Across this campaign, the threat actor shows an understanding of developer behavior and exploits the current hype of AI coding platforms. These attack patterns are highly likely targets the developers and IT administrators. By impersonating brands embedded in routine developer workflows, including Node.js, Chocolatey, and KeePassXC, the actor weaponized familiar installation patterns to deliver infostealer malware. This approach target trust in developer tooling, turning routine software adoption into an initial access vector.
https://cdn.fosstodon.org/media_attachments/files/116/646/978/052/928/854/original/8e6a45e600ab8ee0.png