Falcon API IOC Import Payload (9 indicators)
POST to /indicators/entities/iocs/v1 — Weak/benign indicators pre-filtered. Expiration set to 90 days.
Copy JSON
[
{
"type": "domain",
"value": "@solana-launchpad/sdk (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package identified in Contagious Trader sub-operation; targets Solana developers for wallet exfiltration",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "@validate-sdk/v2 (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package linked to Famous Chollima Contagious Interview campaign",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "express-session-js (npm package)",
"source": "SCC Threat Intel",
"description": "Trojanized npm package used for credential and session theft",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "csec-crypto-utils (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package in Contagious Interview campaign; crypto utility masquerade",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "graph-dynamic (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package linked to graphalgo sub-operation",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "graphbase-js (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package linked to graphalgo sub-operation",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "graphlib-js (npm package)",
"source": "SCC Threat Intel",
"description": "Malicious npm package linked to graphalgo sub-operation",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "solana-sdk (PyPI package)",
"source": "SCC Threat Intel",
"description": "Malicious PyPI package targeting Solana Python developers; wallet and credential exfiltration",
"severity": "high",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
},
{
"type": "domain",
"value": "axios (npm package \u2014 trojanized version)",
"source": "SCC Threat Intel",
"description": "Widely-used axios npm package confirmed trojanized or compromised in a specific version; verify against official maintainer releases before trusting",
"severity": "medium",
"action": "detect",
"platforms": [
"windows",
"mac",
"linux"
],
"applied_globally": true,
"expiration": "2026-07-30T00:00:00Z"
}
]