Malware
movinlike
- First Reported
- Sep 30, 2026
- Latest Reported
- Sep 30, 2026
Reported Context (1)
- decrypts an embedded payload using the malfexteam2027 key, and fetches a 64 MB Node.js bundle (movinlike) from 104.234.65.75:700 that injects into Discord clients, harvests browser and Telegram tdata, and MALFEX: Malicious npm Supply-Chain Campaign Went Unadvised for 14 Months
Malware (2)
Threat Actors (1)
MITRE ATT&CK (6)
Vendors (3)
Products (7)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.