RedLine-style infostealer sample flagged by Metascan engines
The Hades campaign against the PyPI registry poisoned 19 packages with a Bun runtime-based credential stealer that executed automatically on installation, marking a shift from Python-native tooling to cross-runtime malware. Infostealers of this kind harvest saved credentials from browsers and applications — the behavior mapped to T1555.003 — then exfiltrate them to attacker infrastructure. This demo shows how MetaDefender Metascan aggregates 30+ anti-malware engines to flag an infostealer-style executable in seconds. For safety, the demo file is the EICAR test file, a benign, industry-standard string used to validate detection without exposing systems to real malware.
Attack Technique
Infostealer family
MITRE ATT&CK
T1555.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗