You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We are opening this discussion to report a potential malware finding detected inside the official opencti-connector-import-document container image during a security scan of our environment.
Detection Summary:
Our security tooling flagged the following during an agentless malware analysis scan performed on 2026-06-24:
The filename factura 0027560.js is a suspicious artifact commonly associated with trojan delivery via phishing or supply chain compromise. Its presence inside the OpenCTI import-document connector raises concerns about whether this file was introduced during the image build process, via a dependency, or through a compromised artifact in the build pipeline.
Request:
We would like the OpenCTI team to:
Investigate whether this file (factura 0027560.js) is a known artifact in the opencti-connector-import-document image or any of its dependencies.
Review the image build history and third-party dependencies for potential supply chain compromise.
Confirm whether this is a false positive or a legitimate security concern.
If confirmed malicious, release a patched image and publish a security advisory.
We are happy to provide additional technical details if needed.
Thank you for your attention to this matter.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
-
Hello OpenCTI team,
We are opening this discussion to report a potential malware finding detected inside the official opencti-connector-import-document container image during a security scan of our environment.
Detection Summary:
Our security tooling flagged the following during an agentless malware analysis scan performed on 2026-06-24:
Malware detected: Win32.Trojan.Leonem (critical confidence)
Secondary detection: Win32.Trojan.Generic
Affected container: opencti-connector-import-document (running instance)
Malicious file path inside the container: /opt/opencti-connector-import-document/factura 0027560.js
OpenCTI version: 6.9.23
SHA-256 hash: 05c491f3252964d79d46b630f3a39478d2f530d513a7353371b6e40d5aba46a6
Context:
The filename factura 0027560.js is a suspicious artifact commonly associated with trojan delivery via phishing or supply chain compromise. Its presence inside the OpenCTI import-document connector raises concerns about whether this file was introduced during the image build process, via a dependency, or through a compromised artifact in the build pipeline.
Request:
We would like the OpenCTI team to:
Investigate whether this file (factura 0027560.js) is a known artifact in the opencti-connector-import-document image or any of its dependencies.
Review the image build history and third-party dependencies for potential supply chain compromise.
Confirm whether this is a false positive or a legitimate security concern.
If confirmed malicious, release a patched image and publish a security advisory.
We are happy to provide additional technical details if needed.
Thank you for your attention to this matter.
Beta Was this translation helpful? Give feedback.
All reactions