Skip to main content
← Back to Demos
Malware beginner · 15 min

RedLine-style infostealer sample flagged by Metascan engines

The Hades campaign against the PyPI registry poisoned 19 packages with a Bun runtime-based credential stealer that executed automatically on installation, marking a shift from Python-native tooling to cross-runtime malware. Infostealers of this kind harvest saved credentials from browsers and applications — the behavior mapped to T1555.003 — then exfiltrate them to attacker infrastructure. This demo shows how MetaDefender Metascan aggregates 30+ anti-malware engines to flag an infostealer-style executable in seconds. For safety, the demo file is the EICAR test file, a benign, industry-standard string used to validate detection without exposing systems to real malware.

Attack Technique

Infostealer family

MITRE ATT&CK

T1555.003 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---