    "context": "Gambling portal backend. CNAME to 500info.win (Azure). Shares Cloudflare nameservers (paislee/sean) with jiathis.com, indicating same Cloudflare account. Baidu Analytics tracker a29b02d841cccc4c4b32f9c5dbebb0b0.",
    "href": "/ti/ioc/domain/s5gw.mki.mom",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "s5dh.club",
    "context": "Gambling portal. 301 redirect to s5gw.mki.mom. Azure IPs (20.239.154.185, 20.2.192.146). Registered 2025-02-19 via GoDaddy.",
    "href": "/ti/ioc/domain/s5dh.club",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "500info.win",
    "context": "CNAME load balancer target for s5gw.mki.mom. DNS-only, no A record.",
    "href": "/ti/ioc/domain/500info.win",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "l1ewsu3yjkqeroy.xyz",
    "context": "Former C2 sync endpoint (Phase 2). Cloudflare-fronted. /api/ip-sync/sync POST every 10s with channelCode CHMK6IG08F42496C22. DEAD as of 2026-07-03.",
    "href": "/ti/ioc/domain/l1ewsu3yjkqeroy.xyz",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "domain",
    "value": "daohang.2023200.com",
    "context": "Former gambling API backend. DEAD as of 2026-07-03.",
    "href": "/ti/ioc/domain/daohang.2023200.com",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "ipv4",
    "value": "172.67.184.213",
    "context": "Cloudflare IP for v3.jiathis.com (Phase 3)",
    "href": "/ti/ioc/ipv4/172.67.184.213",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "ipv4",
    "value": "104.21.59.230",
    "context": "Cloudflare IP for v3.jiathis.com (Phase 3)",
    "href": "/ti/ioc/ipv4/104.21.59.230",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "ipv4",
    "value": "45.197.102.29",
    "context": "Huawei CDN IP for test.airsplu.cn gambling redirect",
    "href": "/ti/ioc/ipv4/45.197.102.29",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "ipv4",
    "value": "20.239.154.185",
    "context": "Microsoft Azure IP for s5dh.club / s5gw.mki.mom gambling portal",
    "href": "/ti/ioc/ipv4/20.239.154.185",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "ipv4",
    "value": "20.2.192.146",
    "context": "Microsoft Azure IP for s5dh.club / s5gw.mki.mom gambling portal",
    "href": "/ti/ioc/ipv4/20.2.192.146",
    "campaigns": [],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "sha256",
    "value": "e27a0e28da18a7978dd0139bccf48ec5c39454fda6384c95fc0fb004b3b502a2",
    "context": "art-template@4.13.7 npm tarball (Phase 3, published 2026-06-27 by npmpacketmaintainmember8)",
    "href": "/ti/ioc/sha256/e27a0e28da18a7978dd0139bccf48ec5c39454fda6384c95fc0fb004b3b502a2",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "sha256",
    "value": "7c59001d7bdd0dfb04b89d2de3d71b18975b20f22b2af880911413fb29cfdff0",
    "context": "v3.jiathis.com/code/jia.js gambling redirect payload (last-modified 2026-06-30). Baidu Analytics + time-gated redirect to test.airsplu.cn.",
    "href": "/ti/ioc/sha256/7c59001d7bdd0dfb04b89d2de3d71b18975b20f22b2af880911413fb29cfdff0",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "email",
    "value": "npmpacketmaintainmember8@proton.me",
    "context": "Phase 3 publisher account (npmpacketmaintainmember8). Published 4.13.7 on 2026-06-27.",
    "href": "/ti/ioc/email/npmpacketmaintainmember8@proton.me",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "url",
    "value": "https://v3.jiathis.com/code/art.js",
    "context": "Injected script URL in art-template@4.13.6 and 4.13.7 (atob decoded from aHR0cHM6Ly92My5qaWF0aGlzLmNvbS9jb2RlL2FydC5qcw==). Returns 404 as of 2026-07-03.",
    "href": "/ti/ioc/url/url-f99f960b6c04",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "url",
    "value": "https://v3.jiathis.com/code/jia.js",
    "context": "Injected script URL in art-template@4.13.5 (with ?uid=artemplate param). Also loaded by legacy JiaThis widget embeddings across thousands of Chinese websites. LIVE, serving gambling redirect payload.",
    "href": "/ti/ioc/url/url-38919f0acd5c",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-07-03"
  },
  {
    "kind": "email",
    "value": "marketfront@tutamail.com",
    "context": "npm maintainer email for the marketfront account that published the 25 Wave 4 packages. Anonymous Tutanota (tutamail.com) address. Fifth publisher identity and fourth distinct email tied to the oob-moika-tech campaign (after mr.4nd3r50n/pik-libs, nath.dr4k3@gmail.com, emcd-vue@proton.me).",
    "href": "/ti/ioc/email/marketfront@tutamail.com",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "url",
    "value": "/api/v1/events",
    "context": "Wave 4 exfiltration path. Receives a gzip-compressed HTTPS POST carrying harvested credential-file contents, gated by a custom X-Secret header. The full C2 host is RC4+XOR-concealed in the payload and was NOT statically resolved — only the path is known. Detection artifact: outbound POST to /api/v1/events with an X-Secret header and gzip body from a workstation/CI agent during npm install.",
    "href": "/ti/ioc/url/url-817b4ba86c73",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "npm.marketfront.io",
    "context": "Fabricated internal npm registry lure in the @marketfront package READMEs (registry=https://npm.marketfront.io). Scope-parameterized social-engineering artifact (npm.<scope>.io), NOT confirmed functional infrastructure. Same pattern as npm.car-loans.io / npm.cloudplatform-single-spa.io / npm.t-in-one.io in prior waves.",
    "href": "/ti/ioc/domain/npm.marketfront.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "telemetry.marketfront.io",
    "context": "Fabricated telemetry cover-story endpoint referenced in @marketfront READMEs (telemetry.<scope>.io). Social-engineering artifact to normalize expected outbound network activity at install time; NOT the actual exfil destination (which is the RC4-concealed C2 at path /api/v1/events).",
    "href": "/ti/ioc/domain/telemetry.marketfront.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "github.marketfront.io",
    "context": "Fabricated GitHub Enterprise subdomain used as the repository.url in @marketfront package metadata (git+https://github.marketfront.io/platform/<pkg>.git). Scope-parameterized social-engineering artifact (github.<scope>.io); not confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/github.marketfront.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "sha256",
    "value": "3a24e0fd22dce86e897b09cdb146514a0dcf2430a5d3f307c6b5959155c34b33",
    "context": "postinstall.js payload SHA256 in @emcd-vue/auth@7.1.0 (Wave 3 scope, republished/live as of 2026-07-02). Corroborates the same-operator link across waves.",
    "href": "/ti/ioc/sha256/3a24e0fd22dce86e897b09cdb146514a0dcf2430a5d3f307c6b5959155c34b33",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "sha256",
    "value": "78b06a93c16d990d896ed2c77f48097977ae452f009c0345b5396efdf963a97c",
    "context": "postinstall.js payload SHA256 in @emcd-vue/loans@7.2.0 (Wave 3 scope, republished/live as of 2026-07-02).",
    "href": "/ti/ioc/sha256/78b06a93c16d990d896ed2c77f48097977ae452f009c0345b5396efdf963a97c",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "sha256",
    "value": "acb6f87e440ccb5efe299313e7adb506586e31a6e7381515a9fb2057965f715e",
    "context": "postinstall.js payload SHA256 in @emcd-vue/b2b-pay-form@5.8.0 (Wave 3 scope, republished/live as of 2026-07-02).",
    "href": "/ti/ioc/sha256/acb6f87e440ccb5efe299313e7adb506586e31a6e7381515a9fb2057965f715e",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "email",
    "value": "t.tqm.mfe@proton.me",
    "context": "npm maintainer email for the t.tqm.mfe account that published @tqm-mfe/main. Anonymous Proton Mail address and a NEW actor identifier — distinct from marketfront@tutamail.com (the same-day @marketfront Wave 4 sibling). Sixth publisher identity and fifth distinct email tied to the oob-moika-tech campaign (after mr.4nd3r50n/pik-libs, nath.dr4k3@gmail.com, emcd-vue@proton.me, marketfront@tutamail.com).",
    "href": "/ti/ioc/email/t.tqm.mfe@proton.me",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "md5",
    "value": "7c1a3a2eea2fa01246179bcfcd2648b0",
    "context": "scripts/postinstall.js md5 in @tqm-mfe/main@5.4.7. ~182 KB obfuscator.io-style single-line payload, RC4/XOR-behind-base64 obfuscation class (same family as @marketfront Wave 4). Differs from the 5.5.0 postinstall.js.",
    "href": "/ti/ioc/md5/7c1a3a2eea2fa01246179bcfcd2648b0",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "md5",
    "value": "eba5d3fa62ff3bbcd9d3a75d7f884de2",
    "context": "scripts/postinstall.js md5 in @tqm-mfe/main@5.5.0 (dist-tag latest, changelog claims 'Added ARM64 support'). Differs from the 5.4.7 postinstall.js md5, indicating a re-obfuscated / updated payload between the two ~2h-apart versions.",
    "href": "/ti/ioc/md5/eba5d3fa62ff3bbcd9d3a75d7f884de2",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "md5",
    "value": "7f01e8546af142347587931cf56cc47a",
    "context": "dist/index.js md5 in @tqm-mfe/main (identical across 5.4.7 and 5.5.0). Non-functional decoy: module.exports = require('../src/index.js'), where ../src/index.js is absent from the tarball — the library cannot load, so only the postinstall hook runs. Same decoy-facade pattern as @marketfront Wave 4.",
    "href": "/ti/ioc/md5/7f01e8546af142347587931cf56cc47a",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "docs.tqm-mfe.io",
    "context": "Fabricated docs domain in @tqm-mfe/main metadata (homepage https://docs.tqm-mfe.io/platform/main). Scope-parameterized social-engineering artifact (docs.<scope>.io); NOT confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/docs.tqm-mfe.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "jira.tqm-mfe.io",
    "context": "Fabricated Jira domain in @tqm-mfe/main metadata (bugs.url https://jira.tqm-mfe.io/projects/PLATFORM). Scope-parameterized social-engineering artifact (jira.<scope>.io); NOT confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/jira.tqm-mfe.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "npm.tqm-mfe.io",
    "context": "Fabricated internal npm registry lure in the @tqm-mfe/main README (registry=https://npm.tqm-mfe.io). Scope-parameterized social-engineering artifact (npm.<scope>.io) to imply a private registry (the precondition for dependency confusion); NOT confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/npm.tqm-mfe.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "telemetry.tqm-mfe.io",
    "context": "Fabricated telemetry cover-story endpoint referenced in the @tqm-mfe/main README (telemetry.<scope>.io). Social-engineering artifact to normalize expected outbound network activity at install time; NOT the actual exfil destination (which is the RC4-concealed, unresolved C2).",
    "href": "/ti/ioc/domain/telemetry.tqm-mfe.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "domain",
    "value": "github.tqm-mfe.io",
    "context": "Fabricated GitHub host used as the repository.url in @tqm-mfe/main metadata (git+https://github.tqm-mfe.io/platform/main.git). Scope-parameterized social-engineering artifact (github.<scope>.io); NOT confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/github.tqm-mfe.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-07-01"
  },
  {
    "kind": "sha256",
    "value": "ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108",
    "context": "Decrypted Bun bootstrapper (_b blob), identical across all 20 LeoPlatform infected packages",
    "href": "/ti/ioc/sha256/ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "sha256",
    "value": "9f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015",
    "context": "Decrypted worm payload (_p blob), identical across all 20 LeoPlatform infected packages (781,580 bytes)",
    "href": "/ti/ioc/sha256/9f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "sha1",
    "value": "24a0d9e496ec07ca978fab602d5f5e0b39fa03a0",
    "context": "Infected tarball SHA1: leo-logger-1.0.8.tgz",
    "href": "/ti/ioc/sha1/24a0d9e496ec07ca978fab602d5f5e0b39fa03a0",
    "campaigns": [],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "sha1",
    "value": "5e75c14b8acd5752819ab7a10874ddd6389f5238",
    "context": "Infected tarball SHA1: serverless-convention-2.0.4.tgz",
    "href": "/ti/ioc/sha1/5e75c14b8acd5752819ab7a10874ddd6389f5238",
    "campaigns": [],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "sha1",
    "value": "e973173fb757d2dab9c6424b440dd9f7cbe4f14a",
    "context": "Infected tarball SHA1: leo-cache-1.0.2.tgz",
    "href": "/ti/ioc/sha1/e973173fb757d2dab9c6424b440dd9f7cbe4f14a",
    "campaigns": [],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "sha1",
    "value": "a8cb86b78ca56befe90dc466642cb04b98079909",
    "context": "Infected tarball SHA1: rstreams-shard-util-1.0.1.tgz",
    "href": "/ti/ioc/sha1/a8cb86b78ca56befe90dc466642cb04b98079909",
    "campaigns": [],
    "discovered_at": "2026-06-24"
  },
  {
    "kind": "domain",
    "value": "wshu.net",
    "context": "SUPPORTING signal, NOT a unique attacker indicator. wshu.net is a PUBLIC DISPOSABLE-EMAIL provider (verified on disposable-email blocklists: disposable-email-domains, fakefilter, MISP warninglists, authgear free-email list, and in unrelated apps' temp-mail signup logs), so the domain alone catches many unrelated throwaway accounts and is a noisy pivot. The campaign uses the per-scope burner pattern <scope>-<6rand>@wshu.net across all 12 scopes; treat that pattern as corroborating evidence only when combined with the durable code fingerprint (shared runPrepare/onInstall javascript-obfuscator wrapper + byte-identical/near-identical payload blobs + the 2026-06-04 publish burst), not as a standalone domain pivot. The earlier noon-contracts npm package (publisher noondeved94ed@wshu.net, 2026-05-10) shares only this disposable-email provider, not payload or code.",
    "href": "/ti/ioc/domain/wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "apexcraft-8uiljr@wshu.net",
    "context": "npm publisher email for the @apexcraft scope (root @apexcraft/nano-key).",
    "href": "/ti/ioc/email/apexcraft-8uiljr@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "bytemend-dwzfhq@wshu.net",
    "context": "npm publisher email for the @bytemend scope (@bytemend/mfebus).",
    "href": "/ti/ioc/email/bytemend-dwzfhq@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "chunklab-bpriqx@wshu.net",
    "context": "npm publisher email for the @chunklab scope (@chunklab/hexparse).",
    "href": "/ti/ioc/email/chunklab-bpriqx@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "zynkit-sk393b@wshu.net",
    "context": "npm publisher email for the @zynkit scope (@zynkit/jwtbytes and the @zynkit/probe stub).",
    "href": "/ti/ioc/email/zynkit-sk393b@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "petitcode-eq1efk@wshu.net",
    "context": "npm publisher email for the @petitcode scope (@petitcode/eb-retry).",
    "href": "/ti/ioc/email/petitcode-eq1efk@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "tinyfox-yjwiqz@wshu.net",
    "context": "npm publisher email for the @tinyfox scope (@tinyfox/shapecheck).",
    "href": "/ti/ioc/email/tinyfox-yjwiqz@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "glitchpad-revqgz@wshu.net",
    "context": "npm publisher email for the @glitchpad scope (@glitchpad/throttler).",
    "href": "/ti/ioc/email/glitchpad-revqgz@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "thymelab-v0et8w@wshu.net",
    "context": "npm publisher email for the @thymelab scope (@thymelab/logfx).",
    "href": "/ti/ioc/email/thymelab-v0et8w@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "618dfffb6829356c131fded9f4c6528b73b4f9d7ff1fc1d3b457599a12584e29",
    "context": "Obfuscated payload blob dist/cjs/seed.cjs in @apexcraft/nano-key 1.3.7 (277264 bytes).",
    "href": "/ti/ioc/sha256/618dfffb6829356c131fded9f4c6528b73b4f9d7ff1fc1d3b457599a12584e29",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "a9a28f2e9f7e0348092682940b3bf63d47a63afc18eb8bfe628e5ddab0d73b47",
    "context": "Obfuscated payload blob dist/bootstrap.js in @bytemend/mfebus 1.4.2 (277306 bytes).",
    "href": "/ti/ioc/sha256/a9a28f2e9f7e0348092682940b3bf63d47a63afc18eb8bfe628e5ddab0d73b47",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "24c8f9b8ac17c2f88cc01d44543963206472112510962b68cf5f74d598b3b065",
    "context": "Obfuscated payload blob script/prelude.cjs in @chunklab/hexparse 1.1.6 (277265 bytes).",
    "href": "/ti/ioc/sha256/24c8f9b8ac17c2f88cc01d44543963206472112510962b68cf5f74d598b3b065",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "d06ee17d30ebb333ab2e5b6e8a1324fcf95edaaae17b6793ec0f3647338efda1",
    "context": "Obfuscated payload blob dist/prelude.cjs in @zynkit/jwtbytes 0.5.3 (282050 bytes).",
    "href": "/ti/ioc/sha256/d06ee17d30ebb333ab2e5b6e8a1324fcf95edaaae17b6793ec0f3647338efda1",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "32d02f806d58a6670f7cc9b93f1d85b22e0e0f535e1f90a62d86918033896f54",
    "context": "Obfuscated payload blob lib/warmup.js in @petitcode/eb-retry 1.3.5 (282294 bytes).",
    "href": "/ti/ioc/sha256/32d02f806d58a6670f7cc9b93f1d85b22e0e0f535e1f90a62d86918033896f54",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "0d27ca72b6f02faf4db95effb18347a7e2fa2def2034707bf9e56fa217879a3b",
    "context": "Obfuscated payload blob dist/bootstrap.cjs in @tinyfox/shapecheck 0.8.7 (282051 bytes).",
    "href": "/ti/ioc/sha256/0d27ca72b6f02faf4db95effb18347a7e2fa2def2034707bf9e56fa217879a3b",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "68b4fe54a4c05cd0115535ebd4aa8d3cccb03ea5a685f440314814ba1b89e875",
    "context": "Obfuscated payload blob (262934 bytes) shipped BYTE-IDENTICAL in TWO campaign packages: @glitchpad/throttler 2.2.3 (primer.cjs) and @lazyutil/dater 0.9.4 (dist/lib/tzinit.cjs). Confirmed via cmp/sha256 on extracted tarballs. Evidence that the actor reuses identical compiled blobs in at least one case rather than always re-seeding polymorphic per-string-RC4 builds.",
    "href": "/ti/ioc/sha256/68b4fe54a4c05cd0115535ebd4aa8d3cccb03ea5a685f440314814ba1b89e875",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "4e927f22ad04f4ac9b487ae11412fc2a55210188789ac29f3a47ad77931907a5",
    "context": "Obfuscated payload blob dist/bootstrap.js in @thymelab/logfx 2.15.5 (282151 bytes).",
    "href": "/ti/ioc/sha256/4e927f22ad04f4ac9b487ae11412fc2a55210188789ac29f3a47ad77931907a5",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "require(_0x45af03['GyrZN'])",
    "context": "Dynamically-obscured require with an identical variable name (_0x45af03) and proxy key (GyrZN) across most campaign payload blobs. Resolves a Node built-in module name from a decrypted RC4 string at runtime to keep it out of the static module graph. Cross-package code fingerprint.",
    "href": "/ti/ioc/file_path/file_path-abc1dfe8aa1c",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "briskforge-5psyxc@wshu.net",
    "context": "npm publisher email for the @briskforge scope (@briskforge/envcheck).",
    "href": "/ti/ioc/email/briskforge-5psyxc@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "lazyutil-78muyg@wshu.net",
    "context": "npm publisher email for the @lazyutil scope (@lazyutil/dater).",
    "href": "/ti/ioc/email/lazyutil-78muyg@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "frostnode-gk8pbf@wshu.net",
    "context": "npm publisher email for the @frostnode scope (@frostnode/waitfor).",
    "href": "/ti/ioc/email/frostnode-gk8pbf@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "nullzero-rlnozk@wshu.net",
    "context": "npm publisher email for the @nullzero scope (@nullzero/urlcat, flagged version unpublished before inspection).",
    "href": "/ti/ioc/email/nullzero-rlnozk@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "26ddfae644673e0ad65b63caaaf67c0f7dc6c2b2b4127bb5271f8d03fb62091a",
    "context": "Obfuscated payload blob lib/preflight.js in @briskforge/envcheck 0.5.4 (277356 bytes).",
    "href": "/ti/ioc/sha256/26ddfae644673e0ad65b63caaaf67c0f7dc6c2b2b4127bb5271f8d03fb62091a",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "2de602e6422a991346aaf0b74ed6bd525215f5177b9f7f267ccb4d82e919273d",
    "context": "Obfuscated payload blob dist/cjs/tickinit.cjs in @frostnode/waitfor 0.10.5 (259358 bytes).",
    "href": "/ti/ioc/sha256/2de602e6422a991346aaf0b74ed6bd525215f5177b9f7f267ccb4d82e919273d",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "require(_0x2cb1b0['UGeLH'])",
    "context": "Variant of the campaign's dynamically-obscured require fingerprint, found in @frostnode/waitfor dist/cjs/tickinit.cjs. Same technique as the canonical require(_0x45af03['GyrZN']) with a different variable name and proxy key — confirms shared obfuscation template across re-seeded builds.",
    "href": "/ti/ioc/file_path/file_path-0b2b81867f4f",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "email",
    "value": "gleamkit-23vnic@wshu.net",
    "context": "npm publisher email for the @gleamkit scope (@gleamkit/probe scope-reservation stub). Same <scope>-<6char>@wshu.net burner pattern; wshu.net is a public disposable-email provider (supporting signal only).",
    "href": "/ti/ioc/email/gleamkit-23vnic@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "github_repo",
    "value": "angelmaybeth21-oss/test",
    "context": "Second-stage delivery (Amazon Inspector / Operation Friday Harvest). The obfuscated first-stage downloader pulls a ~10.6MB Rust infostealer from this account's GitHub Releases. STRONGER pivot than the shared disposable wshu.net email. Account angelmaybeth21-oss created 2026-06-03; repo 'test' now removed but the account is still live. Dropper URL pattern: github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/{linux,mac,win.js}. SafeDep independently verified the account exists via the GitHub API this session.",
    "href": "/ti/ioc/github_repo/github_repo-775c00203526",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "github_repo",
    "value": "smilingdusty233",
    "context": "Secondary GitHub delivery/staging account associated with the campaign (Amazon Inspector). Created 2026-05-31. SafeDep independently verified the account exists via the GitHub API this session.",
    "href": "/ti/ioc/github_repo/github_repo-abe30b873eb2",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "url",
    "value": "https://github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/linux",
    "context": "GitHub Releases dropper URL for the Linux Rust infostealer ELF second stage (Amazon Inspector). Pattern: .../v1.0.0/{linux,mac,win.js}.",
    "href": "/ti/ioc/url/url-b570e94c0373",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "url",
    "value": "https://github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/mac",
    "context": "GitHub Releases dropper URL for the macOS Rust infostealer Mach-O second stage (Amazon Inspector).",
    "href": "/ti/ioc/url/url-3c45d689277a",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "url",
    "value": "https://github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/win.js",
    "context": "GitHub Releases dropper URL for the Windows Rust infostealer second stage (Amazon Inspector). The win.js name is a masquerade; the artifact is the Windows binary.",
    "href": "/ti/ioc/url/url-cb8182ed6fb1",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "domain",
    "value": "api.telegram.org",
    "context": "Telegram Bot API used as exfil C2 by the Windows variant of the Rust infostealer second stage (Amazon Inspector). Resolves to 149.154.166.110. Linux/macOS variants exfil over HTTP multipart/form-data instead.",
    "href": "/ti/ioc/domain/api.telegram.org",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "ipv4",
    "value": "149.154.166.110",
    "context": "Telegram infrastructure IP for api.telegram.org, the Windows-variant exfil C2 of the Rust infostealer second stage (Amazon Inspector).",
    "href": "/ti/ioc/ipv4/149.154.166.110",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "2457b2e775a5fe7a9e022ba77074a1b9aacb41b4fc0cc1d8a3dc66546599c5de",
    "context": "Second-stage Rust infostealer Linux ELF (~10.6MB) downloaded from github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/linux. Attributed to Amazon Inspector dynamic analysis (VirusTotal/CAPE).",
    "href": "/ti/ioc/sha256/2457b2e775a5fe7a9e022ba77074a1b9aacb41b4fc0cc1d8a3dc66546599c5de",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "b1c7b17f31a84e2596250121c3610ae5e0d592651940dd6c0dd74506f0f38313",
    "context": "Second-stage Rust infostealer macOS Mach-O downloaded from github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/mac. Attributed to Amazon Inspector dynamic analysis.",
    "href": "/ti/ioc/sha256/b1c7b17f31a84e2596250121c3610ae5e0d592651940dd6c0dd74506f0f38313",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "sha256",
    "value": "11fe3a47333f63fd0e0a32ea16351eb302659aba983c07e4ea3dc9b09b618509",
    "context": "Second-stage Rust infostealer Windows binary (win.js) downloaded from github.com/angelmaybeth21-oss/test/releases/download/v1.0.0/win.js. Windows variant exfils via Telegram Bot API and is NOT anti-VM gated. Attributed to Amazon Inspector dynamic analysis.",
    "href": "/ti/ioc/sha256/11fe3a47333f63fd0e0a32ea16351eb302659aba983c07e4ea3dc9b09b618509",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "/tmp/_installer-0/",
    "context": "Host staging directory created by the downloader/second stage (Amazon Inspector).",
    "href": "/ti/ioc/file_path/file_path-bd870497e0ed",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "~/.local/bin/<daemon>",
    "context": "Persistence binary path for the Rust infostealer, masquerading as a benign daemon (observed names: colord, haveged). Paired with the systemd user unit at ~/.config/systemd/user/<daemon>.service (Amazon Inspector).",
    "href": "/ti/ioc/file_path/file_path-c6d1a66f7f4e",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "~/.config/systemd/user/<daemon>.service",
    "context": "systemd USER service unit installed for persistence, masquerading as a benign daemon (colord, haveged). Loads ~/.local/bin/<daemon> (Amazon Inspector).",
    "href": "/ti/ioc/file_path/file_path-f99665105320",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "~/.local/state/<daemon>/{install.nonce,machine.id}",
    "context": "Host state artifacts (install nonce + machine id) written by the Rust infostealer second stage (Amazon Inspector).",
    "href": "/ti/ioc/file_path/file_path-5c4a3842570c",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "file_path",
    "value": "__[0-9A-F]{10}_TAG",
    "context": "Re-entrancy guard variable-name pattern in the obfuscator.io first-stage blobs (e.g. __EE9863E13F_TAG). Together with the string-array function name it defines the 5 build clusters (A=__EE9863E13F_TAG, B=__7D0A53D40B_TAG, C=__38CC632841_TAG, D=__70FE9F7AB6_TAG, E=__4C6BA78C7C_TAG). Members in the same cluster share an obfuscator seed, explaining the byte-identical blob reuse (Amazon Inspector + SafeDep). Hunt as a code/regex fingerprint.",
    "href": "/ti/ioc/file_path/file_path-27588d08861d",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign"
    ],
    "discovered_at": "2026-06-23"
  },
  {
    "kind": "ipv4",
    "value": "192.168.54.1",
    "context": "C2 host for MYRA RAT. RFC 1918 private address, unusual for public npm malware. Port 4444 (C2), port 5555 (screen viewer). Suggests lab/testing environment or internal network targeting.",
    "href": "/ti/ioc/ipv4/192.168.54.1",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "email",
    "value": "kimnbv@proton.me",
    "context": "npm publisher email for account kimijohn01, used to publish all 6 versions of apintergrationpost. Throwaway Proton Mail account.",
    "href": "/ti/ioc/email/kimnbv@proton.me",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "6f4da8919cef1623f7a6a08cb66fc1b3d7f3e5d13f4f3b03c378c0f4a797f52f",
    "context": "apintergrationpost v4.0.1 tarball hash",
    "href": "/ti/ioc/sha256/6f4da8919cef1623f7a6a08cb66fc1b3d7f3e5d13f4f3b03c378c0f4a797f52f",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "bff1cee1548dfc29da7618e11fcc2569ac849f9544056b89cbaa66d0874c1788",
    "context": "apintergrationpost v4.0.2 tarball hash",
    "href": "/ti/ioc/sha256/bff1cee1548dfc29da7618e11fcc2569ac849f9544056b89cbaa66d0874c1788",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "ba8e9452c53f5b66e47cc55e4e3531c1c59113950e49cf4eb5f14df1066f6390",
    "context": "apintergrationpost v4.0.3 tarball hash",
    "href": "/ti/ioc/sha256/ba8e9452c53f5b66e47cc55e4e3531c1c59113950e49cf4eb5f14df1066f6390",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "cc1287f3eb21f176e6337db4739975c457578f4b3f54fd58c899b711f4cbc58f",
    "context": "apintergrationpost v4.0.4 tarball hash",
    "href": "/ti/ioc/sha256/cc1287f3eb21f176e6337db4739975c457578f4b3f54fd58c899b711f4cbc58f",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "2253a51ce77c72ca1cad59fac8827a82d835bb64738cec42a2fa0d77bfac8b7e",
    "context": "apintergrationpost v4.0.5 tarball hash",
    "href": "/ti/ioc/sha256/2253a51ce77c72ca1cad59fac8827a82d835bb64738cec42a2fa0d77bfac8b7e",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "sha256",
    "value": "a6c687f276034f5bcf8070b750060c840a80a97e350592a015ed6e0974be87c4",
    "context": "apintergrationpost v4.0.6 tarball hash",
    "href": "/ti/ioc/sha256/a6c687f276034f5bcf8070b750060c840a80a97e350592a015ed6e0974be87c4",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "file_path",
    "value": "/usr/local/lib/.libcache.so",
    "context": "LD_PRELOAD rootkit shared object. Hooks readdir/stat to hide MYRA files and processes. Compiled from C source during npm postinstall.",
    "href": "/ti/ioc/file_path/file_path-33eaf245d593",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "file_path",
    "value": "/usr/local/lib/.cache-update.sh",
    "context": "MYRA RAT wrapper/launcher script. Invoked by cron (*/13 * * * *) and profile.d. Sets LD_PRELOAD and launches the Node.js RAT agent.",
    "href": "/ti/ioc/file_path/file_path-58770edd0b59",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "file_path",
    "value": "/etc/profile.d/.sh.local",
    "context": "Login persistence. Sourced on every shell login to relaunch MYRA RAT via .cache-update.sh.",
    "href": "/ti/ioc/file_path/file_path-73e497c08d7f",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "file_path",
    "value": "/usr/lib/systemd/systemd-userdbd",
    "context": "Overwritten with Node.js binary. MYRA RAT masquerades as systemd-userdbd service for process blending.",
    "href": "/ti/ioc/file_path/file_path-9bd1525fa91b",
    "campaigns": [],
    "discovered_at": "2026-06-21"
  },
  {
    "kind": "domain",
    "value": "stitch-production.org",
    "context": "C2 domain for credential exfiltration. Registered via GoDaddy on 2026-06-19T11:07:09Z, 75 minutes before first package publish. Cloudflare-fronted. Backend nginx/1.18.0 (Ubuntu). Mimics stitch.withgoogle.com production API.",
    "href": "/ti/ioc/domain/stitch-production.org",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "ipv4",
    "value": "172.67.189.185",
    "context": "Cloudflare IP for stitch-production.org C2 domain",
    "href": "/ti/ioc/ipv4/172.67.189.185",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "ipv4",
    "value": "104.21.65.94",
    "context": "Cloudflare IP for stitch-production.org C2 domain",
    "href": "/ti/ioc/ipv4/104.21.65.94",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "url",
    "value": "https://stitch-production.org/api/v1",
    "context": "C2 endpoint. Credential exfiltration via GET query parameters: ?src=<source>&user=<email>. Fallback beacon: ?email-not-found=true",
    "href": "/ti/ioc/url/url-c5a2ef50f831",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "email",
    "value": "maximus-mcmillan@outlook.com",
    "context": "npm publisher email for @withgoogle/stitch-sdk. Throwaway account.",
    "href": "/ti/ioc/email/maximus-mcmillan@outlook.com",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "sha256",
    "value": "ba5b2a9a7fe596734fb69bdf1a35071d1a2f435a36e8c870bd4390c562d9f614",
    "context": "@withgoogle/stitch-sdk v0.1.1 tarball hash",
    "href": "/ti/ioc/sha256/ba5b2a9a7fe596734fb69bdf1a35071d1a2f435a36e8c870bd4390c562d9f614",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "sha256",
    "value": "638b523ddd3382b622c412e37f274db1a9a6505893fa7236183f0b67a5355e94",
    "context": "@withgoogle/stitch-sdk v0.1.2 tarball hash",
    "href": "/ti/ioc/sha256/638b523ddd3382b622c412e37f274db1a9a6505893fa7236183f0b67a5355e94",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "github_repo",
    "value": "maximus-mcmillan/stitch-sdk",
    "context": "Fabricated repository URL in package.json. GitHub user and repo do not exist (404 / deleted).",
    "href": "/ti/ioc/github_repo/github_repo-7c2d4bdb1b71",
    "campaigns": [],
    "discovered_at": "2026-06-19"
  },
  {
    "kind": "email",
    "value": "ehindero2016@tutamail.com",
    "context": "Operator email on the compromised `ehindero` npm account at time of the malicious @mastra republish.",
    "href": "/ti/ioc/email/ehindero2016@tutamail.com",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "ehindero2016@gmail.com",
    "context": "Original email on the `ehindero` npm account during its clean @mastra/core alpha publishes (2024-11 to 2025-02); same account, later changed to tutamail. Account-takeover indicator.",
    "href": "/ti/ioc/email/ehindero2016@gmail.com",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "sergey2016@tutamail.com",
    "context": "Email of the `sergey2016` npm account that published the easy-day-js dropper. Sibling <name>2016@tutamail.com pattern shared with the operator.",
    "href": "/ti/ioc/email/sergey2016@tutamail.com",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "ipv4",
    "value": "23.254.164.92",
    "context": "Stage-2 download host (dropper). HTTPS GET to https://23.254.164.92:8000/update/49890878. Hostwinds, PTR hwsrv-1327786.hostwindsdns.com. User-Agent gated: serves payload only to Node default UA.",
    "href": "/ti/ioc/ipv4/23.254.164.92",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "ipv4",
    "value": "23.254.164.123",
    "context": "RAT stage-2 C2 (still live at analysis time). HTTPS POST to https://23.254.164.123/49890878. Hostwinds, PTR hwsrv-1327785.hostwindsdns.com. Fronts an expired wolfSSL test cert CN=www.wolfssl.com.",
    "href": "/ti/ioc/ipv4/23.254.164.123",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "url",
    "value": "https://23.254.164.92:8000/update/49890878",
    "context": "Dropper stage-2 retrieval URL; returns the 12-byte-hex-named JS RAT loader only to Node default User-Agent.",
    "href": "/ti/ioc/url/url-76412fcc7af0",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "url",
    "value": "https://23.254.164.123/49890878",
    "context": "RAT stage-2 C2 endpoint; base64-encoded JSON beacon/command protocol (type:prepare/tpcsr/r0), default 10-minute cycle. Campaign path /49890878 shared with the dropper.",
    "href": "/ti/ioc/url/url-f88b7373e400",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "sha256",
    "value": "221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf",
    "context": "Stage-2 payload: 41 KB obfuscated multi-platform cryptocurrency-stealer RAT.",
    "href": "/ti/ioc/sha256/221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "sha256",
    "value": "4a8860240e4231c3a74c81949be655a28e096a7d72f38fbe84e5b37636b98417",
    "context": "easy-day-js@1.11.21 npm tarball (clean precursor, no install hook).",
    "href": "/ti/ioc/sha256/4a8860240e4231c3a74c81949be655a28e096a7d72f38fbe84e5b37636b98417",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "sha256",
    "value": "ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185",
    "context": "easy-day-js@1.11.22 npm tarball (armed: postinstall RAT dropper setup.cjs).",
    "href": "/ti/ioc/sha256/ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "sha256",
    "value": "2e2340f2ab71f321d3ef6fb9a7542fb9f30f3c65ba7ef924fcd8acc63829b5bf",
    "context": "@mastra/core@1.42.1 npm tarball (republished by ehindero, dist.attestations=null, easy-day-js dependency injected).",
    "href": "/ti/ioc/sha256/2e2340f2ab71f321d3ef6fb9a7542fb9f30f3c65ba7ef924fcd8acc63829b5bf",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "setup.cjs",
    "context": "easy-day-js@1.11.22 postinstall dropper (obfuscator.io custom-base64 string-array). Sets NODE_TLS_REJECT_UNAUTHORIZED=0, fetches stage 2, spawns detached node child, then self-deletes (fs.rmSync(__filename)).",
    "href": "/ti/ioc/file_path/file_path-fcac09d05920",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": ".pkg_history",
    "context": "Marker file written to os.tmpdir() by setup.cjs (contains __dirname).",
    "href": "/ti/ioc/file_path/file_path-34b4c3ce284f",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": ".pkg_logs",
    "context": "Marker file written to os.tmpdir() by setup.cjs (bytes of \"easy-day-js\" XOR 0x80).",
    "href": "/ti/ioc/file_path/file_path-a970d908e8cf",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "~/Library/LaunchAgents/com.nvm.protocal.plist",
    "context": "macOS RAT persistence LaunchAgent (typosquats nvm tooling).",
    "href": "/ti/ioc/file_path/file_path-2f1792f4b790",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "~/Library/NodePackages/protocal.cjs",
    "context": "macOS RAT payload body disguised as Node tooling.",
    "href": "/ti/ioc/file_path/file_path-06ac923384c2",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "~/.config/systemd/user/nvmconf.service",
    "context": "Linux RAT persistence systemd user unit (typosquats nvm tooling).",
    "href": "/ti/ioc/file_path/file_path-adfb9d756710",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "~/.config/NodePackages/config.json",
    "context": "Linux RAT config persistence (UID/PrimaryUrl/Cycle).",
    "href": "/ti/ioc/file_path/file_path-991ec52d7441",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "C:\\ProgramData\\NodePackages",
    "context": "Windows RAT persistence/config directory.",
    "href": "/ti/ioc/file_path/file_path-d4d357fe8699",
    "campaigns": [
      "@mastra npm Scope Takeover"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "url",
    "value": "https://files.catbox.moe/j4loim.chk",
    "context": "Decoded C2 / payload URL, reconstructed from endpointmap's _ep+_p byte arrays XOR-decoded with the name-derived key 'endpoint'. catbox.moe is a public anonymous file host abused for inbound payload staging.",
    "href": "/ti/ioc/url/url-5c84395b1a04",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "domain",
    "value": "files.catbox.moe",
    "context": "Payload staging host. catbox.moe flagged by 6/92 VirusTotal vendors at analysis time. Shared atom with LofyGang (lofygang-undicy-http) but used here for INBOUND payload staging vs LofyGang's OUTBOUND exfil — coincidental shared infra, NOT attribution.",
    "href": "/ti/ioc/domain/files.catbox.moe",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "domain",
    "value": "deltajohnsons.com",
    "context": "Custom throwaway email domain shared across all five npm maintainer accounts (one unique random local-part per package). Strongest cluster fingerprint for this operator.",
    "href": "/ti/ioc/domain/deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "avu2mglrijzlnu4ujkca@deltajohnsons.com",
    "context": "procwire maintainer email.",
    "href": "/ti/ioc/email/avu2mglrijzlnu4ujkca@deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "sg5kcaiezwyf9umsphqc@deltajohnsons.com",
    "context": "routecraft maintainer email.",
    "href": "/ti/ioc/email/sg5kcaiezwyf9umsphqc@deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "hmlfyhj29biz62gkvxbh@deltajohnsons.com",
    "context": "endpointmap maintainer email.",
    "href": "/ti/ioc/email/hmlfyhj29biz62gkvxbh@deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "dstc2xvtq7fszbvmbvic@deltajohnsons.com",
    "context": "bytecraft maintainer email.",
    "href": "/ti/ioc/email/dstc2xvtq7fszbvmbvic@deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "ynn47wq89mvauxti9zgf@deltajohnsons.com",
    "context": "staticlayer maintainer email.",
    "href": "/ti/ioc/email/ynn47wq89mvauxti9zgf@deltajohnsons.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "akuznetsov-dev@protonmail.com",
    "context": "Invented author persona 'Anton Kuznetsov' (akuznetsov-oss org packages: procwire, routecraft).",
    "href": "/ti/ioc/email/akuznetsov-dev@protonmail.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "email",
    "value": "vpetrov-node@protonmail.com",
    "context": "Invented author persona 'Viktor Petrov' (vpetrov-oss org packages: bytecraft, endpointmap, staticlayer).",
    "href": "/ti/ioc/email/vpetrov-node@protonmail.com",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "github_repo",
    "value": "akuznetsov-oss",
    "context": "Fabricated GitHub organization (now 404) for procwire and routecraft.",
    "href": "/ti/ioc/github_repo/github_repo-c2638f053756",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "github_repo",
    "value": "vpetrov-oss",
    "context": "Fabricated GitHub organization (now 404) for bytecraft, endpointmap, staticlayer.",
    "href": "/ti/ioc/github_repo/github_repo-f219a1772e7c",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "lib/setup.js",
    "context": "procwire preinstall entrypoint: win32 guard, name-derived XOR key, C2 decode, worker.init().",
    "href": "/ti/ioc/file_path/file_path-eebe441416ca",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "file_path",
    "value": "lib/registry.js",
    "context": "endpointmap metadata-only C2 store: XOR-encoded _ep and _p byte arrays disguised as endpoint constants.",
    "href": "/ti/ioc/file_path/file_path-c76cf141522a",
    "campaigns": [
      "procwire / deltajohnsons Windows Dropper"
    ],
    "discovered_at": "2026-06-17"
  },
  {
    "kind": "domain",
    "value": "olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion",
    "context": "Tor hidden-service C2 for the Atomic Arch implant. Beacon POST /api/agent HTTP/1.0; secondary-payload staging at /bin/linux with hash verification at /bin/sha256/linux. Onion host is XOR-obfuscated in the binary (32-byte repeating key at offset 0x1AA60, 62-byte ciphertext at 0x2DA96). Same /api/agent beacon path as IronWorm.",
    "href": "/ti/ioc/domain/olrh4mibs62l6kkuvvjyc5lrercqg5tz543r4lsw3o6mh5qb7g7sneid.onion",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "sha256",
    "value": "6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b",
    "context": "Dropper ELF inside atomic-lockfile@1.4.2 (./src/hooks/deps). Stripped Rust-async Linux ELF64 PIE, entry 0xeae00, 3,040,376 bytes. MD5 42b59fdbe1b72895b2951412222ebf40.",
    "href": "/ti/ioc/sha256/6144d433f8a0316869877b5f834c801251bbb936e5f1577c5680878c7443c98b",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "md5",
    "value": "42b59fdbe1b72895b2951412222ebf40",
    "context": "MD5 of the atomic-lockfile dropper ELF (./src/hooks/deps).",
    "href": "/ti/ioc/md5/42b59fdbe1b72895b2951412222ebf40",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "sha256",
    "value": "7883bda1ff15425f2dbe622c45a3ae105ddfa6175009bbf0b0cad9bf5c79b316",
    "context": "Linux ELF payload embedded in the js-digest npm package (Atomic Arch wave-2 / bun-delivered variant).",
    "href": "/ti/ioc/sha256/7883bda1ff15425f2dbe622c45a3ae105ddfa6175009bbf0b0cad9bf5c79b316",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "sha256",
    "value": "47893d9badc38c54b71321263ce8178c1abb10396e0aadf9793e61ec8829e204",
    "context": "Secondary payload fetched from the Tor C2 at /bin/linux (verified against /bin/sha256/linux). Suspected cryptominer; detection hint is modification of /usr/bin/monero-wallet-gui.",
    "href": "/ti/ioc/sha256/47893d9badc38c54b71321263ce8178c1abb10396e0aadf9793e61ec8829e204",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "file_path",
    "value": "src/hooks/deps",
    "context": "Path of the Rust-async ELF infostealer dropper inside the atomic-lockfile npm tarball; invoked by the package.json preinstall hook (preinstall: ./src/hooks/deps).",
    "href": "/ti/ioc/file_path/file_path-88f984d402a7",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "file_path",
    "value": "scales.bpf.c",
    "context": "eBPF rootkit component source filename. Hooks getdents64() to hide PIDs from /proc, filenames from directory listings, and socket inodes from /proc/net/tcp + netlink (NETLINK_SOCK_DIAG). Pinned BPF maps /sys/fs/bpf/hidden_pids, /sys/fs/bpf/hidden_names, /sys/fs/bpf/hidden_inodes. Kills ptrace (PTRACE_ATTACH/PTRACE_SEIZE). IronWorm equivalent was q2.bpf.c.",
    "href": "/ti/ioc/file_path/file_path-777c40b68e33",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "github_repo",
    "value": "fardewoak/nodejs-argo",
    "context": "GitHub repo hosting a container image (ghcr.io herbsobering430) tied to the npm publisher herbsobering; appears to be reverse-shell / proxy tooling associated with the Atomic Arch operator.",
    "href": "/ti/ioc/github_repo/github_repo-8b70ca5c56ec",
    "campaigns": [
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-11"
  },
  {
    "kind": "url",
    "value": "https://o4511539639222272.ingest.de.sentry.io/api/4511539669368912/envelope/",
    "context": "Sentry ingest (envelope) endpoint abused as the C2/exfiltration drop. build.rs POSTs stolen git metadata and source diffs here via curl. Sentry org ID o4511539639222272, project ID 4511539669368912, region host ingest.de.sentry.io.",
    "href": "/ti/ioc/url/url-0e9db416e643",
    "campaigns": [],
    "discovered_at": "2026-06-10"
  },
  {
    "kind": "domain",
    "value": "o4511539639222272.ingest.de.sentry.io",
    "context": "Region-pinned Sentry ingest host (org subdomain o4511539639222272, EU/de region) used for exfiltration.",
    "href": "/ti/ioc/domain/o4511539639222272.ingest.de.sentry.io",
    "campaigns": [],
    "discovered_at": "2026-06-10"
  },
  {
    "kind": "file_path",
    "value": "build.rs",
    "context": "Cargo build script added to the crate; executes at compile time on the consumer machine and performs the data collection and exfiltration.",
    "href": "/ti/ioc/file_path/file_path-d0d989980925",
    "campaigns": [],
    "discovered_at": "2026-06-10"
  },
  {
    "kind": "url",
    "value": "https://8197ee42c4f59c83f4cc6d48f5bae821@o4511539639222272.ingest.de.sentry.io/4511539669368912",
    "context": "Full Sentry DSN embedded in the envelope 'dsn' field. The public key 8197ee42c4f59c83f4cc6d48f5bae821 is the most specific attributable indicator in the payload (distinct from the bare ingest URL). DSN form: https://<public_key>@o<org>.ingest.<region>.sentry.io/<project_id>. Hunt for the literal key 8197ee42c4f59c83f4cc6d48f5bae821 in package sources and outbound traffic.",
    "href": "/ti/ioc/url/url-22995333e34a",
    "campaigns": [],
    "discovered_at": "2026-06-10"
  },
  {
    "kind": "file_path",
    "value": "Cargo.toml",
    "context": "Dependency-level indicator: the malicious commit adds a build-dependency 'uuid = { version = \"1.23\", default-features = false, features = [\"v4\"] }' to Cargo.toml, used for Uuid::new_v4().as_simple() to generate the Sentry event_id. An otherwise-unexpected 'uuid' build-dep appearing alongside a new build.rs is a strong combined signal.",
    "href": "/ti/ioc/file_path/file_path-2e9d962a0832",
    "campaigns": [],
    "discovered_at": "2026-06-10"
  },
  {
    "kind": "sha256",
    "value": "51b4dd39a15af1e28e97adc375849d688423ec3d88e8010644395fcdea52a3cc",
    "context": "core/telemetry/_hooks.py — Python stager injected into gpt-pilot; derived from edxeth/Shai-Hulud-Open-Source PYTHON_LOADER.py",
    "href": "/ti/ioc/sha256/51b4dd39a15af1e28e97adc375849d688423ec3d88e8010644395fcdea52a3cc",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "sha256",
    "value": "c96f37e1b9cdc9683a300909492ed9f770b620d0037e5b80e23753cba7ca4077",
    "context": "core/telemetry/_runtime.bin — 758 KB Bun JS payload with // @bun @bun-cjs header, MxGPr9 string-array rotation obfuscation, fromCodePoint decoder",
    "href": "/ti/ioc/sha256/c96f37e1b9cdc9683a300909492ed9f770b620d0037e5b80e23753cba7ca4077",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "file_path",
    "value": "core/telemetry/_hooks.py",
    "context": "Python stager file path in compromised gpt-pilot repository",
    "href": "/ti/ioc/file_path/file_path-c202cdb8f68f",
    "campaigns": [],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "file_path",
    "value": "core/telemetry/_runtime.bin",
    "context": "Bun JS payload file path; .bin extension used to blend with compiled asset naming conventions",
    "href": "/ti/ioc/file_path/file_path-b39532b51e5d",
    "campaigns": [],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "file_path",
    "value": "core/telemetry/.loader.lock",
    "context": "Run-once lock file; presence indicates prior stager execution on the host",
    "href": "/ti/ioc/file_path/file_path-01372a18cbf5",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "github_repo",
    "value": "edxeth/Shai-Hulud-Open-Source",
    "context": "Attacker toolkit repository (created 2026-05-13); contains src/assets/PYTHON_LOADER.py — the template for the gpt-pilot stager",
    "href": "/ti/ioc/github_repo/github_repo-6686c727cc01",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "github_repo",
    "value": "deadbeef3137/Shai-Hulud-Open-Source",
    "context": "Fork of attacker toolkit edxeth/Shai-Hulud-Open-Source",
    "href": "/ti/ioc/github_repo/github_repo-707bc529039b",
    "campaigns": [],
    "discovered_at": "2026-06-08"
  },
  {
    "kind": "file_path",
    "value": "tools/setup",
    "context": "~976 KB UPX-packed Rust ELF infostealer binary dropped inside the malicious npm tarball; invoked by the package.json preinstall hook (preinstall: ./tools/setup).",
    "href": "/ti/ioc/file_path/file_path-a3dec2550575",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "file_path",
    "value": ".github/scripts/precheck",
    "context": "Alternate in-repo path for the IronWorm Rust binary dropper, committed under the spoofed claude author identity.",
    "href": "/ti/ioc/file_path/file_path-5a0085c54ae6",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "file_path",
    "value": "q2.bpf.c",
    "context": "eBPF rootkit component source filename recovered from .BTF.ext debug metadata left in the embedded ELF object (214 verbatim source lines). Provides process hiding (/proc rewriting), TCP socket hiding (netlink filtering), and anti-debugging (ptrace interception, SIGKILL).",
    "href": "/ti/ioc/file_path/file_path-79ddd9e3946a",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "url",
    "value": "http://127.0.0.1:8738",
    "context": "Local loopback HTTP listener used to capture wallet credential POSTs (Exodus desktop wallet password + BIP-39 seed mnemonic injected from the browser/app).",
    "href": "/ti/ioc/url/url-826c7261870d",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "url",
    "value": "https://temp.sh",
    "context": "Fallback exfiltration host (public file-sharing service), reached over Tor via POST /upload when the primary Tor hidden-service C2 is unavailable. Same fallback as IronWorm.",
    "href": "/ti/ioc/url/url-0c6e64b7ce44",
    "campaigns": [
      "IronWorm",
      "Atomic Arch"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "url",
    "value": "tor://api/agent",
    "context": "Primary C2 beacon path /api/agent served over a Tor hidden service (.onion address not published by the researcher). Provides remote shell plus file download/execute. Tor reached via custom torrc + downloaded Tor expert bundle.",
    "href": "/ti/ioc/url/url-22fc577bf3e0",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "url",
    "value": "https://registry.npmjs.org/-/npm/v1/oidc/token/exchange/package",
    "context": "npm OIDC Trusted Publishing token-exchange endpoint abused for self-replication: mints a package-scoped automation token without stored credentials, then republishes trojanized versions.",
    "href": "/ti/ioc/url/url-9e57ef0cdfb1",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "wallet",
    "value": "0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6",
    "context": "Operator's own Ethereum wallet, derived from a hardcoded BIP-39 recovery phrase ('bench crane defense corn wheel trial news abuse finish better paddle slush') left inside the binary and present in the malware's wallet skip-list. Near-empty test wallet; an OPSEC failure that aids attribution.",
    "href": "/ti/ioc/wallet/0x7e28D9889f414B06c19a22A9Bd316f0AC279a4d6",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "github_repo",
    "value": "asteroid-dao/eternal-storage",
    "context": "Victim GitHub repo poisoned by IronWorm. Malicious commit SHA a8f0c75a77698759413dbadcb99b62709816ed42 (backdated, spoofed claude author).",
    "href": "/ti/ioc/github_repo/github_repo-8791fd799b8f",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "github_repo",
    "value": "asteroid-dao/asteroid-protocol",
    "context": "Victim GitHub repo poisoned by IronWorm. Malicious commit SHA 5d7c93caf50a447a8d48cafe2e5cff6b47618b13.",
    "href": "/ti/ioc/github_repo/github_repo-da1dce5360f1",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "github_repo",
    "value": "alisista/aht-testnet",
    "context": "Victim GitHub repo poisoned by IronWorm. Malicious commit SHA 10c619e75181d07ddcccb5c1f62766c85fef08df.",
    "href": "/ti/ioc/github_repo/github_repo-cf1ffc3c8ced",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "github_repo",
    "value": "ocrybit/mweb3waves",
    "context": "Victim GitHub repo (compromised account ocrybit) poisoned by IronWorm. Malicious commit SHA 0fe6a098fe698e586188e0f2e851ef43f1a35958.",
    "href": "/ti/ioc/github_repo/github_repo-e989fd3a0454",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "github_repo",
    "value": "ocrybit/by-coffeescript",
    "context": "Victim GitHub repo (compromised account ocrybit) poisoned by IronWorm. Malicious commit SHA fd64413119575fa119eaa9f94d32208c7d916796.",
    "href": "/ti/ioc/github_repo/github_repo-f8dec39ca7bc",
    "campaigns": [
      "IronWorm"
    ],
    "discovered_at": "2026-06-03"
  },
  {
    "kind": "email",
    "value": "epsteinfuckniggerss911@proton.me",
    "context": "npm maintainer email for account speedsteraxios (faster-axios publisher). Offensive/racist throwaway. Weak actor selector.",
    "href": "/ti/ioc/email/epsteinfuckniggerss911@proton.me",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "f89694ba247a7a67e582572094c9f19d2e09882eff8917f78125d54b733bd24e",
    "context": "faster-axios@1.17.3 npm tarball",
    "href": "/ti/ioc/sha256/f89694ba247a7a67e582572094c9f19d2e09882eff8917f78125d54b733bd24e",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "80c18e0d71a31a2e66d8796c6d7081fa3414c1801057131f1cd851c87c1a029e",
    "context": "faster-axios@1.17.4 npm tarball",
    "href": "/ti/ioc/sha256/80c18e0d71a31a2e66d8796c6d7081fa3414c1801057131f1cd851c87c1a029e",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "bc46e88b1fdf8c27e3404146306b4651f69728f7d8d939a219dfbcb5a23ef69a",
    "context": "Stage 4 hello.exe. PE32 NSIS self-extracting installer, 86,235,515 bytes (~86MB). Contains electron-builder Electron app with Epsilon Stealer in resources/app.asar -> src/index.js (3,360 lines). NSIS header references www.inkscape.org (decoy).",
    "href": "/ti/ioc/sha256/bc46e88b1fdf8c27e3404146306b4651f69728f7d8d939a219dfbcb5a23ef69a",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://cold5.gofile.io/download/web/c5d2304a-2ede-4fd8-904b-9a6cdd3f8a6c/analyst.js",
    "context": "faster-axios v1.17.3 stage-2 delivery URL (gofile.io file hosting). Now returns landing page; likely token-gated or removed.",
    "href": "/ti/ioc/url/url-d1b4590859c1",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://apparently-movers-mysql-heights.trycloudflare.com/download/datab1",
    "context": "faster-axios v1.17.4 stage-2 delivery URL (Cloudflare quick-tunnel C2). LIVE, returned HTTP 200. Stage 3 = Windows-only dropper.",
    "href": "/ti/ioc/url/url-be8a73e94fa8",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://apparently-movers-mysql-heights.trycloudflare.com/download/epsilon",
    "context": "Stage 4 download URL. Dropper fetches hello.exe to %TEMP% and runs via child_process.execFile.",
    "href": "/ti/ioc/url/url-b3babde08035",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://apparently-movers-mysql-heights.trycloudflare.com/download/browser",
    "context": "Shellcode download URL. Epsilon Stealer fetches XOR-encoded (key 0xAA) shellcode for process injection into dllhost.exe.",
    "href": "/ti/ioc/url/url-2cc6594188a1",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "apparently-movers-mysql-heights.trycloudflare.com",
    "context": "Cloudflare quick-tunnel C2 host for faster-axios. Serves: stage-2 delivery (/download/datab1), stage-4 PE (/download/epsilon), and shellcode (/download/browser).",
    "href": "/ti/ioc/domain/apparently-movers-mysql-heights.trycloudflare.com",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "recorded-distinct-face-girlfriend.trycloudflare.com",
    "context": "Epsilon Stealer exfil API tunnel. Endpoints: /customer (registration), /upload (file exfil), /discord-token (Discord token exfil), /clip (clipboard data).",
    "href": "/ti/ioc/domain/recorded-distinct-face-girlfriend.trycloudflare.com",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://recorded-distinct-face-girlfriend.trycloudflare.com/customer",
    "context": "Epsilon Stealer exfil API base. Sub-endpoints: /upload, /discord-token, /clip.",
    "href": "/ti/ioc/url/url-46d756474c87",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "consequences-faces-weblogs-clinical.trycloudflare.com",
    "context": "SHARED INFRASTRUCTURE linking turbo-axios and faster-axios (high confidence same operator). turbo-axios v1.17.2 used this tunnel as stage-2 C2 at /download/datab1. faster-axios Epsilon Stealer source references this tunnel as DOWNLOAD_URL constant (line 99) at /download/load. Campaign-level pivot indicator.",
    "href": "/ti/ioc/domain/consequences-faces-weblogs-clinical.trycloudflare.com",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://consequences-faces-weblogs-clinical.trycloudflare.com/download/load",
    "context": "Secondary download URL used by Epsilon Stealer (faster-axios) for additional payload retrieval.",
    "href": "/ti/ioc/url/url-37957119e0f9",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://consequences-faces-weblogs-clinical.trycloudflare.com/download/datab1",
    "context": "turbo-axios v1.17.2 stage-2 C2 endpoint. Same tunnel reused in faster-axios Epsilon Stealer source. Key infrastructure pivot linking both packages to one operator.",
    "href": "/ti/ioc/url/url-bfddb6cbe803",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "philosophy-moms-incoming-milton.trycloudflare.com",
    "context": "Cloudflare quick-tunnel C2 for turbo-axios v1.17.3 stage-2 delivery. Endpoint: /download/datab1. Rotated tunnel after consequences-faces-weblogs-clinical was used for v1.17.2.",
    "href": "/ti/ioc/domain/philosophy-moms-incoming-milton.trycloudflare.com",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://philosophy-moms-incoming-milton.trycloudflare.com/download/datab1",
    "context": "turbo-axios v1.17.3 stage-2 delivery URL. Rotated Cloudflare quick-tunnel with same /download/datab1 path pattern as all other campaign tunnels.",
    "href": "/ti/ioc/url/url-94fe81bf151c",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "prep-integer-lit-preferences.trycloudflare.com",
    "context": "WebSocket RAT gateway for Epsilon Stealer. Persistent WSS connection with auto-reconnect. Supports arbitrary cmd.exe/powershell execution with real-time stdout streaming.",
    "href": "/ti/ioc/domain/prep-integer-lit-preferences.trycloudflare.com",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "%TEMP%\\hello.exe",
    "context": "Windows drop path for stage-4 NSIS PE, executed via child_process.execFile.",
    "href": "/ti/ioc/file_path/file_path-299e62eaf3d2",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "%LOCALAPPDATA%\\Microsoft\\Windows\\0\\svchost.exe",
    "context": "Epsilon Stealer persistence copy. Binary copied here and launched via HKCU Run key on reboot.",
    "href": "/ti/ioc/file_path/file_path-06ddc0f31f33",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\svchost",
    "context": "Registry Run key set by Epsilon Stealer for boot persistence. Points to %LOCALAPPDATA%\\Microsoft\\Windows\\0\\svchost.exe.",
    "href": "/ti/ioc/file_path/file_path-63c727ebbb91",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "%TEMP%\\browser-extraction-<username>",
    "context": "Staging directory for injected browser credential data. <username> replaced with victim's Windows username.",
    "href": "/ti/ioc/file_path/file_path-a0f1aa8e96f1",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "%TEMP%\\epsilon-<username>",
    "context": "Main staging directory for all Epsilon Stealer exfil data. <username> replaced with victim's Windows username.",
    "href": "/ti/ioc/file_path/file_path-a4a63f7fd166",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "github_repo",
    "value": "speedsteraxios",
    "context": "npm publisher account handle for faster-axios (used as weak actor selector; not a confirmed GitHub repo).",
    "href": "/ti/ioc/github_repo/github_repo-d1b2ccd914ac",
    "campaigns": [
      "Epsilon Axios Typosquat Campaign"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "email",
    "value": "emcd-vue@proton.me",
    "context": "npm maintainer email for the emcd-vue account that published the Wave 3 packages. Anonymous Proton Mail address. Fourth email identity tied to the oob-moika-tech campaign.",
    "href": "/ti/ioc/email/emcd-vue@proton.me",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "emcd-vue.io",
    "context": "Fake domain used in Wave 3 package README and metadata to impersonate the EMCD organization. Not related to real emcd.io. Social engineering artifact.",
    "href": "/ti/ioc/domain/emcd-vue.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "github.emcd-vue.io",
    "context": "Fake GitHub subdomain used as the repository URL in @emcd-vue package metadata (git+https://github.emcd-vue.io/platform/auth.git). Social engineering artifact designed to mimic a private GitHub Enterprise instance.",
    "href": "/ti/ioc/domain/github.emcd-vue.io",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "~/.emcd-vue_init.js",
    "context": "Second-stage dropper written to the user home directory (not OS temp dir) by the Wave 3 postinstall hook, then spawned detached. Dot-hidden file. Persistence upgrade over Waves 1+2 which used os.tmpdir().",
    "href": "/ti/ioc/file_path/file_path-18b2e77e2232",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "~/.emcd-vue_init/",
    "context": "Home-directory cache directory used for run-once deduplication. Contains JSON files keyed by hash(package_name + hostname + project_root). Wave 3 replacement for Wave 2's ~/.cache/._t-in-one_init/.",
    "href": "/ti/ioc/file_path/file_path-3694d055c31d",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "EMCD_VUE_NO_TELEMETRY",
    "context": "Functional kill switch environment variable checked by the Wave 3 postinstall code. Setting this variable causes the payload to exit early without beaconing. NOT the variable advertised in the README (which is EMCD_VUE_8D440FE1_NO_TEL — non-functional by design).",
    "href": "/ti/ioc/file_path/file_path-d28f087cd53b",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "EMCD_VUE_8D440FE1_NO_TEL",
    "context": "README-advertised kill switch env var — deliberately mismatched from the functional code kill switch (EMCD_VUE_NO_TELEMETRY). Setting this variable does NOT prevent payload execution. Social engineering artifact: the 8D440FE1 hex fragment in the name indicates deliberate construction, not a typo.",
    "href": "/ti/ioc/file_path/file_path-bda88e7bb928",
    "campaigns": [],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "031ba872d5a84bfb18115f432811e4b45180346a1bae653f7fd85f918e7bb3a3",
    "context": "patch-client@4.0.4 malicious tarball SHA256",
    "href": "/ti/ioc/sha256/031ba872d5a84bfb18115f432811e4b45180346a1bae653f7fd85f918e7bb3a3",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "df1732f5bfec12e066be44dee02ec8a243e4868d38672c1b1d065359dd735a14",
    "context": "index.js dropper SHA256 (ROT-9 + AES-128-GCM loader)",
    "href": "/ti/ioc/sha256/df1732f5bfec12e066be44dee02ec8a243e4868d38672c1b1d065359dd735a14",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "sha256",
    "value": "0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35",
    "context": "decrypted Bun worm payload SHA256",
    "href": "/ti/ioc/sha256/0dc06ecdaa63fe24859cfd955053c23245c536e4733480239d14bebf12688e35",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://registry.npmjs.org/-/npm/v1/oidc/token/exchange/package/",
    "context": "npm OIDC-to-publish-token exchange endpoint abused for self-propagation",
    "href": "/ti/ioc/url/url-6e07621b67f6",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "url",
    "value": "https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/",
    "context": "Bun runtime download URL used by the Miasma worm bootstrapper across all waves (inferred for Wave 5; unconfirmed until payload is reversed)",
    "href": "/ti/ioc/url/url-64f182498063",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "/var/run/secrets/kubernetes.io/serviceaccount/token",
    "context": "Kubernetes service account token harvested",
    "href": "/ti/ioc/file_path/file_path-ca72b599811b",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "/var/run/docker.sock",
    "context": "Docker socket abused for container escape",
    "href": "/ti/ioc/file_path/file_path-71329c4cc6e3",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "/tmp/p<random>.js",
    "context": "Temp file pattern for decoded worm payload before Bun execution (inherited from prior Miasma waves; unconfirmed for Wave 5 until payload is reversed)",
    "href": "/ti/ioc/file_path/file_path-689667fb8c5f",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "/tmp/b-<random>/bun",
    "context": "runtime artifact (downloaded Bun runtime)",
    "href": "/ti/ioc/file_path/file_path-59b338a3cd5c",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "file_path",
    "value": "/tmp/kitty-<random>",
    "context": "runtime worm artifact",
    "href": "/ti/ioc/file_path/file_path-3f0c1ce3224a",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "login.microsoftonline.com",
    "context": "Azure managed identity / token endpoint queried",
    "href": "/ti/ioc/domain/login.microsoftonline.com",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "domain",
    "value": "graph.microsoft.com",
    "context": "Azure Graph API queried for identity data",
    "href": "/ti/ioc/domain/graph.microsoft.com",
    "campaigns": [
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-06-01"
  },
  {
    "kind": "email",
    "value": "nath.dr4k3@gmail.com",
    "context": "npm maintainer email for the t-in-one account that published the 12 Wave 2 packages. First email identity tied to the oob-moika-tech campaign (Wave 1 accounts mr.4nd3r50n and pik-libs had no public email).",
    "href": "/ti/ioc/email/nath.dr4k3@gmail.com",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "file_path",
    "value": "._t-in-one_init.js",
    "context": "Second-stage dropper written to the OS temp directory (os.tmpdir()) by the Wave 2 postinstall hook, then spawned detached. Follows the same ._<scope>_init.js naming pattern as Wave 1's ._cloudplatform-single-spa_init.js.",
    "href": "/ti/ioc/file_path/file_path-aee3ea2cd2fb",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "file_path",
    "value": "~/.cache/._t-in-one_init/",
    "context": "Run-once de-duplication marker directory created by the Wave 2 payload so a host is beaconed only once. New in Wave 2.",
    "href": "/ti/ioc/file_path/file_path-747bf8f427cd",
    "campaigns": [],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "domain",
    "value": "npm.t-in-one.io",
    "context": "Fabricated internal npm registry domain in the @t-in-one README and .npmrc lure (registry=https://npm.t-in-one.io). Social engineering artifact; not confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/npm.t-in-one.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "domain",
    "value": "docs.t-in-one.io",
    "context": "Fabricated docs domain in @t-in-one README. Social engineering artifact; not confirmed functional.",
    "href": "/ti/ioc/domain/docs.t-in-one.io",
    "campaigns": [],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "domain",
    "value": "jira.t-in-one.io",
    "context": "Fabricated Jira domain in @t-in-one README. Social engineering artifact; not confirmed functional.",
    "href": "/ti/ioc/domain/jira.t-in-one.io",
    "campaigns": [],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "sha256",
    "value": "23ccdefb9b917373a4b723d8d482eb6b8880e7e45b0d21cfa5d21d5c27da4918",
    "context": "SHA256 of the @t-in-one/add_application@5.7.1 npm tarball (registry.npmjs.org). Sample Wave 2 artifact.",
    "href": "/ti/ioc/sha256/23ccdefb9b917373a4b723d8d482eb6b8880e7e45b0d21cfa5d21d5c27da4918",
    "campaigns": [],
    "discovered_at": "2026-05-29"
  },
  {
    "kind": "domain",
    "value": "copilot-ai.whisdev.org",
    "context": "Secondary hostname on C2 IP 195.201.194.107. Linked to bink/ptc-bink/whisdev persona cluster (JFrog attribution).",
    "href": "/ti/ioc/domain/copilot-ai.whisdev.org",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "sha256-validate-rpc.vercel.app",
    "context": "Contagious Trader exfil endpoint used by polymarket-validator (toskypi, Feb 2026)",
    "href": "/ti/ioc/domain/sha256-validate-rpc.vercel.app",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "changelog.rest",
    "context": "Contagious Trader exfil endpoint used by changelog-logger-utilities (toskypi, Mar 2026)",
    "href": "/ti/ioc/domain/changelog.rest",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "polblxpnl.space",
    "context": "Contagious Trader C2 domain",
    "href": "/ti/ioc/domain/polblxpnl.space",
    "campaigns": [],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "sha256",
    "value": "b2954c945b51dbd6fa88ac72338b7fbf76dec7d9909ceada9d36b21330842c97",
    "context": "MicrosoftSystem64 Linux ELF binary (81 MB Node.js SEA, v1.0.8)",
    "href": "/ti/ioc/sha256/b2954c945b51dbd6fa88ac72338b7fbf76dec7d9909ceada9d36b21330842c97",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "email",
    "value": "tosky.pi1016@gmail.com",
    "context": "npm account toskypi, linked to ~20 DPRK npm accounts per kmsec.uk. Published polymarket-validator, changelog-logger-utilities. Famous Chollima.",
    "href": "/ti/ioc/email/tosky.pi1016@gmail.com",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://huggingface.co/jpeek998/system-releases/resolve/main",
    "context": "Binary update URL for MicrosoftSystem64 self-update (24h interval)",
    "href": "/ti/ioc/url/url-961b993523df",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://huggingface.co/Lordplay/system-releases",
    "context": "Original binary hosting repo on HuggingFace (disabled by HF, account Lordplay created 2025-11-24). Shared by jpeek868/886/895 cluster.",
    "href": "/ti/ioc/url/url-ad92b7bf2e37",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://huggingface.co/jpeek998/linux_doc_75a5ffec36ca",
    "context": "Third victim dataset: 48 screenshot files, started 2026-05-28T06:10:24Z. Active compromise evidence.",
    "href": "/ti/ioc/url/url-6a9350e31e52",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "file_path",
    "value": "~/.local/share/MicrosoftSystem64",
    "context": "Linux install directory for MicrosoftSystem64 binary and state files",
    "href": "/ti/ioc/file_path/file_path-52873c1fd43c",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "file_path",
    "value": "~/.pcl-state/uploads.json",
    "context": "Screenshot upload state tracker for HuggingFace exfiltration",
    "href": "/ti/ioc/file_path/file_path-1cd95f5e2f53",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "oob.moika.tech",
    "context": "Shared C2 host across all three waves. Hosts /report exfiltration endpoint and /payload/{platform} second-stage scripts. Wave 3 platform strings: linux-x64, darwin-arm64, win.",
    "href": "/ti/ioc/domain/oob.moika.tech",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://oob.moika.tech/report",
    "context": "Exfiltration endpoint. Receives HTTP POST with process.env, hostname, username, platform, arch, cwd, Node.js version, and X-Secret authentication header.",
    "href": "/ti/ioc/url/url-0f283ce50690",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://oob.moika.tech/payload/mac.js",
    "context": "Second-stage payload for macOS, fetched by postinstall hook on darwin systems.",
    "href": "/ti/ioc/url/url-5b6a9aeee063",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://oob.moika.tech/payload/win.js",
    "context": "Second-stage payload for Windows, fetched by postinstall hook on win32 systems.",
    "href": "/ti/ioc/url/url-fd0e7e849589",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "url",
    "value": "https://oob.moika.tech/payload/linux.js",
    "context": "Second-stage payload for Linux, fetched by postinstall hook on linux systems.",
    "href": "/ti/ioc/url/url-ebd523705dbe",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "file_path",
    "value": "._cloudplatform-single-spa_init.js",
    "context": "Temp file written by the postinstall hook when downloading the second-stage payload. Written to the OS temp directory (os.tmpdir()). Name is consistent across all packages regardless of scope.",
    "href": "/ti/ioc/file_path/file_path-b7d5e2a03a48",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "telemetry.car-loans.io",
    "context": "Fabricated telemetry domain appearing only in @car-loans scope README text. Social engineering artifact — not confirmed functional C2. Declared opt-out: CAR_LOANS_NO_TELEMETRY=1. Actual exfiltration target is oob.moika.tech.",
    "href": "/ti/ioc/domain/telemetry.car-loans.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "telemetry.cloudplatform-single-spa.io",
    "context": "Fabricated telemetry domain appearing only in @cloudplatform-single-spa scope README text. Social engineering artifact — not confirmed functional C2. Declared opt-out: CLOUDPLATFORM_SINGLE_SPA_NO_TELEMETRY=1. Actual exfiltration target is oob.moika.tech.",
    "href": "/ti/ioc/domain/telemetry.cloudplatform-single-spa.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "npm.car-loans.io",
    "context": "Fabricated private npm registry domain in @car-loans README and .npmrc comment (registry=https://npm.car-loans.io). Social engineering artifact confirming target org uses a private npm registry — the precondition for dependency confusion. Not confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/npm.car-loans.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "npm.cloudplatform-single-spa.io",
    "context": "Fabricated private npm registry domain in @cloudplatform-single-spa README. Social engineering artifact confirming target org uses a private npm registry. Not confirmed functional infrastructure.",
    "href": "/ti/ioc/domain/npm.cloudplatform-single-spa.io",
    "campaigns": [
      "oob-moika-tech-depconf-2026"
    ],
    "discovered_at": "2026-05-28"
  },
  {
    "kind": "domain",
    "value": "21baseballacademy.com",
    "context": "Ad script delivery domain used by terminal3airport packages. Hosts external JS payload at cdn.21baseballacademy.com.",
    "href": "/ti/ioc/domain/21baseballacademy.com",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "domain",
    "value": "abdct.com",
    "context": "Popunder redirect destination triggered by adware in terminal3airport packages.",
    "href": "/ti/ioc/domain/abdct.com",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "domain",
    "value": "woofbeginner.com",
    "context": "Additional ad/monetization script host used by terminal3airport packages.",
    "href": "/ti/ioc/domain/woofbeginner.com",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "url",
    "value": "https://cdn.21baseballacademy.com/script/jrqK2HPsliMjRW5Q.js",
    "context": "External ad script injected into proxy pages by terminal3airport packages.",
    "href": "/ti/ioc/url/url-b0d246209ba7",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "url",
    "value": "https://woofbeginner.com/0a/91/35/0a913561831bdf2c26dcf18b852b5cc1.js",
    "context": "Additional monetization script loaded by terminal3airport adware.",
    "href": "/ti/ioc/url/url-2975114f1199",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "email",
    "value": "adofhiter23@gmail.com",
    "context": "npm maintainer email for terminal3airport account. Published all 141 malicious packages.",
    "href": "/ti/ioc/email/adofhiter23@gmail.com",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "github_repo",
    "value": "lucideproxy/svg",
    "context": "GitHub repository referenced in package source code. Associated with Lucide Proxy project.",
    "href": "/ti/ioc/github_repo/github_repo-ad6147b12ea6",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "sha256",
    "value": "0d27f455ae056aa908c276d9b17a73d469227257838ec9bcbcb3f1c66169b5a4",
    "context": "SHA-256 of obfuscated JS file a3g0q43tbe.js found in wave 2-3 packages.",
    "href": "/ti/ioc/sha256/0d27f455ae056aa908c276d9b17a73d469227257838ec9bcbcb3f1c66169b5a4",
    "campaigns": [],
    "discovered_at": "2026-05-27"
  },
  {
    "kind": "url",
    "value": "ws://204.10.194.247:9877",
    "context": "WebSocket C2 relay endpoint for forge-jsx RAT campaign",
    "href": "/ti/ioc/url/url-253b2bf9df4b",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "url",
    "value": "http://204.10.194.247:8765",
    "context": "HTTP API endpoint for forge-jsx RAT campaign",
    "href": "/ti/ioc/url/url-cb4c7a0deb59",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "email",
    "value": "jacksonkaandorp2@outlook.com",
    "context": "npm account email for jacksonkaandorp2, publisher of forge-jsxy (Wave 2)",
    "href": "/ti/ioc/email/jacksonkaandorp2@outlook.com",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "email",
    "value": "rafaelsilva19930303@gmail.com",
    "context": "npm account email for rafael_silva, publisher of forge-jsx4 (Wave 3)",
    "href": "/ti/ioc/email/rafaelsilva19930303@gmail.com",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "domain",
    "value": "taohunter.ai",
    "context": "Domain associated with johntaohunter npm account (Wave 1)",
    "href": "/ti/ioc/domain/taohunter.ai",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "4938d47fe6216f8f9fee0527bf5112c04c15a9ea62f87869677619aa5400f09f",
    "context": "SHA-256 of forge-jsxy v1.0.91 (latest Wave 2 version)",
    "href": "/ti/ioc/sha256/4938d47fe6216f8f9fee0527bf5112c04c15a9ea62f87869677619aa5400f09f",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "8070daba5d6ca61c357574526d1e0f468ae575a4edf74cc90a8d8b8c78e3aeef",
    "context": "SHA-256 of forge-jsxy v1.0.66 (first Wave 2 version)",
    "href": "/ti/ioc/sha256/8070daba5d6ca61c357574526d1e0f468ae575a4edf74cc90a8d8b8c78e3aeef",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "6321dacc21675f81c4cee7db8434ca4cf0e228d3b592bde26a0a40f223dbb00e",
    "context": "SHA-256 of forge-jsx4 v1.0.123 tarball (Wave 3)",
    "href": "/ti/ioc/sha256/6321dacc21675f81c4cee7db8434ca4cf0e228d3b592bde26a0a40f223dbb00e",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "file_path",
    "value": "~/.config/systemd/user/forge-js-worker.service",
    "context": "Linux systemd persistence for forge-jsx RAT",
    "href": "/ti/ioc/file_path/file_path-1cbc96dac65a",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "file_path",
    "value": "~/.config/autostart/forge-js-worker.desktop",
    "context": "Linux XDG autostart persistence for forge-jsx RAT",
    "href": "/ti/ioc/file_path/file_path-6146aef02482",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "file_path",
    "value": "~/Library/LaunchAgents/com.forgejs.worker.plist",
    "context": "macOS LaunchAgent persistence for forge-jsx RAT",
    "href": "/ti/ioc/file_path/file_path-e8d302abc731",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "ipv4",
    "value": "212.193.3.61",
    "context": "New C2 IP introduced in Wave 3 parallel packages (pino-zod, zod-pino). AS unknown. WebSocket relay port 9877, HTTP API port 8765. Rotated from 204.10.194.247.",
    "href": "/ti/ioc/ipv4/212.193.3.61",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "url",
    "value": "ws://212.193.3.61:9877",
    "context": "WebSocket C2 relay endpoint for forge-jsx RAT Wave 3 parallel packages (pino-zod, zod-pino)",
    "href": "/ti/ioc/url/url-6fa771ff7557",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "url",
    "value": "http://212.193.3.61:8765",
    "context": "HTTP API endpoint for forge-jsx RAT Wave 3 parallel packages (pino-zod, zod-pino)",
    "href": "/ti/ioc/url/url-2807b9470bab",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "0eb72e0794c7e51ca1d790c443b5f573e1288bad6e6c56d1bd9c4b69a71d65d0",
    "context": "SHA-256 of pino-zod v1.0.122 tarball (Wave 3 parallel)",
    "href": "/ti/ioc/sha256/0eb72e0794c7e51ca1d790c443b5f573e1288bad6e6c56d1bd9c4b69a71d65d0",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "1f7616b3c38f85860abd9ae989d72915e9c13f0d106804471a811a38d63e5293",
    "context": "SHA-256 of zod-pino v1.0.125 tarball (Wave 3 parallel, latest known version)",
    "href": "/ti/ioc/sha256/1f7616b3c38f85860abd9ae989d72915e9c13f0d106804471a811a38d63e5293",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "0085d5b5d4a2bbb3fd1f38e6b251872d4f753aa8f1ac7f20524c521ff5ca5933",
    "context": "SHA-256 of compose-logger-stand v1.0.126 tarball (Wave 4 bridge package)",
    "href": "/ti/ioc/sha256/0085d5b5d4a2bbb3fd1f38e6b251872d4f753aa8f1ac7f20524c521ff5ca5933",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "email",
    "value": "jacksonkaandorp_3@outlook.com",
    "context": "npm account email for jacksondkeindlson, publisher of compose-logger-stand (Wave 4 bridge). Variant of Wave 2's jacksonkaandorp2@outlook.com handle pattern.",
    "href": "/ti/ioc/email/jacksonkaandorp_3@outlook.com",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "a99be9fe0e7d66064a11ee096fd8c1a9178e3ee2b761fa8a2bde81bfe846b9a2",
    "context": "SHA-256 of zod-pino434 v1.0.127 tarball (Wave 4, first package with rotated AES key)",
    "href": "/ti/ioc/sha256/a99be9fe0e7d66064a11ee096fd8c1a9178e3ee2b761fa8a2bde81bfe846b9a2",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "9e570641fd815e2fd6cf50aaa847c43c2fe938c7b368bf7c239f511827ff9a24",
    "context": "SHA-256 of zod-pino434 v1.0.128 tarball (Wave 4, latest known version)",
    "href": "/ti/ioc/sha256/9e570641fd815e2fd6cf50aaa847c43c2fe938c7b368bf7c239f511827ff9a24",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "93817e263f285f20ed213eb07bbab2857493183c0abf9563facfc65fdd4467f7",
    "context": "SHA-256 of zod-pino444 v1.0.128 tarball (Wave 4)",
    "href": "/ti/ioc/sha256/93817e263f285f20ed213eb07bbab2857493183c0abf9563facfc65fdd4467f7",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "1d4ef70d7856704b373579ae23cba0ebf690ef062b29361f6aa0f51a1cdd9052",
    "context": "SHA-256 of zod-pino444 v1.0.131 tarball (Wave 4, latest known version)",
    "href": "/ti/ioc/sha256/1d4ef70d7856704b373579ae23cba0ebf690ef062b29361f6aa0f51a1cdd9052",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "email",
    "value": "donimiqueakers@gmail.com",
    "context": "npm account email for donimique, publisher of zod-pino434, zod-pino444, zredis-typed, pinokio-redis (Wave 4)",
    "href": "/ti/ioc/email/donimiqueakers@gmail.com",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "a1853a45bcb561f96e0e7c0dec7f96e640ae53be62e65158880812ff104c9e41",
    "context": "SHA-256 of zredis-typed v1.0.127 tarball (Wave 4, only known version)",
    "href": "/ti/ioc/sha256/a1853a45bcb561f96e0e7c0dec7f96e640ae53be62e65158880812ff104c9e41",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "sha256",
    "value": "a400b0342add77fd3a58e086334b35e11d79e234b180bb360f48adcd61ec4acd",
    "context": "SHA-256 of pinokio-redis v1.0.127 tarball (Wave 4, only known version; user-confirmed all versions malicious)",
    "href": "/ti/ioc/sha256/a400b0342add77fd3a58e086334b35e11d79e234b180bb360f48adcd61ec4acd",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-05-26"
  },
  {
    "kind": "domain",
    "value": "polymarketbot.polymarketdev.workers.dev",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/polymarketbot.polymarketdev.workers.dev",
    "campaigns": [
      "Crypto Wallet Drainers"
    ],
    "discovered_at": "2026-05-21"
  },
  {
    "kind": "sha256",
    "value": "e01b85c1437085a519217338fe4ee5ed7858c28a10f8c1477b2f1857c3386edb",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/e01b85c1437085a519217338fe4ee5ed7858c28a10f8c1477b2f1857c3386edb",
    "campaigns": [
      "Crypto Wallet Drainers"
    ],
    "discovered_at": "2026-05-21"
  },
  {
    "kind": "email",
    "value": "dmtnatpepes@proton.me",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/dmtnatpepes@proton.me",
    "campaigns": [
      "Crypto Wallet Drainers"
    ],
    "discovered_at": "2026-05-21"
  },
  {
    "kind": "domain",
    "value": "utaq.cfww.shop",
    "context": "Former Coruna exploit kit host (Phase 2). 180.178.50.158 AS45753 Netsec Limited HK. Hosted 14 exploit modules (606KB) at /gooll/. DEAD as of 2026-07-03.",
    "href": "/ti/ioc/domain/utaq.cfww.shop",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "domain",
    "value": "git.youzzjizz.com",
    "context": "Former payload host (Phase 1, version 4.13.3). String.fromCharCode decoded URL. DEAD as of 2026-07-03.",
    "href": "/ti/ioc/domain/git.youzzjizz.com",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "ipv4",
    "value": "180.178.50.158",
    "context": "IP for utaq.cfww.shop (former Coruna exploit kit host, Phase 2). AS45753 Netsec Limited, Hong Kong. DEAD.",
    "href": "/ti/ioc/ipv4/180.178.50.158",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "ipv4",
    "value": "172.67.141.14",
    "context": "Cloudflare IP for l1ewsu3yjkqeroy.xyz (former C2 sync, Phase 2). DEAD.",
    "href": "/ti/ioc/ipv4/172.67.141.14",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "ipv4",
    "value": "104.21.40.254",
    "context": "Cloudflare IP for l1ewsu3yjkqeroy.xyz (former C2 sync, Phase 2). DEAD.",
    "href": "/ti/ioc/ipv4/104.21.40.254",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "273206e2973df6ba7474aa66693797c98dcf26b794da4c3e863ab8d8c694868d",
    "context": "art-template@4.13.3 npm tarball (Phase 1)",
    "href": "/ti/ioc/sha256/273206e2973df6ba7474aa66693797c98dcf26b794da4c3e863ab8d8c694868d",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "5b5fe5d92808a732d0d44246cd706295cc739ed7f4dcae19112df666bc5d4f7d",
    "context": "art-template@4.13.5 npm tarball (Phase 2, unpublished from npm)",
    "href": "/ti/ioc/sha256/5b5fe5d92808a732d0d44246cd706295cc739ed7f4dcae19112df666bc5d4f7d",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "101afde88ff8b5c02fd341eda55022a39203088c2ff11dcb73214911cf5afb77",
    "context": "art-template@4.13.6 npm tarball (Phase 2, unpublished from npm)",
    "href": "/ti/ioc/sha256/101afde88ff8b5c02fd341eda55022a39203088c2ff11dcb73214911cf5afb77",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "d8e3973a0b3c5359d1f53a22491b56bdd31dee13a51c01c7126bc6694584512f",
    "context": "Original Coruna exploit kit payload served from v3.jiathis.com/code/jia.js (Phase 2, no longer served)",
    "href": "/ti/ioc/sha256/d8e3973a0b3c5359d1f53a22491b56bdd31dee13a51c01c7126bc6694584512f",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "f31bdd069fe7966ae11be1f78ee5dd44445938856dd1df12379e0e84a6851f5c",
    "context": "49554fde7424c31c.js stage-4 Coruna malware loader (50KB, Phase 2)",
    "href": "/ti/ioc/sha256/f31bdd069fe7966ae11be1f78ee5dd44445938856dd1df12379e0e84a6851f5c",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha1",
    "value": "57620206d62079baad0e57e6d9ec93120c0f5247",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/57620206d62079baad0e57e6d9ec93120c0f5247",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha1",
    "value": "14669ca3b1519ba2a8f40be287f646d4d7593eb0",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/14669ca3b1519ba2a8f40be287f646d4d7593eb0",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "md5",
    "value": "7d86eb847ecfd3c972fa457a6abaa0da",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/7d86eb847ecfd3c972fa457a6abaa0da",
    "campaigns": [],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "email",
    "value": "goofychris69@gmail.com",
    "context": "Persistent maintainer account (daughtrymom). Controls art-template, express-art-template, art-template-loader, koa-art-template across all phases.",
    "href": "/ti/ioc/email/goofychris69@gmail.com",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "email",
    "value": "npmpacketmaintainmember7@proton.me",
    "context": "Phase 2 publisher account (npmpacketmaintainmember7). Published 4.13.5 and 4.13.6. Removed from maintainers after Phase 3.",
    "href": "/ti/ioc/email/npmpacketmaintainmember7@proton.me",
    "campaigns": [
      "art-template npm Supply Chain Compromise"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "domain",
    "value": "check.git-service.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/check.git-service.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "domain",
    "value": "www.youtube.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/www.youtube.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "ipv4",
    "value": "160.119.64.3",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/160.119.64.3",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "ipv4",
    "value": "185.95.159.32",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/185.95.159.32",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "3de04fe2a76262743ed089efa7115f4508619838e77d60b9a1aab8b20d2cc8bf",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/3de04fe2a76262743ed089efa7115f4508619838e77d60b9a1aab8b20d2cc8bf",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "85f54c089d78ebfb101454ec934c767065a342a43c9ee1beac8430cdd3b2086f",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/85f54c089d78ebfb101454ec934c767065a342a43c9ee1beac8430cdd3b2086f",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "c0b094e46842260936d4b97ce63e4539b99a3eae48b736798c700217c52569dc",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/c0b094e46842260936d4b97ce63e4539b99a3eae48b736798c700217c52569dc",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "sha256",
    "value": "069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-20"
  },
  {
    "kind": "domain",
    "value": "t.m-kosche.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/t.m-kosche.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "ipv4",
    "value": "169.254.170.2",
    "context": "AWS ECS task metadata endpoint queried for credentials",
    "href": "/ti/ioc/ipv4/169.254.170.2",
    "campaigns": [
      "Mini Shai-Hulud",
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "sha256",
    "value": "a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "sha1",
    "value": "1916faa365f2788b6e193514872d51a242876569",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/1916faa365f2788b6e193514872d51a242876569",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "sha1",
    "value": "7cb42f57561c321ecb09b4552802ae0ac55b3a7a",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/7cb42f57561c321ecb09b4552802ae0ac55b3a7a",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "sha1",
    "value": "dc3d62a2181beb9f326952a2d212900c94f2e13d",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/dc3d62a2181beb9f326952a2d212900c94f2e13d",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-19"
  },
  {
    "kind": "ipv4",
    "value": "1.1.1.1",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/1.1.1.1",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "ipv4",
    "value": "8.8.8.8",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/8.8.8.8",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "sha256",
    "value": "449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/449e4265979b5fdb2d3446c021af437e815debd66de7da2fe54f1ad93cbcc75e",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "sha256",
    "value": "c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/c2f4dc64aec4631540a568e88932b61daebbfb7e8281b812fa01b7215f9be9ea",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "sha256",
    "value": "78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "sha256",
    "value": "3427a90c8cb9af764445448648176e120ebc6af0a538158340cf6220de4d01b7",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/3427a90c8cb9af764445448648176e120ebc6af0a538158340cf6220de4d01b7",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "sha256",
    "value": "fdba4191831a13debf9d8c0c940b0301c7b7f01d27f1b1c73ed3ceaa2db4103b",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/fdba4191831a13debf9d8c0c940b0301c7b7f01d27f1b1c73ed3ceaa2db4103b",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-14"
  },
  {
    "kind": "ipv4",
    "value": "207.90.194.2",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/207.90.194.2",
    "campaigns": [
      "Claude Code Hook Backdoors"
    ],
    "discovered_at": "2026-05-13"
  },
  {
    "kind": "sha1",
    "value": "8daaa2003784a92f4761ed3c9d5560ef8cf4bffa",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/8daaa2003784a92f4761ed3c9d5560ef8cf4bffa",
    "campaigns": [
      "Claude Code Hook Backdoors"
    ],
    "discovered_at": "2026-05-13"
  },
  {
    "kind": "md5",
    "value": "b604b21749a396111bb111d46d97b1c4",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/b604b21749a396111bb111d46d97b1c4",
    "campaigns": [
      "Claude Code Hook Backdoors"
    ],
    "discovered_at": "2026-05-13"
  },
  {
    "kind": "domain",
    "value": "git-tanstack.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/git-tanstack.com",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-12"
  },
  {
    "kind": "domain",
    "value": "filev2.getsession.org",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/filev2.getsession.org",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-12"
  },
  {
    "kind": "domain",
    "value": "169.254.169.254",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/169.254.169.254",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-12"
  },
  {
    "kind": "sha256",
    "value": "ce7e4199506959fd7a71b64209b2c07b9c82e53a946aa7d78298dc9249230d01",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/ce7e4199506959fd7a71b64209b2c07b9c82e53a946aa7d78298dc9249230d01",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-12"
  },
  {
    "kind": "sha1",
    "value": "79ac49eedf774dd4b0cfa308722bc463cfe5885c",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/79ac49eedf774dd4b0cfa308722bc463cfe5885c",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-05-12"
  },
  {
    "kind": "domain",
    "value": "82.221.101.203",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/82.221.101.203",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-10"
  },
  {
    "kind": "ipv4",
    "value": "82.221.101.203",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/82.221.101.203",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-10"
  },
  {
    "kind": "sha256",
    "value": "263df2348f54f1f4980542a41f69d77b085fb28091a95979ba7f0e9f3d0da861",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/263df2348f54f1f4980542a41f69d77b085fb28091a95979ba7f0e9f3d0da861",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-10"
  },
  {
    "kind": "email",
    "value": "noondeved94ed@wshu.net",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/noondeved94ed@wshu.net",
    "campaigns": [
      "wshu.net npm Credential-Stealer Campaign",
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-10"
  },
  {
    "kind": "domain",
    "value": "172.86.73.132",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/172.86.73.132",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-07"
  },
  {
    "kind": "ipv4",
    "value": "172.86.73.132",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/172.86.73.132",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-07"
  },
  {
    "kind": "sha256",
    "value": "86d17961e9662c53e1fb61701388b7c741bf79c093061df968a3e53c829dcb16",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/86d17961e9662c53e1fb61701388b7c741bf79c093061df968a3e53c829dcb16",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-07"
  },
  {
    "kind": "email",
    "value": "daltonchristiano060@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/daltonchristiano060@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-05-07"
  },
  {
    "kind": "domain",
    "value": "paidgirl.site",
    "context": "Operator-controlled origin allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/domain/paidgirl.site",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "cms.paidgirl.site",
    "context": "ams-ssk deployment serving folders/:folder/files/download-all consumed by common-tg-service",
    "href": "/ti/ioc/domain/cms.paidgirl.site",
    "campaigns": [
      "shetty123 Telegram Hijack"
    ],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "helper-thge.onrender.com",
    "context": "Attribution-laundering HTTP relay; used by common-tg-service on 403/495 responses",
    "href": "/ti/ioc/domain/helper-thge.onrender.com",
    "campaigns": [
      "shetty123 Telegram Hijack"
    ],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "promoteclients2.glitch.me",
    "context": "Operator host leaked in ams-ssk Swagger DTO; sequential staging (promoteClients2)",
    "href": "/ti/ioc/domain/promoteclients2.glitch.me",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "zomcall.netlify.app",
    "context": "Allowed origin in common-tg-service auth guard",
    "href": "/ti/ioc/domain/zomcall.netlify.app",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "report-upi.netlify.app",
    "context": "Allowed origin; names the UPI/India targeting",
    "href": "/ti/ioc/domain/report-upi.netlify.app",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "email",
    "value": "storeslaksmi@gmail.com",
    "context": "Hardcoded 2FA recovery email implanted on every hijacked Telegram account",
    "href": "/ti/ioc/email/storeslaksmi@gmail.com",
    "campaigns": [
      "shetty123 Telegram Hijack"
    ],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "email",
    "value": "dodieajt@gmail.com",
    "context": "Operator npoint.io account credentials committed in npoint.service.js",
    "href": "/ti/ioc/email/dodieajt@gmail.com",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "email",
    "value": "shettysaikumar3@gmail.com",
    "context": "npm publisher email for shetty123 (publisher of both packages)",
    "href": "/ti/ioc/email/shettysaikumar3@gmail.com",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "31.97.59.2",
    "context": "Operator IP allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/ipv4/31.97.59.2",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "148.230.84.50",
    "context": "Operator IP allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/ipv4/148.230.84.50",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "13.228.225.19",
    "context": "Operator IP allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/ipv4/13.228.225.19",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "18.142.128.26",
    "context": "Operator IP allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/ipv4/18.142.128.26",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "54.254.162.138",
    "context": "Operator IP allow-listed in common-tg-service auth guard",
    "href": "/ti/ioc/ipv4/54.254.162.138",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "sha1",
    "value": "5061bc9611e31a48a8085cfab4cb875a6cc633ec",
    "context": "common-tg-service-1.3.207.tgz npm tarball",
    "href": "/ti/ioc/sha1/5061bc9611e31a48a8085cfab4cb875a6cc633ec",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "sha1",
    "value": "80da04770a779330803bdd00d00a354adc12859a",
    "context": "ams-ssk-1.0.33.tgz npm tarball",
    "href": "/ti/ioc/sha1/80da04770a779330803bdd00d00a354adc12859a",
    "campaigns": [],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "domain",
    "value": "152.67.0.53",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/152.67.0.53",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "ipv4",
    "value": "152.67.0.53",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/152.67.0.53",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-05-03"
  },
  {
    "kind": "sha256",
    "value": "e2fda5aa8397799669f29258f69e803cf05d322c1d93269eef6754ca024c3865",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/e2fda5aa8397799669f29258f69e803cf05d322c1d93269eef6754ca024c3865",
    "campaigns": [
      "fucktestpad npm Malware"
    ],
    "discovered_at": "2026-05-01"
  },
  {
    "kind": "sha256",
    "value": "3071422c3294e7b61cb490c57c48c8dea569bacf12e57a078293b6547d7586d3",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/3071422c3294e7b61cb490c57c48c8dea569bacf12e57a078293b6547d7586d3",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha256",
    "value": "56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fb",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fb",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha256",
    "value": "5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha256",
    "value": "d2815d425ae08cc627f1db69009442165f8bbc64b7e9157e2ff9d7aab02094d4",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/d2815d425ae08cc627f1db69009442165f8bbc64b7e9157e2ff9d7aab02094d4",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha256",
    "value": "8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha256",
    "value": "2d4e21d2e78d0868ce7894487e67c67f929d8d81d78c5b07a3ad225b13eae890",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/2d4e21d2e78d0868ce7894487e67c67f929d8d81d78c5b07a3ad225b13eae890",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2026-04-30"
  },
  {
    "kind": "sha1",
    "value": "0a3dd44d361c34cd9036eeb3f49601160a636648",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/0a3dd44d361c34cd9036eeb3f49601160a636648",
    "campaigns": [
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "domain",
    "value": "franki.requestcatcher.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/franki.requestcatcher.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "ipv4",
    "value": "169.254.169.254",
    "context": "AWS IMDS endpoint queried for cloud credentials",
    "href": "/ti/ioc/ipv4/169.254.169.254",
    "campaigns": [
      "No Specific Campaign",
      "Mini Shai-Hulud",
      "Miasma: The Spreading Blight"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "email",
    "value": "npmtpoc@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/npmtpoc@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "ipv4",
    "value": "18.208.244.120",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/18.208.244.120",
    "campaigns": [
      "Crypto Wallet Drainers"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "md5",
    "value": "0123456789abcdef0123456789abcdef",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/0123456789abcdef0123456789abcdef",
    "campaigns": [
      "Crypto Wallet Drainers"
    ],
    "discovered_at": "2026-04-29"
  },
  {
    "kind": "domain",
    "value": "audit.checkmarx.cx",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/audit.checkmarx.cx",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "ipv4",
    "value": "94.154.172.43",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/94.154.172.43",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "sha256",
    "value": "18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "sha256",
    "value": "8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "sha1",
    "value": "de0fac2e4500dabe0009e67214ff5f5447ce83dd",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/de0fac2e4500dabe0009e67214ff5f5447ce83dd",
    "campaigns": [
      "TeamPCP",
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "sha1",
    "value": "bbbca2ddaa5d8feaa63e36b76fdaad77386f024f",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/bbbca2ddaa5d8feaa63e36b76fdaad77386f024f",
    "campaigns": [
      "TeamPCP",
      "Mini Shai-Hulud"
    ],
    "discovered_at": "2026-04-24"
  },
  {
    "kind": "ipv4",
    "value": "0.0.0.0",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/0.0.0.0",
    "campaigns": [
      "fucktestpad npm Malware"
    ],
    "discovered_at": "2026-04-16"
  },
  {
    "kind": "email",
    "value": "fucktestpad@opemails.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/fucktestpad@opemails.com",
    "campaigns": [
      "fucktestpad npm Malware"
    ],
    "discovered_at": "2026-04-16"
  },
  {
    "kind": "domain",
    "value": "204.10.194.247",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/204.10.194.247",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "ipv4",
    "value": "204.10.194.247",
    "context": "C2 server (AS206216 Advin Services LLC, Nurnberg DE). WebSocket relay on port 9877, HTTP API on port 8765. Shared across all forge-jsx/forge-jsxy/forge-jsx4 waves.",
    "href": "/ti/ioc/ipv4/204.10.194.247",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "4cb96c3b033c1aaf7b3d0fe54749058f14d4d914947a6d6d430aca108a7daa5a",
    "context": "SHA-256 of forge-jsx (Wave 1)",
    "href": "/ti/ioc/sha256/4cb96c3b033c1aaf7b3d0fe54749058f14d4d914947a6d6d430aca108a7daa5a",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "email",
    "value": "john@taohunter.ai",
    "context": "npm account email for johntaohunter, publisher of @johntaohunter/forge-jsx",
    "href": "/ti/ioc/email/john@taohunter.ai",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "email",
    "value": "johnceballos0716@gmail.com",
    "context": "npm account email for johnceballos0716, publisher of forge-jsx (Wave 1)",
    "href": "/ti/ioc/email/johnceballos0716@gmail.com",
    "campaigns": [
      "forge-jsx RAT"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "domain",
    "value": "api-sub.jrodacooker.dev",
    "context": "Earlier C2 domain for js-logger-pack, DNS since removed",
    "href": "/ti/ioc/domain/api-sub.jrodacooker.dev",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "domain",
    "value": "huggingface.co",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/huggingface.co",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "ipv4",
    "value": "195.201.194.107",
    "context": "WebSocket + HTTP C2 server on port 8010. Hetzner, DE, AS24940. Secondary hostname: copilot-ai.whisdev.org.",
    "href": "/ti/ioc/ipv4/195.201.194.107",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "a49eee6b6db9da14db46587b68bf1d8a80976812f629bf3e100ac6ba83cf8490",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/a49eee6b6db9da14db46587b68bf1d8a80976812f629bf3e100ac6ba83cf8490",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "6ce3b22b07fd5aef1dd77237334d80718601e4e02a706485572d3dda8993a4e3",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/6ce3b22b07fd5aef1dd77237334d80718601e4e02a706485572d3dda8993a4e3",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "571533a643e67c38087f4da8cce0d3dc14670a52403717e4943433d392860a7f",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/571533a643e67c38087f4da8cce0d3dc14670a52403717e4943433d392860a7f",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "585c5ab1fea06bed4956e34ffd6d6b576122addd34d252b163ae0801098e9eaf",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/585c5ab1fea06bed4956e34ffd6d6b576122addd34d252b163ae0801098e9eaf",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "9f0a7174f9537bdbf63fe2329cea9a14198076180390af9f43a0e5b5c7c46912",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/9f0a7174f9537bdbf63fe2329cea9a14198076180390af9f43a0e5b5c7c46912",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "e35801137cd09fa02aa996145d18ec68d67d71db9810f2608a6285ee1c08b054",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/e35801137cd09fa02aa996145d18ec68d67d71db9810f2608a6285ee1c08b054",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "df45bbac7695f0edad3edde36904f2722f2af761887744a2f1d65df705d28dc6",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/df45bbac7695f0edad3edde36904f2722f2af761887744a2f1d65df705d28dc6",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "43c93c609d48b6cb4f1275c285b5e6960ef74e7f5811b442e3c1038d49128d73",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/43c93c609d48b6cb4f1275c285b5e6960ef74e7f5811b442e3c1038d49128d73",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha256",
    "value": "dbbc31c641c2f1b9a867e745c30dda27dff2db7d91f9faddcf08a504ca2a9d11",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/dbbc31c641c2f1b9a867e745c30dda27dff2db7d91f9faddcf08a504ca2a9d11",
    "campaigns": [],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "sha1",
    "value": "b0a0c8779961bcce1851d35125a7b48fc6ec7d5c",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/b0a0c8779961bcce1851d35125a7b48fc6ec7d5c",
    "campaigns": [],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "email",
    "value": "jpeek868@gmail.com",
    "context": "npm publisher account jpeek868, author of js-logger-pack. Part of jpeek account rotation cluster (jpeek868/886/895). DPRK Famous Chollima.",
    "href": "/ti/ioc/email/jpeek868@gmail.com",
    "campaigns": [
      "Contagious Interview"
    ],
    "discovered_at": "2026-04-15"
  },
  {
    "kind": "domain",
    "value": "xienztiavkygvacpqzgr.supabase.co",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/xienztiavkygvacpqzgr.supabase.co",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-14"
  },
  {
    "kind": "domain",
    "value": "ndfcioahsbgsjmulpjgt.supabase.co",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/ndfcioahsbgsjmulpjgt.supabase.co",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-14"
  },
  {
    "kind": "sha256",
    "value": "4600db4fc30fb6ffa68deed4a25679e674bb3a3e8dae31f3dfc83bea0d757a8f",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/4600db4fc30fb6ffa68deed4a25679e674bb3a3e8dae31f3dfc83bea0d757a8f",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-14"
  },
  {
    "kind": "sha256",
    "value": "2e131f47090516e5a60553aa40d46823e08162390c1d6deb075cf317f00309f7",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/2e131f47090516e5a60553aa40d46823e08162390c1d6deb075cf317f00309f7",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-14"
  },
  {
    "kind": "email",
    "value": "tanvisoul9@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/tanvisoul9@gmail.com",
    "campaigns": [
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-14"
  },
  {
    "kind": "domain",
    "value": "64.227.183.144",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/64.227.183.144",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-04-10"
  },
  {
    "kind": "ipv4",
    "value": "64.227.183.144",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/64.227.183.144",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-04-10"
  },
  {
    "kind": "email",
    "value": "victim59@proton.me",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/victim59@proton.me",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2026-04-10"
  },
  {
    "kind": "domain",
    "value": "cloudflareinsights.vercel.app",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/cloudflareinsights.vercel.app",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "domain",
    "value": "cloudflarefirewall.vercel.app",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/cloudflarefirewall.vercel.app",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "55bee3abfa26a78989baae1053a778d3b4a984d5451621a851211a45fe2a82b9",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/55bee3abfa26a78989baae1053a778d3b4a984d5451621a851211a45fe2a82b9",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "02a00a158ceedaaf7a4bf53002a74d60339d4668d463831fe218905816b72e07",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/02a00a158ceedaaf7a4bf53002a74d60339d4668d463831fe218905816b72e07",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "9d2037fc0ad9ada672d30e17a9496cbde392c5093a9fde0b8f16d28e2e0c50c7",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/9d2037fc0ad9ada672d30e17a9496cbde392c5093a9fde0b8f16d28e2e0c50c7",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "7bff4518f4d49ddf3d04d8167a6f5f17aed9b3703290f65cf71c61ea61f0a7bc",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/7bff4518f4d49ddf3d04d8167a6f5f17aed9b3703290f65cf71c61ea61f0a7bc",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "aa36d4bee44ee1d35af0e211e8cca957044c782b177787b1181d18d6d6323037",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/aa36d4bee44ee1d35af0e211e8cca957044c782b177787b1181d18d6d6323037",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "f4914c528cf92a7e97ac3b24138afb86b4cd9db6960d92ffbbff36a1fb90ead9",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/f4914c528cf92a7e97ac3b24138afb86b4cd9db6960d92ffbbff36a1fb90ead9",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "fc095d3e6a613e27d267d80b448101ef78b02ec07dd3993c734202839015fb54",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/fc095d3e6a613e27d267d80b448101ef78b02ec07dd3993c734202839015fb54",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "sha256",
    "value": "86f60a2196c3d1355efdcfee41f1549c30c6081bf6c106d11e44a64691f8ebd3",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/86f60a2196c3d1355efdcfee41f1549c30c6081bf6c106d11e44a64691f8ebd3",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "email",
    "value": "vanes.s.p.orit.a@googlemail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/vanes.s.p.orit.a@googlemail.com",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "email",
    "value": "support@polymarket.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/support@polymarket.com",
    "campaigns": [
      "big.js Typosquat SSH Backdoor"
    ],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "email",
    "value": "m8ch88l@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/m8ch88l@gmail.com",
    "campaigns": [],
    "discovered_at": "2026-04-09"
  },
  {
    "kind": "domain",
    "value": "telemetry.api-monitor.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/telemetry.api-monitor.com",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "ipv4",
    "value": "143.198.237.25",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/143.198.237.25",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "ipv4",
    "value": "23.236.116.77",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/23.236.116.77",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "ipv4",
    "value": "209.34.235.18",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/209.34.235.18",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha256",
    "value": "4dbecce9ab3cf1739a9b90f9a9f304a3a44f69332320ae0753c129cf078e6f34",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/4dbecce9ab3cf1739a9b90f9a9f304a3a44f69332320ae0753c129cf078e6f34",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha256",
    "value": "513eed96cabdea495a7141666eb77216dee6f0754ef643917346a47a2ff61476",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/513eed96cabdea495a7141666eb77216dee6f0754ef643917346a47a2ff61476",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha256",
    "value": "834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/834b6e5db5710b9308d0598978a0148a9dc832361f1fa0b7ad4343dcceba2812",
    "campaigns": [
      "fairwords Credential Worm"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "89.36.224.5",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/89.36.224.5",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "datahub.ink",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/datahub.ink",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "cloud-sync.online",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/cloud-sync.online",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "byte-io.us",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/byte-io.us",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "api.ipify.org",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/api.ipify.org",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "ipinfo.io",
    "context": "Legitimate service abused by Epsilon Stealer for victim geolocation (GET /json). Also used for sandbox IP blacklist check.",
    "href": "/ti/ioc/domain/ipinfo.io",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "ipv4",
    "value": "89.36.224.5",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/89.36.224.5",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "ipv4",
    "value": "208.115.220.17",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/208.115.220.17",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha256",
    "value": "0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha256",
    "value": "0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "sha1",
    "value": "dfd224461edb06c556ee0d5677bd78ddda80b910",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/dfd224461edb06c556ee0d5677bd78ddda80b910",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-08"
  },
  {
    "kind": "domain",
    "value": "prod.universitecentrale.net",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/prod.universitecentrale.net",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "domain",
    "value": "urlvoelpilswwxkiosey.supabase.co",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/urlvoelpilswwxkiosey.supabase.co",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "domain",
    "value": "chat.universitecentrale.net",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/chat.universitecentrale.net",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "ipv4",
    "value": "146.0.0.0",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/146.0.0.0",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "333e5b7c412736685b3c296a58663a7763744949",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/333e5b7c412736685b3c296a58663a7763744949",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "4c385d4376314b24793b6b4e3526783f72383667",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/4c385d4376314b24793b6b4e3526783f72383667",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "2a6e3839766d215e40785f6b277dc2a34d4e2f71",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/2a6e3839766d215e40785f6b277dc2a34d4e2f71",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "442158353951337678587c236567276e767a3d39",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/442158353951337678587c236567276e767a3d39",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "3f3922326c646a2d2f78703073224a3e4a366761",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/3f3922326c646a2d2f78703073224a3e4a366761",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "3c335f732e6f5c3b48665745325c572b25724a60",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/3c335f732e6f5c3b48665745325c572b25724a60",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "2968623b3a4c275d544149674522663559617b74",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/2968623b3a4c275d544149674522663559617b74",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "5551307d753c3c5a59333c25525f2f446d2a213e",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/5551307d753c3c5a59333c25525f2f446d2a213e",
    "campaigns": [],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "3d69675671616a6426515e7cc2a32e4ac2a32c33",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/3d69675671616a6426515e7cc2a32e4ac2a32c33",
    "campaigns": [],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "sha1",
    "value": "c2a32a743329604e5633767d4e7e567a48246476",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/c2a32a743329604e5633767d4e7e567a48246476",
    "campaigns": [],
    "discovered_at": "2026-04-06"
  },
  {
    "kind": "domain",
    "value": "admondtamang.com.np",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/admondtamang.com.np",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "domain",
    "value": "gist.github.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/gist.github.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "domain",
    "value": "gist.githubusercontent.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/gist.githubusercontent.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "sha256",
    "value": "40aa5d412a50db79a814ac5ad65237745727cb4777843d66a760f64285a5a3e6",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/40aa5d412a50db79a814ac5ad65237745727cb4777843d66a760f64285a5a3e6",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "sha1",
    "value": "1c5d51c2002f452a4dd58a1a73a9dd90a7fe0297",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/1c5d51c2002f452a4dd58a1a73a9dd90a7fe0297",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "md5",
    "value": "814132e794e5d007e9b8ebd223a9494f",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/814132e794e5d007e9b8ebd223a9494f",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "md5",
    "value": "0c0fc7a0c23cdb5e1c8f66b208053ed6",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/0c0fc7a0c23cdb5e1c8f66b208053ed6",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "ipv4",
    "value": "144.31.107.231",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/144.31.107.231",
    "campaigns": [
      "Strapi Plugin C2 Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "email",
    "value": "w1gtd@sharebot.net",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/w1gtd@sharebot.net",
    "campaigns": [
      "Strapi Plugin C2 Campaign"
    ],
    "discovered_at": "2026-04-03"
  },
  {
    "kind": "domain",
    "value": "jsonkeeper.com",
    "context": "Public JSON paste service used as dead-drop C2. Shared TTP-family with express-session-js (DPRK Contagious Interview / Famous Chollima) — technique-level link, not hard attribution.",
    "href": "/ti/ioc/domain/jsonkeeper.com",
    "campaigns": [
      "No Specific Campaign",
      "emiltype/jsonspack"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "domain",
    "value": "216.126.237.71",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/216.126.237.71",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "ipv4",
    "value": "216.126.237.71",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/216.126.237.71",
    "campaigns": [
      "No Specific Campaign",
      "tanvisoul9 npm Backdoors"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "ipv4",
    "value": "216.126.229.166",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/216.126.229.166",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "ipv4",
    "value": "216.126.227.239",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/216.126.227.239",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "sha256",
    "value": "b5cca27ca1d792bd8c46b83fccfa4e5ba38916eb78877a19cbb39392ce98cc39",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/b5cca27ca1d792bd8c46b83fccfa4e5ba38916eb78877a19cbb39392ce98cc39",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "md5",
    "value": "a36adbc35e69b22acbf9f834a0deb286",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/a36adbc35e69b22acbf9f834a0deb286",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-04-02"
  },
  {
    "kind": "domain",
    "value": "sfrclak.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/sfrclak.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "ipv4",
    "value": "142.11.206.73",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/142.11.206.73",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "sha256",
    "value": "5bb67e88846096f1f8d42a0f0350c9c46260591567612ff9af46f98d1b7571cd",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/5bb67e88846096f1f8d42a0f0350c9c46260591567612ff9af46f98d1b7571cd",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "sha256",
    "value": "59336a964f110c25c112bcc5adca7090296b54ab33fa95c0744b94f8a0d80c0f",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/59336a964f110c25c112bcc5adca7090296b54ab33fa95c0744b94f8a0d80c0f",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "sha256",
    "value": "fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "sha256",
    "value": "e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "email",
    "value": "ifstap@proton.me",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/ifstap@proton.me",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "email",
    "value": "nrwise@proton.me",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/nrwise@proton.me",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-31"
  },
  {
    "kind": "domain",
    "value": "83.142.209.203",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/83.142.209.203",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-27"
  },
  {
    "kind": "ipv4",
    "value": "83.142.209.203",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/83.142.209.203",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-27"
  },
  {
    "kind": "sha256",
    "value": "7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-27"
  },
  {
    "kind": "sha256",
    "value": "cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-27"
  },
  {
    "kind": "domain",
    "value": "models.litellm.cloud",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/models.litellm.cloud",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-24"
  },
  {
    "kind": "domain",
    "value": "checkmarx.zone",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/checkmarx.zone",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-24"
  },
  {
    "kind": "sha256",
    "value": "d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/d2a0d5f564628773b6af7b9c11f6b86531a875bd2d186d7081ab62748a800ebb",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-24"
  },
  {
    "kind": "sha1",
    "value": "9343aeefca37aa49a6ea54397d7615adae5c72c9",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/9343aeefca37aa49a6ea54397d7615adae5c72c9",
    "campaigns": [
      "TeamPCP"
    ],
    "discovered_at": "2026-03-24"
  },
  {
    "kind": "domain",
    "value": "malicanbur.pro",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/malicanbur.pro",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "ipv4",
    "value": "31.220.48.155",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/31.220.48.155",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "ipv4",
    "value": "173.211.46.22",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/173.211.46.22",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "sha256",
    "value": "0be2375362227f846c56c4de2db4d3113e197f0c605c297a7e0e0c154e94464e",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/0be2375362227f846c56c4de2db4d3113e197f0c605c297a7e0e0c154e94464e",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "sha256",
    "value": "5196c3a832897e30c26da768379750bd3c886890e74d0f28a8921bbd19b553fc",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/5196c3a832897e30c26da768379750bd3c886890e74d0f28a8921bbd19b553fc",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "email",
    "value": "jaimeandujo086@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/jaimeandujo086@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-16"
  },
  {
    "kind": "domain",
    "value": "discord.com",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/discord.com",
    "campaigns": [
      "No Specific Campaign",
      "fucktestpad npm Malware"
    ],
    "discovered_at": "2026-03-06"
  },
  {
    "kind": "sha256",
    "value": "3733f0add545e5537a7d3171a132df51e0b4105aebe85db35dbe868a056d3d24",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/3733f0add545e5537a7d3171a132df51e0b4105aebe85db35dbe868a056d3d24",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2026-03-06"
  },
  {
    "kind": "sha256",
    "value": "62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0",
    "campaigns": [
      "Shai-Hulud",
      "miasma-train-p1"
    ],
    "discovered_at": "2025-11-24"
  },
  {
    "kind": "sha256",
    "value": "a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a",
    "campaigns": [
      "Shai-Hulud",
      "miasma-train-p1"
    ],
    "discovered_at": "2025-11-24"
  },
  {
    "kind": "email",
    "value": "jaddyday2@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/jaddyday2@gmail.com",
    "campaigns": [
      "Enterprise Dependency Confusion"
    ],
    "discovered_at": "2025-10-23"
  },
  {
    "kind": "domain",
    "value": "webhook.site",
    "context": "Network indicator from blog post",
    "href": "/ti/ioc/domain/webhook.site",
    "campaigns": [
      "Shai-Hulud",
      "No Specific Campaign"
    ],
    "discovered_at": "2025-09-16"
  },
  {
    "kind": "sha256",
    "value": "bc18414929992e8e8d2211f9c51ebc7241294a1af3cfdbdd5ca417974b2dac0b",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/bc18414929992e8e8d2211f9c51ebc7241294a1af3cfdbdd5ca417974b2dac0b",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2025-09-16"
  },
  {
    "kind": "sha256",
    "value": "46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2025-09-16"
  },
  {
    "kind": "email",
    "value": "scttcper@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/scttcper@gmail.com",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2025-09-16"
  },
  {
    "kind": "email",
    "value": "github_token@github.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/github_token@github.com",
    "campaigns": [
      "Shai-Hulud"
    ],
    "discovered_at": "2025-09-16"
  },
  {
    "kind": "sha1",
    "value": "fc4a4858bafef54d1b1d7697bfb5c52f4c166976",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/fc4a4858bafef54d1b1d7697bfb5c52f4c166976",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "md5",
    "value": "19111111111111111111111111111111",
    "context": "MD5 hash from blog post",
    "href": "/ti/ioc/md5/19111111111111111111111111111111",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x66a9893cC07D91D95644AEDD05D03f95e1dBA8Af",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x66a9893cC07D91D95644AEDD05D03f95e1dBA8Af",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x10ed43c718714eb63d5aa57b78b54704e256024e",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x10ed43c718714eb63d5aa57b78b54704e256024e",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x13f4ea83d0bd40e75c8222255bc855a974568dd4",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x13f4ea83d0bd40e75c8222255bc855a974568dd4",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x1111111254eeb25477b68fb85ed929f73a960582",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x1111111254eeb25477b68fb85ed929f73a960582",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xd9e1ce17f2641f24ae83637ab66a2cca9c378b9f",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xd9e1ce17f2641f24ae83637ab66a2cca9c378b9f",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xfc4a4858bafef54d1b1d7697bfb5c52f4c166976",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xfc4a4858bafef54d1b1d7697bfb5c52f4c166976",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x66a9893cc07d91d95644aedd05d03f95e1dba8af",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x66a9893cc07d91d95644aedd05d03f95e1dba8af",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xFc4a4858bafef54D1b1d7697bfb5c52F4c166976",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xa29eeFb3f21Dc8FA8bce065Db4f4354AA683c024",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xa29eeFb3f21Dc8FA8bce065Db4f4354AA683c024",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x40C351B989113646bc4e9Dfe66AE66D24fE6Da7B",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x40C351B989113646bc4e9Dfe66AE66D24fE6Da7B",
    "campaigns": [
      "qix npm Account Compromise"
    ],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x30F895a2C66030795131FB66CBaD6a1f91461731",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x30F895a2C66030795131FB66CBaD6a1f91461731",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x57394449fE8Ee266Ead880D5588E43501cb84cC7",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x57394449fE8Ee266Ead880D5588E43501cb84cC7",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xCd422cCC9f6e8f30FfD6F68C0710D3a7F24a026A",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xCd422cCC9f6e8f30FfD6F68C0710D3a7F24a026A",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x7C502F253124A88Bbb6a0Ad79D9BeD279d86E8f4",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x7C502F253124A88Bbb6a0Ad79D9BeD279d86E8f4",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xe86749d6728d8b02c1eaF12383c686A8544de26A",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xe86749d6728d8b02c1eaF12383c686A8544de26A",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xa4134741a64F882c751110D3E207C51d38f6c756",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xa4134741a64F882c751110D3E207C51d38f6c756",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xD4A340CeBe238F148034Bbc14478af59b1323d67",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xD4A340CeBe238F148034Bbc14478af59b1323d67",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xB00A433e1A5Fc40D825676e713E5E351416e6C26",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xB00A433e1A5Fc40D825676e713E5E351416e6C26",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xd9Df4e4659B1321259182191B683acc86c577b0f",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xd9Df4e4659B1321259182191B683acc86c577b0f",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x0a765FA154202E2105D7e37946caBB7C2475c76a",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x0a765FA154202E2105D7e37946caBB7C2475c76a",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xE291a6A58259f660E8965C2f0938097030Bf1767",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xE291a6A58259f660E8965C2f0938097030Bf1767",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xe46e68f7856B26af1F9Ba941Bc9cd06F295eb06D",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xe46e68f7856B26af1F9Ba941Bc9cd06F295eb06D",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xa7eec0c4911ff75AEd179c81258a348c40a36e53",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xa7eec0c4911ff75AEd179c81258a348c40a36e53",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x3c6762469ea04c9586907F155A35f648572A0C3E",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x3c6762469ea04c9586907F155A35f648572A0C3E",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x322FE72E1Eb64F6d16E6FCd3d45a376efD4bC6b2",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x322FE72E1Eb64F6d16E6FCd3d45a376efD4bC6b2",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x51Bb31a441531d34210a4B35114D8EF3E57aB727",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x51Bb31a441531d34210a4B35114D8EF3E57aB727",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x314d5070DB6940C8dedf1da4c03501a3AcEE21E1",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x314d5070DB6940C8dedf1da4c03501a3AcEE21E1",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x75023D76D6cBf88ACeAA83447C466A9bBB0c5966",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x75023D76D6cBf88ACeAA83447C466A9bBB0c5966",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x1914F36c62b381856D1F9Dc524f1B167e0798e5E",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x1914F36c62b381856D1F9Dc524f1B167e0798e5E",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xB9e9cfd931647192036197881A9082cD2D83589C",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xB9e9cfd931647192036197881A9082cD2D83589C",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xE88ae1ae3947B6646e2c0b181da75CE3601287A4",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xE88ae1ae3947B6646e2c0b181da75CE3601287A4",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x0D83F2770B5bDC0ccd9F09728B3eBF195cf890e2",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x0D83F2770B5bDC0ccd9F09728B3eBF195cf890e2",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xe2D5C35bf44881E37d7183DA2143Ee5A84Cd4c68",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xe2D5C35bf44881E37d7183DA2143Ee5A84Cd4c68",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xd21E6Dd2Ef006FFAe9Be8d8b0cdf7a667B30806d",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xd21E6Dd2Ef006FFAe9Be8d8b0cdf7a667B30806d",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x93Ff376B931B92aF91241aAf257d708B62D62F4C",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x93Ff376B931B92aF91241aAf257d708B62D62F4C",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x5C068df7139aD2Dedb840ceC95C384F25b443275",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x5C068df7139aD2Dedb840ceC95C384F25b443275",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x70D24a9989D17a537C36f2FB6d8198CC26c1c277",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x70D24a9989D17a537C36f2FB6d8198CC26c1c277",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x0ae487200606DEfdbCEF1A50C003604a36C68E64",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x0ae487200606DEfdbCEF1A50C003604a36C68E64",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xc5588A6DEC3889AAD85b9673621a71fFcf7E6B56",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xc5588A6DEC3889AAD85b9673621a71fFcf7E6B56",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x3c23bA2Db94E6aE11DBf9cD2DA5297A09d7EC673",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x3c23bA2Db94E6aE11DBf9cD2DA5297A09d7EC673",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x5B5cA7d3089D3B3C6393C0B79cDF371Ec93a3fd3",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x5B5cA7d3089D3B3C6393C0B79cDF371Ec93a3fd3",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x4Cb4c0E7057829c378Eb7A9b174B004873b9D769",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x4Cb4c0E7057829c378Eb7A9b174B004873b9D769",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xd299f05D1504D0B98B1D6D3c282412FD4Df96109",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xd299f05D1504D0B98B1D6D3c282412FD4Df96109",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x241689F750fCE4A974C953adBECe0673Dc4956E0",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x241689F750fCE4A974C953adBECe0673Dc4956E0",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xBc5f75053Ae3a8F2B9CF9495845038554dDFb261",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xBc5f75053Ae3a8F2B9CF9495845038554dDFb261",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x5651dbb7838146fCF5135A65005946625A2685c8",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x5651dbb7838146fCF5135A65005946625A2685c8",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x5c9D146b48f664f2bB4796f2Bb0279a6438C38b1",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x5c9D146b48f664f2bB4796f2Bb0279a6438C38b1",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xd2Bf42514d35952Abf2082aAA0ddBBEf65a00BA3",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xd2Bf42514d35952Abf2082aAA0ddBBEf65a00BA3",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xbB1EC85a7d0aa6Cd5ad7E7832F0b4c8659c44cc9",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xbB1EC85a7d0aa6Cd5ad7E7832F0b4c8659c44cc9",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x013285c02ab81246F1D68699613447CE4B2B4ACC",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x013285c02ab81246F1D68699613447CE4B2B4ACC",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x97A00E100BA7bA0a006B2A9A40f6A0d80869Ac9e",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x97A00E100BA7bA0a006B2A9A40f6A0d80869Ac9e",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x4Bf0C0630A562eE973CE964a7d215D98ea115693",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x4Bf0C0630A562eE973CE964a7d215D98ea115693",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x805aa8adb8440aEA21fDc8f2348f8Db99ea86Efb",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x805aa8adb8440aEA21fDc8f2348f8Db99ea86Efb",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xae9935793835D5fCF8660e0D45bA35648e3CD463",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xae9935793835D5fCF8660e0D45bA35648e3CD463",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xB051C0b7dCc22ab6289Adf7a2DcEaA7c35eB3027",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xB051C0b7dCc22ab6289Adf7a2DcEaA7c35eB3027",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xf7a82C48Edf9db4FBe6f10953d4D889A5bA6780D",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xf7a82C48Edf9db4FBe6f10953d4D889A5bA6780D",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x06de68F310a86B10746a4e35cD50a7B7C8663b8d",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x06de68F310a86B10746a4e35cD50a7B7C8663b8d",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x51f3C0fCacF7d042605ABBE0ad61D6fabC4E1F54",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x51f3C0fCacF7d042605ABBE0ad61D6fabC4E1F54",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x49BCc441AEA6Cd7bC5989685C917DC9fb58289Cf",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x49BCc441AEA6Cd7bC5989685C917DC9fb58289Cf",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x7fD999f778c1867eDa9A4026fE7D4BbB33A45272",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x7fD999f778c1867eDa9A4026fE7D4BbB33A45272",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xe8749d2347472AD1547E1c6436F267F0EdD725Cb",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xe8749d2347472AD1547E1c6436F267F0EdD725Cb",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x2B471975ac4E4e29D110e43EBf9fBBc4aEBc8221",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x2B471975ac4E4e29D110e43EBf9fBBc4aEBc8221",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x02004fE6c250F008981d8Fc8F9C408cEfD679Ec3",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x02004fE6c250F008981d8Fc8F9C408cEfD679Ec3",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xC4A51031A7d17bB6D02D52127D2774A942987D39",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xC4A51031A7d17bB6D02D52127D2774A942987D39",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xa1b94fC12c0153D3fb5d60ED500AcEC430259751",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xa1b94fC12c0153D3fb5d60ED500AcEC430259751",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xdedda1A02D79c3ba5fDf28C161382b1A7bA05223",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xdedda1A02D79c3ba5fDf28C161382b1A7bA05223",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xE55f51991C8D01Fb5a99B508CC39B8a04dcF9D04",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xE55f51991C8D01Fb5a99B508CC39B8a04dcF9D04",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0x7a250d5630b4cf539739df2c5dacb4c659f2488d",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0x7a250d5630b4cf539739df2c5dacb4c659f2488d",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "wallet",
    "value": "0xe592427a0aece92de3edee1f18e0157c05861564",
    "context": "Cryptocurrency wallet address from blog post",
    "href": "/ti/ioc/wallet/0xe592427a0aece92de3edee1f18e0157c05861564",
    "campaigns": [],
    "discovered_at": "2025-09-08"
  },
  {
    "kind": "sha256",
    "value": "863d274bbeb22ab969f742a06d89bdf0ababb99fdeb074a0fd9057f28b1ef257",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/863d274bbeb22ab969f742a06d89bdf0ababb99fdeb074a0fd9057f28b1ef257",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-08-12"
  },
  {
    "kind": "sha1",
    "value": "9066ceeb391d9c7ba6aba650109c2fa3f8e088eb",
    "context": "SHA-1/commit-like hash from blog post",
    "href": "/ti/ioc/sha1/9066ceeb391d9c7ba6aba650109c2fa3f8e088eb",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-08-12"
  },
  {
    "kind": "email",
    "value": "graphite7199@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/graphite7199@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-08-12"
  },
  {
    "kind": "email",
    "value": "graphitediscord199@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/graphitediscord199@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-08-12"
  },
  {
    "kind": "sha256",
    "value": "31204fbbc097677d518e1c01d88cf24b491ef29cc8f56d1ef2b81e5ccc8440e2",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/31204fbbc097677d518e1c01d88cf24b491ef29cc8f56d1ef2b81e5ccc8440e2",
    "campaigns": [
      "eslint-config-prettier Compromise"
    ],
    "discovered_at": "2025-07-21"
  },
  {
    "kind": "sha256",
    "value": "c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441",
    "context": "SHA-256 hash from blog post",
    "href": "/ti/ioc/sha256/c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441",
    "campaigns": [
      "eslint-config-prettier Compromise"
    ],
    "discovered_at": "2025-07-21"
  },
  {
    "kind": "ipv4",
    "value": "206.214.129.67",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/206.214.129.67",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-04-23"
  },
  {
    "kind": "ipv4",
    "value": "8.152.163.60",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/8.152.163.60",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2025-04-21"
  },
  {
    "kind": "ipv4",
    "value": "13.60.183.44",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/13.60.183.44",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2024-12-11"
  },
  {
    "kind": "ipv4",
    "value": "13.60.0.0",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/13.60.0.0",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2024-12-11"
  },
  {
    "kind": "ipv4",
    "value": "13.63.255.255",
    "context": "IP address indicator from blog post",
    "href": "/ti/ioc/ipv4/13.63.255.255",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2024-12-11"
  },
  {
    "kind": "email",
    "value": "josh.weavery@gmail.com",
    "context": "Email indicator from blog post",
    "href": "/ti/ioc/email/josh.weavery@gmail.com",
    "campaigns": [
      "No Specific Campaign"
    ],
    "discovered_at": "2024-11-04"
  }
]