npm

eyevox

eyevox is identified in the SafeDep analysis "ixpresso-core: Windows RAT Disguised as a WhatsApp Agent". ixpresso-core poses as an AI WhatsApp agent on npm but installs Veltrix, a Windows RAT that steals browser credentials, Discord tokens, and keystrokes via a hardcoded Discord webhook.

discovered 2026-04-16

Threat types

ratcredential_stealerdata_exfiltrationpersistencec2_agent

Malicious versions

  • 2.1.4
  • 2.1.5
  • 2.1.6
  • 2.1.7
  • 2.1.8
  • 2.1.9
  • 2.1.10
  • 2.1.11

Campaigns

Indicators

Techniques

Read the full analysis →