PULSE NAME
IOC - Attackers adopt JavaScript runtime Bun to spread NWHStealer
WHITE celestre 2026-05-08 Modified: 2026-05-08
18
IOCs
MEDIUM VOLUME
In our previous research, we analyzed a Windows infostealer we track as NWHStealer. The attackers behind this stealer are continuously finding new methods to distribute the stealer. During our hunting activities, we noticed how attackers are using a JavaScript runtime called Bun to help distribute it. Bun is a legitimate, fast, all-in-one JavaScript and TypeScript toolkit designed as a modern, high-performance replacement for Node.js. It is built from the ground up to simplify modern web development by integrating several essential tools into a single executable.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
Bun Loader NWH
Indicators of Compromise (18)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0020999b2e3e4d1b2cfb69e4df9440d3ce05d508573889fdc12b724ce75a0cd8 2026-05-08
FileHash-SHA256 021838f30a43026084978bce187c165c6b640d8d474ec009d48078d21ec62025 2026-05-08
FileHash-SHA256 0614c4cc6375ab6bdcdd2dfa913a67d32c3e8be9b95a4a2aa09bb131b98191c8 2026-05-08
FileHash-SHA256 0fa42df08cc467ec52b2d388b5575114a8ec067d13f6b1a653ec33fe879f88ca 2026-05-08
FileHash-SHA256 15f79980650393d182f81cd6e389210568aa1f5f875e515efe6cb9485d64b7fb 2026-05-08
FileHash-SHA256 20454ba58d509300fd694ae6159db4efa1b7ff965f98c29e7d087e20f96578c1 2026-05-08
FileHash-SHA256 308da9f49ffa1d1744e428b567792ab22712159974e9da8d8e0414ecd81de93e 2026-05-08
FileHash-SHA256 33d07aa24b217f27df6a483295c817da198e12511a6989bcc6b917feaf8e491d 2026-05-08
FileHash-SHA256 3710fb27d2032ef1eb1252ebf5c4dd516d2b2c0a83fb82c664c89e504b990fa9 2026-05-08
FileHash-SHA256 5427b4cefb329ed0e9585b3ce58a2788baf87e3b0c7221373f9bbd5f32c85b62 2026-05-08
FileHash-SHA256 96fe4ddfe256dc9d2c6faea7c18e2583cd9d9c0099a4ad2cf082f569ee8379f4 2026-05-08
FileHash-SHA256 c8e96b55f13435c4b43b7209d2403f1a0e0f9deb05edc50e0f777430be693b07 2026-05-08
FileHash-SHA256 d3a896f450561b2546b418b469a8e10949c7320212eb1c72b48e2b1e37c34ba5 2026-05-08
domain cosmic-nebula.cc 2026-05-08
domain silent-harvester.cc 2026-05-08
domain silent-orbit.cc 2026-05-08
domain support-onion.club 2026-05-08
domain whale-ether.pro 2026-05-08