ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain filev2.getsession.org.

Database Entry


IOC ID:1811369
IOC: filev2.getsession.org
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS24940 HETZNER-AS
Country:- DE
First seen:2026-05-12 14:49:43 UTC
Last seen:2026-05-12 13:39:54 UTC
UUID:258bf622-4de4-11f1-b930-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Reference: https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem

Avatar
johannes
Outbound HTTPS connections to or during npm install or build steps, from the Step Security report "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages". See all IOC from that report at https://rosti.dev/reports/rkF1AXYC