ixpresso-core
ixpresso-core is identified in the SafeDep analysis "ixpresso-core: Windows RAT Disguised as a WhatsApp Agent". ixpresso-core poses as an AI WhatsApp agent on npm but installs Veltrix, a Windows RAT that steals browser credentials, Discord tokens, and keystrokes via a hardcoded Discord webhook.
discovered 2026-04-16
Threat types
ratcredential_stealercrypto_drainerdata_exfiltrationpersistencec2_agent
Malicious versions
- 1.0.0
- 1.0.1
- 1.0.2
Campaigns
Indicators
Techniques
- ttpT1195.001 Supply Chain Compromise: Compromise Software Dependencies and Development Toolsuses
- ttpT1059.007 Command and Scripting Interpreter: JavaScriptuses
- ttpT1552.001 Unsecured Credentials: Credentials In Filesuses
- ttpT1041 Exfiltration Over C2 Channeluses
- ttpT1552.004 Unsecured Credentials: Private Keysuses
- ttpT1528 Steal Application Access Tokenuses
- ttpT1539 Steal Web Session Cookieuses
- ttpT1105 Ingress Tool Transferuses
- ttpT1071.001 Application Layer Protocol: Web Protocolsuses
- ttpT1102 Web Serviceuses
- ttpT1546 Event Triggered Executionuses
