Part of the Graphalgo campaign. The module, first published around 2026-08-11, contains a second-stage remote access trojan in plaintext that runs automatically. The RAT collects system information, executes decrypted Go or JavaScript payloads, and polls two command-and-control channels every 3-10 seconds: an Ethereum smart contract used as a dead drop (Arbitrum Sepolia) and a Slack bot token.
{
"iocs": {
"domains": [
"gocommunity.io",
"gogets.dev",
"portfolio-devs.slack.com",
"portfolio-testers.slack.com",
"mediumstar.slack.com"
],
"files": [
{
"digests": {
"sha256": "5f892a5424e88a21a3eb3d7f82ebf04d8ac31cdb19ada25153be4165df977d0f"
},
"paths": [
"import-resource.sqlite3"
]
}
]
}
}