Obfuscated JavaScript Crypto Stealer is Being Distributed Through New NPM Packages

    Date: 08/07/2026

    Severity: High

    Summary

    Analysis revealed 10 NPM packages published from July 18–22, 2026, that download an obfuscated crypto-stealing malware and RAT from a remote server, with the payload concealed inside a JSON object to mask its malicious nature.

    Indicators of Compromise (IOC) List

    Domains/URLs

    https://31.97.137.157:45000

    https://46.183.25.232:45000

    https://bet.slotgambit.com

    Hash  

    6d585d11236277c42bf3666192f89733b1d5595967f6434a2e1b6c9d8584a22c

    f591ececf07aedf2f60dc9a362033b6f718799d5909ab38b6941a5296555532b

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://bet.slotgambit.com" or url like "https://bet.slotgambit.com" or siteurl like "https://bet.slotgambit.com" or domainname like "https://31.97.137.157:45000" or url like "https://31.97.137.157:45000" or siteurl like "https://31.97.137.157:45000" or domainname like "https://46.183.25.232:45000" or url like "https://46.183.25.232:45000" 

    Detection Query 2 :

    sha256hash IN ("6d585d11236277c42bf3666192f89733b1d5595967f6434a2e1b6c9d8584a22c","f591ececf07aedf2f60dc9a362033b6f718799d5909ab38b6941a5296555532b")

    Reference:    

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-08-06-Obfuscated-JavaScript-Crypto-Stealer.txt                              


    Tags

    MalwareObfuscationNode Package Manager (NPM)RATStealercryptocurrency

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags