# Copyright (c) 2014-2026 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Aliases: shai-hulud, phantomraven, miasmarat

# Reference: https://www.reversinglabs.com/blog/operation-brainleeches-malicious-npm-packages-fuel-supply-chain-and-phishing-attacks

http://137.184.153.238
137.184.153.238:443
brainleeches.xyz
ourwhite.brainleeches.xyz

# Reference: https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys
# Reference: https://blog.phylum.io/sensitive-data-exfiltration-campaign-targets-npm-and-pypi/

threatest.com
app.threatest.com
down.threatest.com
cjq18vv2vtc0000pszdggkb7ssayyyyyd.oast.fun

# Reference: https://blog.phylum.io/persistent-npm-campaign-shipping-trojanized-jquery/

addpack.newrxl.online
ajax.failexpect.biz.id
anti-spam.truex.biz.id
api-bo.my.id
api-system.engineer
api-web-vrip.hanznesia.my.id
api.codatuys.biz.id
api.iimg.my.id
api.jstyy.xyz
api.newrxl.online
apii-pandawara.ganznesia.my.id
apii.codatuys.cab
apii.fukaes.ninja
apiiiwebterbaru2024.duckdns.org
apiweb.eventtss.my.id
codatuys.cab
cssimage.dimashost.xyz
dana-dompet-digital.qxue.biz.id
danu.eventtss.my.id
denii.biz.id
dimashost.xyz
ditzzultimate.xyz
dmdpanel.my.id
eventtss.my.id
failexpect.biz.id
fukaes.ninja
ganznesia.my.id
icikipoxx.pw
iimg.my.id
irisainginbos.icikipoxx.pw
jqbzu-18.cfd
jstyy.xyz
klikmelanjutkan-klik.sahdk.my.id
lngss.my.id
lnpss.my.id
log.api-system.engineer
log.systems-alexhost.xyz
nd.api-system.engineer
newrxl.online
newww.my.id
ns.api-system.engineer
panel-host.clannesia.com
panel-host.dmdpanel.my.id
panel.api-bo.my.id
paneljs.dimashost.xyz
paneljs.hanznesia.my.id
patipride.icikipoxx.pw
pokemon.denii.biz.id
project.systemgoods.me
pukil.dannew.biz.id
qxue.biz.id
sahdk.my.id
saystem.ditzzultimate.xyz
system-alexhosting.biz.id
systemgoods.me
systemport.duckdns.org
systems-alexhost.xyz
terbarucuy.terbaruxx.my.id
terbaruxx.biz.id
terbaruxx.cafegt.my.id
terbaruxx.hydickyy.my.id
terbaruxx.iwvx77.cfd
terbaruxx.jqbzu-18.cfd
terbaruxx.lngss.my.id
terbaruxx.lnpss.my.id
terbaruxx.my.id
terbaruxx.newww.my.id
terbaruxx.newxxx.online
terbaruxx.x-vip.my.id
truex.biz.id

# Reference: https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell

5.199.166.1:31337

# Reference: https://www.sonatype.com/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers

eoi2ectd5a5tn1h.m.pipedream.net

# Reference: https://x.com/BleepinComputer/status/1914723629192847406
# Reference: https://x.com/ValidinLLC/status/1914759729722622340
# Reference: https://app.validin.com/detail?find=297eeccac7d5e089db1af9bd2862fe9c3d81a742&type=hash&ref_id=77c4dbed5fc#tab=host_pairs

0x9c.xyz
npmjr.com

# Reference: https://socket.dev/blog/malicious-npm-packages-hijack-cursor-editor-on-macos

aiide.xyz
api.aiide.xyz
cursor.sw2031.com
t.sw2031.com

# Reference: https://www.aikido.dev/blog/catching-a-rat-remote-access-trojian-rand-user-agent-supply-chain-compromise
# Reference: https://app.validin.com/detail?find=f501e29ccf5831a92111&type=hash&ref_id=44e8bf21260#tab=host_pairs (# 2025-05-24)
# Reference: https://www.virustotal.com/gui/file/236ff897dee7d21319482cd67815bd22391523e37e0452fa230813b30884a86f/detection

23.27.20.143:27017
85.239.62.36:27017
85.239.62.36:3306

# Reference: https://x.com/malwrhunterteam/status/2015776569986310310
# Reference: https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem

136.0.9.8:27017
136.0.9.8:3306
136.0.9.8:443

# Reference: https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages

webhook.site/bb8ca5f6-4175-45d2-b042-fc9ebb8170b7

# Reference: https://socket.dev/blog/malicious-fezbox-npm-package-steals-browser-passwords-from-cookies-via-innovative-qr-code
# Reference: https://intel.breakglass.tech/post/fezbox-npm-supply-chain-qr-steganography-operator-self-doxx-nanjing

http://1.94.210.59
http://183.210.123.88
1.94.210.59:8080
183.210.123.88:443
my-nest-app-production.up.railway.app
res.cloudinary.com/dhuenbqsq/image/upload/v1755767716/b52c81c176720f07f702218b1bdc7eff_h7f6pn.jpg

# Reference: https://socket.dev/blog/10-npm-typosquatted-packages-deploy-credential-harvester
# Reference: https://www.virustotal.com/gui/file/80552ce00e5d271da870e96207541a4f82a782e7b7f4690baeca5d411ed71edb/detection

http://195.133.79.43
195.133.79.43:8080

# Reference: https://unit42.paloaltonetworks.com/npm-supply-chain-attack/ (# shai-hulud)

webhook.site/bb8ca5f6-4175-45d2-b042-fc9ebb8170b7

# Reference: https://x.com/marius_benthin/status/2020806955804098628

ext-checkdin.vercel.app

# Reference: https://socket.dev/blog/malicious-dydx-packages-published-to-npm-and-pypi

priceoracle.site
dydx.priceoracle.site

# Reference: https://x.com/marius_benthin/status/2023699199821304045

storeartifacts.com
package.storeartifacts.com

# Reference: https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies

storeartifact.com
packages.storeartifact.com

# Reference: https://x.com/marius_benthin/status/2011354562494345218

jpartifacts.com
npm.jpartifacts.com

# Reference: https://www.esentire.com/blog/north-korean-apt-malware-analysis-dev-popper-rat-and-omnistealer-everyday-im-shufflin

177.243.216.132:27017

# Reference: https://youtu.be/NCl8kSbac-Y?t=2240

185.183.106.85:43662

# Reference: https://youtu.be/NCl8kSbac-Y?t=2506
# Reference: https://www.virustotal.com/gui/ip-address/144.126.214.174/relations

tradeeno.com
admin.tradeeno.com
api.tradeeno.com
gfrja.mongodb.net
cluster0.gfrja.mongodb.net

# Reference: https://youtu.be/NCl8kSbac-Y?t=2521
# BANNER_0_HASH-HOST=477f1899900e9977482e981e7522c98c
# ETAG-HOST=W/"69744288-264"

asdf11.xyz
lll.taxi
mashhad.app
myaunet.su

# Reference: https://threatbook.io/blog/lazarus-group-poisons-axios-inside-the-npm-supply-chain-attack

142.11.196.73:8080
142.11.199.73:8080

# Reference: https://opensourcemalware.com/npm/chai-extensions-extras

server-check-genimi.vercel.app

# Reference: https://opensourcemalware.com/npm/chai-as-chain-v2

jsonkeeper.com/b/FAWPU

# Reference: https://x.com/npm_malware/status/2039447751214395503

jsonkeeper.com/b/YY8VI

# Reference: https://x.com/abh1sek/status/2041160413778460947

jsonkeeper.com/b/XB9WY

# Reference: https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/

144.31.107.231:8181
144.31.107.231:8888
144.31.107.231:9999

# Reference: https://x.com/marius_benthin/status/2041951353233145912

213.186.33.5:14444
83.168.95.79:14444
grimgg.pl

# Reference: https://socket.dev/blog/namastex-npm-packages-compromised-canisterworm

api-monitor.com
telemetry.api-monitor.com
cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io

# Reference: https://x.com/npm_malware/status/2046952330084687973
# Reference: https://socket.dev/npm/package/@zohodesk/react-cli/files/1.1.18/lib/utils/dependencyPostPublish.js

tsi-desk-mock.tsi.zohocorpin.com

# Reference: https://x.com/npm_malware/status/2047405340254421279
# Reference: https://socket.dev/npm/package/snapchat-followers-free-membership761/files/1.0.2/package%20gene.py
# wordpres_user = khalidirrajy@gmail.com

fundacionsuma.org/wp-admin/post.php
hiromi-haneda.com/wp-admin/post.php
journaldogs.com/wp-admin/post.php

# Reference: https://x.com/npm_malware/status/2047770322938835364
# Reference: https://socket.dev/npm/package/ikyy/files/4.0.6/lib/buathtml.js

sl.rzkyfdlh.tech

# Reference: https://x.com/npm_malware/status/2048145137986138186
# Reference: https://socket.dev/npm/package/apple-psh/files/4.0.3/index.js

54.173.15.59:8080

# Reference: https://x.com/npm_malware/status/2048311208928026761
# Reference: https://socket.dev/npm/package/@gbrlxvii/ts-env-validator/files/1.0.5/postinstall.js

aaronstack.com

# Reference: https://socket.dev/blog/tanstack-brandsquat-compromise

api.svix.com/ingest/api/v1/source/src_3387PLMB2uhXOBe3Q8sHu/in/3j2jokvbaF4WWdngv8zBbk

# Reference: https://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise

domainzero.masscan.cloud
zero.masscan.cloud

# Reference: https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack

filev2.getsession.org
seed1.getsession.org
seed2.getsession.org

# Reference: https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack

37.16.75.69:443
37.16.75.69:53
azurestaticprovider.net
sh.azurestaticprovider.net

# Reference: https://x.com/TekDefense/status/2054963016039342549
# Reference: https://socket.dev/blog/node-ipc-package-compromised

atlantis-software.net

# Reference: https://x.com/MosheTov/status/2055763192064725428
# Reference: https://x.com/TekDefense/status/2055818318209020115
# Reference: https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/

80.200.28.28:2222
87e0bbc636999b.lhr.life
b94b6bcfa27554.lhr.life
bbc45e9f547785.lhr.life
edcf8b03c84634.lhr.life

# Reference: https://socket.dev/blog/antv-packages-compromised
# Reference: https://github.com/nrwl/nx-console/issues/3139
# Reference: https://www.virustotal.com/gui/ip-address/185.95.159.32/relations
# FAVICON_HASH-HOST=39d1ecd455dec00203608a6f11603658
# LOCATION-HOST=https://www.youtube.com/watch?v=-az2KeSBwfQ

indi23.com
m-kosche.com
ngeshorts.fun
omeglebang.xyz
primul-ziar.com
primulziar.com
t.m-kosche.com
# fulcio.sigstore.dev
# rekor.sigstore.dev
slsa-framework.github.io

# Reference: https://x.com/tuckner/status/2056826907421823231
# Reference: https://x.com/tuckner/status/2057078903663993343

karasb.com/api/v1/release

# Reference: https://x.com/abh1sek/status/2057104532451307987
# Reference: https://github.com/goofychris/art-template/issues/665

youzzjizz.com
git.youzzjizz.com
v3.jiathis.com/code/

# Reference: https://socket.dev/blog/malicious-postinstall-hook-found-across-700-github-repos

/parikhpreyash4/systemd-network-helper-aa5c751f/
/parikhpreyash4/
/systemd-network-helper-aa5c751f/

# Reference: https://socket.dev/blog/laravel-lang-compromise
# Reference: https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer

flipboxstudio.info

# Reference: https://x.com/abh1sek/status/2058885937149759960

violet-tricky-quelea-562.mypinata.cloud

# Reference: https://x.com/TekDefense/status/2059326344144830519
# Reference: https://sandyclaw.permiso.io/shared/TjuubIDEi4-0jMKA0VNdC8jU-0gp7cCQSs6ce-FItkI#network-activity
# Reference: https://sandyclaw.permiso.io/shared/pTo9oJ24gF7lcF3veq6mFRct3a_7Mfubl4L1VWRE3qE#network-activity

18.208.244.120:9999

# Reference: https://x.com/safedepio/status/2059386595317317964
# Reference: https://safedep.io/malicious-forge-jsx-npm-rat/

204.10.194.247:3000
204.10.194.247:8765
204.10.194.247:9000
204.10.194.247:9877

# Reference: https://x.com/safedepio/status/2059618763797110846
# Reference: https://github.com/friuns2/codex-mobile/issues/198

anyclaw.store
sentry.anyclaw.store

# Reference: https://x.com/KirkDerpca/status/2061111487607848977

128.199.50.160:3000
128.199.50.160:5000
128.199.50.160:8888
128.199.50.160:8899

# Reference: https://safedep.io/malicious-npm-terminal3airport-proxy-adware-spam/

1baseballacademy.com
abdct.com
cdn.21baseballacademy.com
woofbeginner.com

# Reference: https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/

moika.tech
t-in-one.io
docs.t-in-one.io
npm.t-in-one.io
oob.moika.tech

# Reference: https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack-spreads-like-worm

/liuende501

# Reference: https://x.com/KirkDerpca/status/2062560775844085828
# Reference: https://sandyclaw.permiso.io/shared/LbtOhteft_qJlU1Xf1aSNVlDKby8rjrwWN0sg5jw2YA

w74ghp3dc2o7gmsqrl4b6itmvd14vslga.oastify.com
housecall-ui.w74ghp3dc2o7gmsqrl4b6itmvd14vslga.oastify.com

# Reference: https://x.com/KirkDerpca/status/2062556551898886234
# Reference: https://sandyclaw.permiso.io/packages/cde215b6-baa0-492f-be6c-53e0cd3db4ae
# Reference: https://sandyclaw.permiso.io/packages/6d244ce0-bd78-41e9-9dad-ec1028fcafd2
# Reference: https://sandyclaw.permiso.io/packages/d1941f7c-034a-484e-812a-818681abbd3f

46.224.67.169:3000
46.224.67.169:4000
46.224.67.169:8080
46.224.67.169:8081
46.224.67.169:8082

# Reference: https://x.com/KirkDerpca/status/2062588370925269071
# Reference: https://sandyclaw.permiso.io/shared/NoxCO0i_JjcbyqXm4cMRMZ5RnAqTPtIWovBtPE5e1ag

kpfdtycruuyszysbsjtoj9al6djfqrtve.oast.fun

# Reference: https://x.com/KirkDerpca/status/2062690292608782530

http://213.218.160.189
213.218.160.189:8080

# Reference: https://x.com/KirkDerpca/status/2063226652784460250

g1i0b9xx6mira6mal5yv02n6pxvouck09.oastify.com
iug24bqzzobt38fce7rxt4g8izoqmed22.oastify.com

# Reference: https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-worms-target-bioinformatics-and-mcp-developers-via-malicious

/thebeautifulmarchoftime
/thebeautifulsnadsoftime

# Reference: https://x.com/KirkDerpca/status/2065225499643654213

154.57.164.71:30782

# Reference: https://x.com/nextronresearch/status/2066474280087384217
# Reference: https://www.virustotal.com/gui/file/22480680a22ba444a3924f906cbec947d11f011200b89ef6b67afd48b4c71d77/detection
# Reference: https://www.virustotal.com/gui/file/cc5c72e90d7eda42e66a54c0197abbba1951561d3d864963b6aca7fe43a0ab06/detection
# Reference: https://www.virustotal.com/gui/file/d8f8c416ebde7d90088d6029a5b9b88a2a021bf3b99896f205d78732d376ef5e/detection
# Reference: https://www.virustotal.com/gui/file/e76741a1747dde6b4e4dbc88ca16fc8eb59385b6b18f6c64d1b397dfe0843647/detection

194.11.226.41:4000

# Reference: https://x.com/abh1sek/status/2068329349003292698

webhook.site/#!/view/22e20640-e2a1-4bb2-b203-061077d055ff/

# Reference: https://x.com/nextronresearch/status/2068958596646265033
# Reference: https://www.virustotal.com/gui/file/4ce45e016a304d813e67b29a08265b2101c2e15a09ace5de6539cad02567affe/detection

23.27.249.58:3258
node22.lunes.host

# Reference: https://x.com/nextronresearch/status/2069046332132561335
# Reference: https://www.virustotal.com/gui/file/63bcea329041f266c2664c59944fd6c10d4604af9c81393f7679cb9b7403e22d/detection
# CLASS_0_HASH-HOST/IP=7821f3ae28d83fcdf36c1b47f4255f2b

richardjini.com
safdadfasf.com

# Reference: https://blog.trailofbits.com/2026/06/03/the-sorry-state-of-skill-distribution/

internal-artifacts.corp.dev
npm.internal-artifacts.corp.dev

# Reference: https://www.ox.security/blog/alright-lets-see-if-this-works-shai-hulud-miasma-hades-variant-spreads-on-npm/

/l3v1cs/Html-Bootstrap-TinDog/

# Reference: https://x.com/marsomx_/status/2070409152040403227
# Reference: https://x.com/marsomx_/status/2070461846423826792
# Reference: https://x.com/nullableVoidPtr/status/2070435397436596352
# Reference: https://gist.github.com/danslo/0b26f6d197c2d7a5de426f3e31adceca
# Reference: https://gist.github.com/danslo/4383aa7438957d69876f4ab004c43847
# Reference: https://gist.github.com/danslo/4646133a7185a5f36ae7f3ec2b5dbd5b
# Reference: https://gist.github.com/danslo/ba62cf6a571aee1aa4ba27bd809f815d

http://89.106.74.19
89.106.74.19:7671
89.106.74.19:7676
89.106.74.19:7679

# Reference: https://x.com/MosheTov/status/2073754781500215650
# Reference: https://www.ox.security/blog/malware-detected-reverse-shell-without-javascript-files-in-npm/

185.112.147.174:2222
185.112.147.174:7007
185.112.147.174:9000

# Reference: https://www.ox.security/blog/malware-slop-crypto-stealer-impersonating-polymarket-exposes-its-own-credentials/
# BANNER_0_HASH-HOST=0b22e0f087e4b61d55b3b3ca44a1c67b

23.27.180.36:3000
rocksy.shop
svganchordev.net
a7.svganchordev.net

# Reference: https://x.com/abh1sek/status/2076948658986398021
# Reference: https://x.com/abh1sek/status/2076955904214483093
# Reference: https://github.com/asyncapi/generator/issues/2184
# Reference: https://safedep.io/asyncapi-generator-supply-chain-attack-miasma-rat/

85.137.53.71:8080
85.137.53.71:8081
85.137.53.71:8091

# Reference: https://x.com/nextronresearch/status/2077745652092510247

bax.h4x.tv
nordhax.dd.h4x.tv
