Cover image for project: NEXUS Hudson Rock IN PROGRESS

Technical summary

NEXUS Hudson Rock detects emails and usernames associated with computers infected by info-stealers (RedLine, Lumma, Raccoon, etc.) through the free, keyless public Cavalier OSINT Tools API. It ships a 7-day local cache, automatic enrichment through the Intelligence Hub (priority 46, complementary to HIBP) and on-demand operation.

Executed scope

  • Plugin registration (registerTab('hudsonrock','Hudson Rock','shield-alert',tab.php,'OSINT & Enrichment') + registerDoc) with hudsonrock_install() preparing the hudsonrock_cache table (query_key PK, query_type, compromised, stealers_count, service counts, JSON payload, timestamps).
  • 5 API actions: hudsonrock_stats (totals, alert dashboard and API pulse), hudsonrock_query (manual lookup with force), hudsonrock_delete (cache removal), hudsonrock_settings_save (auto_enrich + cache_ttl_days) and hudsonrock_settings (config read).
  • Integration with the free, public Cavalier OSINT Tools API (no authentication): search-by-email?email= and search-by-username?username= at cavalier.hudsonrock.com/api/json/v2/osint-tools, with 8s timeout, IPv4 and fallback to stale cache when the API is down.
  • Query normalization: hudsonrock_normalize_query() tells emails apart (via FILTER_VALIDATE_EMAIL) from usernames (2–128 alphanumeric chars + ._%+-@), producing email:/username: cache keys.
  • Local cache with 7-day TTL (configurable 1–30 via hudsonrock_settings_save): hudsonrock_lookup() serves fresh cache, otherwise queries the API and persists with INSERT … ON DUPLICATE KEY UPDATE.
  • Enrichment (Intelligence Hub): nx_intel_register_enricher('hudsonrock', ['email'], 'hudsonrock_intel_enrich', 46) — after HIBP (45) since it is complementary; honors auto_enrich and the max_live_lookups budget (default 3); signals with source=hudsonrock and summary "Info-stealer: N incident(s) · families"; severity min(95, 55 + N*8) when compromised, 8 when clean; data.complementary explains the difference to HIBP.
  • Alert dashboard: hudsonrock_stats() lists compromised=1 entries (latest 20) with stealer families and service counts, plus recent history (25) and an API availability pulse.
  • On-demand only: no cronjob.json (no periodic routine needed) and no CLI.
  • Fast Responses: fastr.json manifest with /hudsonrock <email or username> (required arg), hudsonrock_query action.
  • UI (tab.php, 361 lines, Alpine hudsonRockTab()): API Online/Offline badge, stat cards, manual lookup with demo shortcuts (username test, demo email), stealer list with family/OS/IP/compromise date, alert dashboard with removal and a recent-cache table with filter.

Stack and tools

  • PHP 8 backend (no framework) + MySQL 8 (hudsonrock_cache)
  • Hudson Rock Cavalier OSINT Tools API v2 (public, free, keyless)
  • Alpine.js + Tailwind CSS (tab.php)
  • Internal Plugin API (PluginManager tabs/actions + fastr.json + enricher)

Operational tags

  • Hudson Rock
  • Info-stealer
  • Malware
  • Cavalier
  • OSINT
  • Email
  • Username
  • NEXUS Plugin

Operational result

  • Info-stealer detection: any email or username found in NEXUS can be checked against credentials stolen by local malware (RedLine, Lumma, Raccoon, etc.).
  • Complementary to HIBP: while HaveIBeenPwned covers database breaches, Hudson Rock covers info-stealer compromise — both enrich the same email in the Intelligence Hub.
  • Free and keyless: the Cavalier API is public and free, with a local cache to save requests.
  • Resilient failure: if the API goes down, the plugin serves stale cache with a warning instead of failing the lookup.
  • Controlled budget: enrichment honors max_live_lookups and auto_enrich, avoiding excessive consumption.
  • On-demand: no scheduled cron — checks happen when requested (panel, API or /hudsonrock slash).

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Detects emails and usernames associated with computers infected by info-stealers (RedLine, Lumma, Raccoon, etc.) through the free, keyless public Cavalier OSINT Tools API; ships a 7-day local cache, automatic enrichment through the Intelligence Hub (priority 46, complementary to HIBP) and on-demand operation.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.