Skip to main content

Cybersecurity researchers have discovered malicious npm packages that are exfiltrating sensitive data.



Cybersecurity researchers have recently detected a new group of malicious packages in the npm package registry that have been designed to extract sensitive developer information.


Phylum, a software supply chain firm, was the first to identify these "test" packages on July 31, 2023. Shortly after their discovery, the packages were removed and re-uploaded under different names that appeared legitimate. The motive behind this campaign remains unclear, but it is suspected to be targeted at the cryptocurrency sector due to references to modules like "rocketrefer" and "binarium."


All the packages were published by a user named malikrukd4732. Each module shares a common feature: the ability to execute JavaScript ("index.js") code, which can then exfiltrate valuable information to a remote server. This code is spawned in a child process by the "preinstall.js" file, which is executed upon package installation, initiating the execution of all the contained code.


The first step of the malicious code involves gathering the current operating system username and the current working directory. This information is then sent in a GET request to 185.62.57[.]60:8000/http. The exact purpose of this action is currently unknown, but it is believed that the data could be used to trigger "unseen server-side behaviors."


The script then proceeds to search for files and directories with specific extensions, such as .env, .svn, .gitlab, .hg, .idea, .yarn, .docker, .vagrant, .github, .asp, .js, .php, .aspx, .jspx, .jhtml, .py, .rb, .pl, .cfm, .cgi, .ssjs, .shtml, .env, .ini, .conf, .properties, .yml, and .cfg.


Once the data is harvested, including potentially sensitive credentials and intellectual property, it is transmitted to the server in the form of a ZIP archive file.


The attack highlights the exploitation of open-source repositories to distribute malicious code, with other examples, like a PyPI campaign, identified by ReversingLabs and Sonatype. In this campaign, suspicious Python packages such as VMConnect, quantiumbase, and ethter were used to contact a command-and-control (C2) server and attempt to download an unspecified Base64-encoded string with additional commands.


To deceive developers and appear trustworthy, the threat actors created corresponding repositories on GitHub with legitimate-looking descriptions, omitting the malicious behavior.


Previously, in early July 2023, ReversingLabs exposed a group of 13 rogue npm modules as part of a campaign called Operation Brainleeches. These modules were collectively downloaded about 1,000 times and facilitated credential harvesting via bogus Microsoft 365 login forms launched from JavaScript email attachments. The npm modules were used to host files for email phishing attacks and supply chain attacks against developers.


The fraudulent npm packages were posted between May 11 and June 13, 2023, and some were used to implant credential harvesting scripts into applications.


This activity highlights the abuse of legitimate services like jsDelivr, a content delivery network (CDN) for npm packages, for malicious purposes.

Popular posts from this blog

AT&T Resets Millions of Customer Passcodes After Data Leak: What You Need to Know

AT&T recently confirmed a significant data breach affecting over 7.6 million current customers and 65 million former customers. The leaked information, which dates back to 2019 or earlier, includes personal details like names, addresses, phone numbers, and social security numbers. Fortunately, financial information and call history were not compromised. In response to the breach, AT&T has reset passcodes for affected customers. Passcodes, usually four-digit numbers, serve as an additional layer of security when accessing accounts. However, security experts warn that the encrypted passcodes leaked alongside customer information could be easily deciphered, posing a risk of unauthorized account access. Affected customers are advised to set up free fraud alerts with major credit bureaus and remain vigilant for any suspicious activity related to their accounts. AT&T is proactively reaching out to impacted customers via email or letter to inform them about the breach and the meas...

Sam Bankman-Fried sentenced to 25 years in jail for FTX fraud

FTX co-founder Sam Bankman-Fried has been sentenced to 25 years in prison for his involvement in seven counts of conspiracy and fraud related to the collapse of the cryptocurrency exchange he established. The judge handed down a sentence of 240 months for four charges and 60 months for two others, along with ordering Bankman-Fried to forfeit more than $11 billion, including property, as recommended by prosecutors. The judge's decision fell short of the 40 to 50 years requested by prosecutors, but exceeded the defense's plea for six and a half years, though it was notably less than the maximum sentence of 110 years. During the trial, it was revealed that Bankman-Fried was aware of the risks FTX faced, misused customer funds, and knowingly engaged in wrongful activities. He justified his actions by weighing the risk of getting caught against potential gains. The judge dismissed claims that customers would be reimbursed, highlighting that FTX customers suffered losses of $8 billio...

What is a VPN and why would you need one?

  Understanding VPN: A Comprehensive Guide for Beginners In today's digital age, the internet is an essential part of our daily lives. From online banking and shopping to social networking and entertainment, we rely on the internet for numerous activities. However, with the increasing reliance on the internet, concerns about online privacy and security have become more prominent. This is where a VPN comes into play. If you're unfamiliar with the term, this guide will explain what a VPN is, how it works, and why you might want to consider using one. What is a VPN? VPN stands for Virtual Private Network. It is a service that creates a secure, encrypted connection between your device (such as a computer, smartphone, or tablet) and the internet. Think of it as a private tunnel through which your data travels, hidden from prying eyes. How Does a VPN Work? When you connect to the internet without a VPN, your data travels through your Internet Service Provider (ISP) and can be potenti...