├── Blob phishing in the wild: a Nyasher browser relay
A Shared Document lure built a blob page that relayed a remote browser screen and visitor input. I replayed the client locally and traced its code to Nyasher.
read write-up → ├── A Tiny npm Loader With a Much Bigger Payload
A five-stage npm postinstall chain that builds a local Node runtime, disguises an obfuscated implant as a VS Code manifest, and targets credentials, wallets, SSH material, and files.
read write-up → ├── Same Loader, New Front Doors
Tracking a DPRK Contagious Interview npm loader through five delivery methods.
read write-up ↗ ├── npm Malware Cluster Uses Hidden README Payloads to Trigger Credential Theft
A look at an npm package cluster using postinstall, npx, credential scanning, encrypted reporting, AI-agent file propagation, and GitHub-based delivery attempts.
read write-up ↗ ├── How My Homemade NPM Hunter Caught a Mini Shai-Hulud Package
├── 4 Firebase Projects, 410 Reply Addresses, 1 Operator
A reply-harvesting phishing operation, traced from Firebase to a Hetzner VPS in Falkenstein.
read write-up ↗