Cybersecurity researcher Saurabh identified suspicious code within the React2shell-scanner script, revealing a hidden payload designed to execute mshta.exe and download a secondary malware stage from py-installer.cc.
Malicious ‘React2shell-scanner’ on GitHub targets researchers with malware
Related articles
