- Socket found 60 malicious NPM packages
- Malware counterfeit legitimate packages
- It was able to exfilter sensitive data
CyberSecurity Researchers Socket has warned of several malicious packages hosting NPM, stealing sensitive user data and forwarding them to the striker.
In a blog post, Socket said that the 60 packs of NPM, which were uploaded from May 12 and forward with the help of three separate accounts. The packages contained a post-installation script running under ‘NPM Install’ and Exfiltrates host names, internal IP addresses, user home catalogs, current work folders, user names and system-DNS servers.
The script also checks for host names related to sky providers and reverse DNS strings to make sure it does not run in a sandbox.
While socket theoretically, Socket said the packages did not provide additional malware or escalated privileges. Neither was any persistence mechanisms discovered.
A new spin on old tricks
Apparently this was a typical typosquatting attack.
The names of the packages corresponded to others, legitimate, such as “Flipper-plugins”, “React-XTerm2” or “Hermes-Inspector-Msggen”. Based on the names, researchers assumed attackers targeted CI/CD pipes.
Before the packages were withdrawn from the depot, the packages were downloaded about 3,000 times.
The complete list of the 60 malicious packages can be found on this link. Those who have downloaded any of these are advised to remove them immediately and then run a complete system scan. They also need to rotate key information and activate 2FA where possible.
Socket discovered a separate campaign, also at NPM, and also uses the typosquatting technique. However, this distributes eight malicious packages that can delete files, corrupt data and bricks entire systems. They have been present at NPM for about two years, it was said, and during this time they managed to collect 6,200 downloads.
Platforms such as NPM or Pypi are constantly targeting cyber criminals who use it to try to compromise software developers working on open source projects.
Via Bleeping computer