Signature Base unknown stable yara
MAL_JS_NPM_SupplyChain_Compromise_Sep25 [yara]
Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)
Detection Logic
filesize < 20MB
and (
1 of ($x*)
or (
1 of ($sa*)
and 1 of ($sb*)
)
)
and not uint8(0) == 0x7b // JSON { Field Validations
Loading…
Comments (0)
Loading comments...