{
  "Event": {
    "analysis": "1",
    "date": "2026-06-23",
    "extends_uuid": "",
    "info": "[Threat Intel] Artifact scanner detects npm package 'node-fetch-utils' using external dependency resolution with remote tarball dependency from GitHub",
    "protected": false,
    "publish_timestamp": "1782454636",
    "published": true,
    "threat_level_id": "2",
    "timestamp": "1782454636",
    "uuid": "2c5fd967-53f0-4a6b-9a82-f5200f036944",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#d3f567",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"JavaScript - T1059.007\"",
        "relationship_type": ""
      },
      {
        "colour": "#7da4ad",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Match Legitimate Resource Name or Location - T1036.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#256f6a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"DLL - T1574.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#43c8db",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Process Injection - T1055\"",
        "relationship_type": ""
      },
      {
        "colour": "#b76d96",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Registry Run Keys / Startup Folder - T1547.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#d596aa",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Compromise Software Supply Chain - T1195.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Hidden Window - T1564.003\"",
        "relationship_type": ""
      },
      {
        "colour": "#30cc3b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"File Deletion - T1070.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#98f3da",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Visual Basic - T1059.005\"",
        "relationship_type": ""
      },
      {
        "colour": "#4c0fbb",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Ingress Tool Transfer - T1105\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005e",
        "local": false,
        "name": "rectifyq:topic=\"supply-chain\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782270026",
        "to_ids": false,
        "type": "link",
        "uuid": "17d22bfe-8295-4e73-a2c1-416d9dc9d66e",
        "value": "https://x.com/nextronresearch/status/2068958596646265033",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782270026",
        "to_ids": false,
        "type": "text",
        "uuid": "979dca4a-e512-4412-b792-1754aa22f1f2",
        "value": "A malicious npm package named 'node-fetch-utils' was discovered masquerading as a legitimate fetch helper utility. The package declares a remote tarball dependency from GitHub that executes upon installation. It runs an obfuscated postinstall script targeting Windows systems, which downloads a bundled Python runtime and drops it as Microsoft\\EdgeBroker\\pythonw.exe for persistence. The dropper then uses this disguised runtime to execute a fileless Python implant decrypted in memory and launched hidden via wscript. The dropper scripts self-delete while the disguised runtime remains active on the compromised system, establishing command and control communications."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782270026",
        "to_ids": false,
        "type": "text",
        "uuid": "0fbaafc6-0401-4411-a922-3293635ece2a",
        "value": "Name: Artifact scanner detects npm package 'node-fetch-utils' using external dependency resolution with remote tarball dependency from GitHub\nAuthor: AlienVault\nAdversary: \nTags: [\"python implant\", \"obfuscated script\", \"node-fetch-utils\", \"javascript dropper\", \"dependency confusion\", \"supply chain attack\", \"node-fetch-core\", \"npm\", \"persistence\", \"fileless malware\"]\nTgtd countries: []\nMlwr families: [\"node-fetch-utils\", \"node-fetch-core\"]\nAttack_ids: [\"T1059.007\", \"T1036.005\", \"T1574.001\", \"T1140\", \"T1055\", \"T1547.001\", \"T1027\", \"T1195.002\", \"T1564.003\", \"T1070.004\", \"T1071.001\", \"T1059.005\", \"T1105\"]\nIndustries: []"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782447657",
        "to_ids": true,
        "type": "url",
        "uuid": "de2a4f19-d1dc-42cc-83e8-411040cf0df6",
        "value": "http://node22.lunes.host:3258",
        "Tag": [
          {
            "colour": "#f08989",
            "local": false,
            "name": "NotFoundError",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "C2",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782447678",
        "to_ids": true,
        "type": "hostname",
        "uuid": "08249894-3235-4920-92ef-b95d4ef6539d",
        "value": "node22.lunes.host",
        "Tag": [
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ],
    "Object": [
      {
        "comment": "",
        "deleted": false,
        "description": "File object describing a file with meta-information",
        "meta-category": "file",
        "name": "file",
        "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
        "template_version": "25",
        "timestamp": "1782447699",
        "uuid": "d70ed7ac-45c8-44ec-9a4e-171c822de658",
        "Attribute": [
          {
            "category": "Payload delivery",
            "comment": "2nd-stage JS",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "md5",
            "timestamp": "1782447699",
            "to_ids": true,
            "type": "md5",
            "uuid": "d413a2cf-1825-465e-b6a2-93f9fe485a22",
            "value": "7bd07e4d557852446a284d038fa0ed0e",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              },
              {
                "colour": "#342294",
                "local": false,
                "name": "CommentAdded",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "2nd-stage JS",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha1",
            "timestamp": "1782445648",
            "to_ids": true,
            "type": "sha1",
            "uuid": "a3a59561-21ac-4ea3-8045-c3bc5573a89d",
            "value": "191f6b9a3bc7f0f01c6aaae6485b7bf85e6c12f4",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "2nd-stage JS",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "sha256",
            "timestamp": "1782445648",
            "to_ids": true,
            "type": "sha256",
            "uuid": "8a3fd81f-a44b-40e6-b3a0-cd56012dbae6",
            "value": "4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affe",
            "Tag": [
              {
                "colour": "#260091",
                "local": false,
                "name": "rectifyq:ioc=\"enriched\"",
                "relationship_type": ""
              },
              {
                "colour": "#220085",
                "local": false,
                "name": "rectifyq:samples-found-in=\"VirusTotal\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
                "relationship_type": ""
              },
              {
                "colour": "#626567",
                "local": false,
                "name": "rectifyq:no-samples-in=\"Tria.ge\"",
                "relationship_type": ""
              }
            ]
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "ssdeep",
            "timestamp": "1782445382",
            "to_ids": true,
            "type": "ssdeep",
            "uuid": "8a53a663-3d7b-479b-8f7b-fb6745bba739",
            "value": "96:hHq3ZJ9DvVc4qjMPyI8vNXF9yZtBR+Yr3KLr6SVMSaL:gn9DvVc4qQKIoNXmZtH+Yr3KLvV5aL"
          },
          {
            "category": "Other",
            "comment": "",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "size-in-bytes",
            "timestamp": "1782445382",
            "to_ids": false,
            "type": "size-in-bytes",
            "uuid": "9de54851-fc89-4376-bda6-161b0292606d",
            "value": "4218"
          },
          {
            "category": "Payload delivery",
            "comment": "",
            "deleted": false,
            "disable_correlation": false,
            "object_relation": "vhash",
            "timestamp": "1782445382",
            "to_ids": true,
            "type": "vhash",
            "uuid": "b5749a8d-abeb-4fb9-b1cb-3b4b70da8a4c",
            "value": "8c3d2877779681310df0d0a4d17d33bc"
          },
          {
            "category": "Other",
            "comment": "Checked: 26/06/2026\nLast-scan\t:  25/06/2026",
            "deleted": false,
            "disable_correlation": true,
            "object_relation": "text",
            "timestamp": "1782445382",
            "to_ids": false,
            "type": "text",
            "uuid": "36fb7a5b-4450-4d54-9cae-b4c6c88ecbb9",
            "value": "2nd-stage JS\r\nType Description: JavaScript\nMicrosoft: Trojan:Script/Wacatac.C!ml\nVT Total Detection:5/61\nFirst Submission:2026-06-22T06:36:09.000000+00:00\nLast Submission:2026-06-22T06:36:09.000000+00:00"
          }
        ]
      }
    ]
  }
}