NPM users warned dozens of malicious packages aim to steal host and network data


  • Socket found 60 malicious NPM packages
  • Malware counterfeit legitimate packages
  • It was able to exfilter sensitive data

CyberSecurity Researchers Socket has warned of several malicious packages hosting NPM, stealing sensitive user data and forwarding them to the striker.

In a blog post, Socket said that the 60 packs of NPM, which were uploaded from May 12 and forward with the help of three separate accounts. The packages contained a post-installation script running under ‘NPM Install’ and Exfiltrates host names, internal IP addresses, user home catalogs, current work folders, user names and system-DNS servers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top