File hash 02ff86c7f9fe609a753ff15bda90baa3c3e0d4a2e559ec4fcf8a3de0954b7c55
That file flags as fine across vendors on Virustotal (all the URLs, files, domains and IPs flag as clean across all security vendors).
Press enter or click to view image in full size
![]()
The actual file served, trackpoint-async.js, had malicious code starting at this function:
The code in this sample matches valid Bitcoin, Etherum and TRX wallets in clipboard:
Press enter or click to view image in full size
![]()
It then replaces said addresses in clipboard with
The wallet values are swapped for attacker controlled wallets. Addresses appear to vary.
Get Kevin Beaumont’s stories in your inbox
Join Medium for free to get updates from this writer.
It…






