Keylogger sample detected by signature-based engines
The July 29 digest detailed how two legitimate joyfill npm packages were trojanized, delivering a remote access trojan that executed the moment developers imported the package into Node.js projects — an attack aimed directly at developer machines and CI/CD pipelines. Keyloggers are among the most common payloads in such trojanized binaries: once running, they hook the keyboard input path to silently capture credentials and sensitive text typed by the victim. Metascan correlates verdicts from 30+ anti-malware engines to catch known keylogger families. For safety, the demo file is the EICAR test file — a benign, industry-standard signature used to verify detection — so no real malware is involved.
Attack Technique
Keylogger family
MITRE ATT&CK
T1056.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗