Malware
GHOSTBLADE
According to Google, GHOSTBLADE is delivered via the DarkSword exploit chain.
GHOSTBLADE is a JavaScript malware family operated by UNC6353.
Background
Per Google, GHOSTBLADE is distributed through the DarkSword exploit chain. It is a JavaScript dataminer that harvests and exfiltrates a broad range of data from a compromised device, sending the collected information to an attacker-controlled server over HTTP(S). Compared to GHOSTKNIFE and GHOSTSABER, GHOSTBLADE is more limited: it lacks support for extra modules or backdoor-style features and does not run continuously. Like GHOSTKNIFE, however, it contains code to remove crash reports, though it targets a different directory where such reports might reside.
Source: Malpedia (Fraunhofer FKIE).