Signature Base unknown stable yara

MAL_JS_NPM_SupplyChain_Compromise_Sep25 [yara]

Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)

View Source

Detection Logic

filesize < 20MB
      and (
         1 of ($x*)
         or (
            1 of ($sa*)
            and 1 of ($sb*)
         )
      )
      and not uint8(0) == 0x7b  // JSON {

Field Validations

Loading…

Comments (0)

Loading comments...