EtherHiding: The trojan in your toolchain
2026-03-31 • Cyber Centre •
https://cyber.gc.ca/en/news-events/etherhiding-trojan-your-toolchain
A threat actor inserted a heavily whitespace-padded JavaScript downloader into a Tailwind CSS configuration file in a private GitHub repository, causing it to execute inside developers' Node.js environments. The multistage JADESNOW chain retrieved encrypted payloads through TRON, Aptos, and Binance Smart Chain transactions before installing the InvisibleFerret.JavaScript backdoor in VS Code or Cursor AI. InvisibleFerret established persistence by modifying editor telemetry modules and supported system profiling, arbitrary JavaScript execution, and recursive theft of files and directories. The Cyber Centre published hashes, C2 infrastructure, ATT&CK mappings, and a YARA rule for detecting the obfuscated downloader.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.27.202.27 | 2025-10-20 | 2026-07-31 |
| IPv4 | 136.0.9.8 | 2025-10-20 | 2026-04-21 |
| IPv4 | 166.88.4.2 | 2025-10-20 | 2026-04-21 |
| YARA | jadesnow_obfuscated_downloader | 2026-03-31 | 2026-03-31 |
| IPv4 | 23.27.202.143 | 2026-03-31 | 2026-03-31 |
| HASH | 91822e59bd642f8e6f321011d0fb45b… | 2026-03-31 | 2026-03-31 |
| HASH | 7237310e076459d2fce2f531941b592… | 2026-03-31 | 2026-03-31 |
| HASH | d043f264ff5216fa724cad2d35ba4d8… | 2026-03-31 | 2026-03-31 |