Threat Advisory

Netskope Threat Labs Exposes Malware-as-a-Service NodeJS Infostealer

Threat: Malware
Threat Actor Name: TroysDen
Threat Actor Type: Financially Motivated
Targeted Region: Global
Targeted Sector: Technology & IT, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

A malware campaign is targeting AI developers and software engineers through trojanized GitHub repositories impersonating popular AI tools and developer resources. Attackers clone legitimate repositories, modify installation instructions or embed malicious payloads, and deliver a multi-stage SmartLoader infection chain that ultimately installs credential-stealing malware. The campaign leverages EtherHiding, resolving command-and-control (C2) infrastructure from the Polygon blockchain at runtime, enabling attackers to dynamically update C2 servers while evading traditional detection methods. The activity primarily targets organizations in the financial services, banking, and technology sectors.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

### Summary

A malware campaign is targeting AI developers and software engineers through trojanized GitHub repositories impersonating popular AI tools and developer resources. Attackers clone legitimate repositories, modify installation instructions or embed malicious payloads, and deliver a multi-stage SmartLoader infection chain that ultimately installs credential-stealing malware. The campaign leverages EtherHiding, resolving command-and-control (C2) infrastructure from the Polygon blockchain at runtime, enabling attackers to dynamically update C2 servers while evading traditional detection methods. The activity primarily targets organizations in the financial services, banking, and technology sectors.[emaillocker id="1283"]

The attack begins with fake repositories for tools such as Claude, ComfyUI, AI coding assistants, Python security guides, and Rust frameworks. Victims download a ZIP archive containing obfuscated Lua scripts executed through SmartLoader, which performs reconnaissance, geolocation checks, and blockchain-based C2 resolution before retrieving additional payloads. The final stage deploys NodeJS-based infostealers designed to steal browser credentials, cloud API keys, authentication tokens, and other sensitive developer assets.

Successful compromise of developer workstations could lead to credential theft, unauthorized access to cloud environments, CI/CD pipelines, and software repositories, creating opportunities for downstream supply chain attacks. Organizations should verify the authenticity of GitHub repositories before downloading developer tools, enforce least-privilege access, monitor for suspicious installation scripts, and rotate exposed credentials and API keys if compromise is suspected.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195 Supply Chain Compromise -
Initial access T1566.003 Phishing Spearphishing via Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1571 Non Standard Port-
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis B0032 Executable Code Obfuscation
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Execution E1204 User Execution
Discovery E1082 System Information Discovery
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Exfiltration E1020 Automated Exfiltration

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu