Date: 08/07/2026
Severity: High
Summary
Analysis revealed 10 NPM packages published from July 18–22, 2026, that download an obfuscated crypto-stealing malware and RAT from a remote server, with the payload concealed inside a JSON object to mask its malicious nature.
Indicators of Compromise (IOC) List
Domains/URLs | https://31.97.137.157:45000 https://46.183.25.232:45000 https://bet.slotgambit.com |
Hash | 6d585d11236277c42bf3666192f89733b1d5595967f6434a2e1b6c9d8584a22c
f591ececf07aedf2f60dc9a362033b6f718799d5909ab38b6941a5296555532b
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://bet.slotgambit.com" or url like "https://bet.slotgambit.com" or siteurl like "https://bet.slotgambit.com" or domainname like "https://31.97.137.157:45000" or url like "https://31.97.137.157:45000" or siteurl like "https://31.97.137.157:45000" or domainname like "https://46.183.25.232:45000" or url like "https://46.183.25.232:45000" |
Detection Query 2 : | sha256hash IN ("6d585d11236277c42bf3666192f89733b1d5595967f6434a2e1b6c9d8584a22c","f591ececf07aedf2f60dc9a362033b6f718799d5909ab38b6941a5296555532b")
|
Reference:
https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-06-Obfuscated-JavaScript-Crypto-Stealer.txt