Homebrew malvertising campaign (11-11-2025)

Google Search Ad

Google ad for Homebrew

Traffic view

Traffic

Decoy page

Decoy page

Payload

Commands

VirusTotal

IOCs

Decoy page sites[.]google[.]com/view/brewpageapp/brew
Payload URL palymera[.]com/fourk/update
Payload SHA256 dfd92ae11fd7185a03419adcf8cec1c75b18eb7256465da49e46d9a042e263f0
Malvertising Research index