ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://api.github.com/search/commits?q=beautifulcastle.

Database Entry


IOC ID:1797082
IOC: https://api.github.com/search/commits?q=beautifulcastle
IOC Type :url
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS36459 GITHUB
Country:- US
First seen:2026-04-24 08:50:30 UTC
Last seen:never
UUID:2a6e1a36-3fb9-11f1-8759-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Tags:teampcp
Reference: https://www.mend.io/blog/compromised-bitwarden-cli-npm-worm-ai-poisoning/

Avatar
johannes
Fallback channel search query, from the Mend.io report "The Butlerian Jihad: Compromised Bitwarden CLI Deploys npm Worm, Poisons AI Assistants, and Dumps GitHub Secrets". See all IOC from that report at https://rosti.dev/reports/onwuRLqp