EtherHiding: The trojan in your toolchain

2026-03-31 Cyber Centre

https://cyber.gc.ca/en/news-events/etherhiding-trojan-your-toolchain

Thumbnail for EtherHiding: The trojan in your toolchain

A threat actor inserted a heavily whitespace-padded JavaScript downloader into a Tailwind CSS configuration file in a private GitHub repository, causing it to execute inside developers' Node.js environments. The multistage JADESNOW chain retrieved encrypted payloads through TRON, Aptos, and Binance Smart Chain transactions before installing the InvisibleFerret.JavaScript backdoor in VS Code or Cursor AI. InvisibleFerret established persistence by modifying editor telemetry modules and supported system profiling, arbitrary JavaScript execution, and recursive theft of files and directories. The Cyber Centre published hashes, C2 infrastructure, ATT&CK mappings, and a YARA rule for detecting the obfuscated downloader.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.27.202.27 2025-10-20 2026-07-31
IPv4 136.0.9.8 2025-10-20 2026-04-21
IPv4 166.88.4.2 2025-10-20 2026-04-21
YARA jadesnow_obfuscated_downloader 2026-03-31 2026-03-31
IPv4 23.27.202.143 2026-03-31 2026-03-31
HASH 91822e59bd642f8e6f321011d0fb45b… 2026-03-31 2026-03-31
HASH 7237310e076459d2fce2f531941b592… 2026-03-31 2026-03-31
HASH d043f264ff5216fa724cad2d35ba4d8… 2026-03-31 2026-03-31

Related Reports

« Back