[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPZFu-Ia7YwpUrFDbAIovdPqE_bJCb159nvtQMNvGaO8":3},{"article":4,"iocs":37,"watch_terms":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":17,"category":18,"article_tags":21},"2885e35d-68e4-4a89-85b5-b4a5dd75ac59","Inside the sample is another (base64 encoded) PS script that will load the next stage from: https...","inside-the-sample-is-another-base64-encoded-ps-script-that-will-load-the-next-st","Inside the sample is another (base64 encoded) PS script that will load the next stage from: https:\u002F\u002F*.ecs-ent-aff-mgr\\.in.net\u002FJetBrains-91267b64-989f-49b4-89b4-984e0154d4d2\nThat next stage is also a PS script, that is over 14MB in size and obfuscated...\n🤷‍♂️ https:\u002F\u002Ft.co\u002FLesGOu4Eyz https:\u002F\u002Ft.co\u002FInsum8JgFf","A multi-stage malware campaign has been identified using base64-encoded PowerShell scripts that load obfuscated payloads from attacker-controlled infrastructure. The second-stage payload exceeds 14MB and is heavily obfuscated, suggesting sophisticated evasion techniques. The attack vector appears to target development tools or package repositories, potentially affecting supply chain security.","Multi-stage PowerShell malware with base64 encoding and obfuscation detected in supply chain attack.",null,"https:\u002F\u002Fx.com\u002Fmalwrhunterteam\u002Fstatus\u002F2036410316553085114","2026-03-24T11:50:28+00:00","2026-03-24T12:00:14.011354+00:00",7,[],"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":17,"icon":11,"name":19,"slug":20},"Malware","malware",[22,27,32],{"category":23},{"id":24,"icon":11,"name":25,"slug":26},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":28},{"id":29,"icon":11,"name":30,"slug":31},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[38,42,46],{"type":39,"value":40,"context":41},"domain","ecs-ent-aff-mgr.in.net","C2 domain hosting obfuscated second-stage PowerShell payload",{"type":43,"value":44,"context":45},"url","https:\u002F\u002F*.ecs-ent-aff-mgr.in.net\u002FJetBrains-91267b64-989f-49b4-89b4-984e0154d4d2","C2 URL serving second-stage malware payload",{"type":20,"value":47,"context":48},"Multi-stage PowerShell loader (base64-encoded)","Initial stage dropper with embedded second-stage payload URL",[]]