Skip to main content
← Back to Demos
Malware beginner · 15 min

Keylogger sample detected by signature-based engines

The July 29 digest detailed how two legitimate joyfill npm packages were trojanized, delivering a remote access trojan that executed the moment developers imported the package into Node.js projects — an attack aimed directly at developer machines and CI/CD pipelines. Keyloggers are among the most common payloads in such trojanized binaries: once running, they hook the keyboard input path to silently capture credentials and sensitive text typed by the victim. Metascan correlates verdicts from 30+ anti-malware engines to catch known keylogger families. For safety, the demo file is the EICAR test file — a benign, industry-standard signature used to verify detection — so no real malware is involved.

Attack Technique

Keylogger family

MITRE ATT&CK

T1056.001 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---