Huntbase Hub · All hunts

Threat hunts for npm

4 hunts covering npm, each with a hypothesis, the queries that test it and what the hunt cannot see.

4 hunts

  1. high Part 2 of 2
    Research by Cisco Talos

    Obfuscated Phishing and Exfiltration in Node Environments

    An adversary has deployed an obfuscated phishing kit on an asset with developer tools like npm, using encoded HTTP query parameters to exfiltrate stolen credentials and session cookies to rare or known-malicious domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  2. high Part 1 of 2
    Research by Cisco Talos

    Obfuscated JavaScript and Local Collection

    An intruder is using obfuscated JavaScript within npm install scripts or malicious browser extensions to collect credentials and cookies from the local endpoint while evading static analysis.

    5 query2 analytic1 checkpoint1 action2 task
    collection · defense evasion · execution
  3. high Part 2 of 2
    Research by Elastic Security Labs

    CHAINDROP: C2 Discovery and Worm Propagation

    An attacker has infected local development environments via trojanized npm packages and is using Ethereum smart contracts to discover C2 infrastructure before propagating the worm using stolen GitHub credentials.

    4 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  4. high Part 1 of 2
    Research by Elastic Security Labs

    CHAINDROP: Host-Based Node.js Worm Execution and Harvesting

    An attacker has gained initial access through a backdoored npm package preinstall hook, which executes a dropper to install a rogue Bun runtime and harvest developer credentials from local IDE configurations.

    3 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution