IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE22 IOCs

Sckit Supply Chain Worm Hits MemTensor npm & PyPi scopes

SS
Step Security
Published September 30, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYPlayINFRASTRUCTURE139.84.223.178https://0b48fafd6fbe.…https://8a8acaf167b3.…CAPABILITYMETA StealerPlayVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability(2)
Victim

Indicators of Compromise

Indicators of Compromise22

TypeIndicatorConfidenceScoreFirst Seen
IP139.84.223.178
exploitintel-blogmalware
High
58
Oct 9, 26
SHA2568f647f17a1934679c4095e21bee2b9bd83e28476603758bc91408a0c8443e3b4
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2565dbc82475ce61369e53f795f0a44451715763450051fa2a84d38d6b2e8700114
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256f7c4014e284f3d56c452b8b222a287c54f73dc4a40a7e022e765ac8376362947
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25616de381deb978744535b10f68fe15165251374b86eef18ffc2c47f61ea673047
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttps://0b48fafd6fbe.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256d6b3e77c36ee8017c9bf30d1da7218ec0ea843768d313eb8e35845c8a9b38a26
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25665faf8ccbcf5b34eb4f72c71bf82815fa9c1e2f947b9c898491540e866132c31
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256c1b0998347b489582bae7b7f4930f9831d9ef4b6bc150cfd488ee1a43272dd36
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25656cd3416d2ec2aa7e7cec2a06010cf0b58eb09c0a5486809df52afeaca8f14be
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttps://8a8acaf167b3.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://c747d139e7e9.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256f8ccdd1da7dff1aef16377a2842bc7acf7c516e32122dd6e42dc4a4e57653fce
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttps://266297c6df27.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256e077c387b223811064b7bbc5a55a0182fca9bf50894f949ff284d4be87d44b26
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2569de0d5b0ca184f71f630be5781d134998883a02d5d7bc65aeb9559d8f9efb364
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256d9169ce8f4faaa663bf5f44918b5612ed9f933ba18987207dc4ab412733d5164
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256381ac6dc1715d9298fe81b2a53a11f7b7d78e361ee3a6619ad54f8c4b062cc18
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2565405e330507602e803f7dd6f2a9d4555aec8558ab222b51413594a962da6888a
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttps://73376a079d87.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://d4f77a3a8cb0.skyleen.fr
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://10729e014d0e.skyleen.fr/eb57efaa7365698fc1e4decc/initial-ci-v2
intel-blogmalwarenetwork
High
58
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph22 total IOCs
IPSHA256URL
SHA25614URL7IP1Actors1Malware2REPORTSckit Supply Chain Worm HiPlayMETA StealerPlay
scroll to zoom · drag to pan · click IOC to open