Destructive malware available in NPM repo went unnoticed for 2 years

Date:

Share:



Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to begin in July of that year was given no termination date. Pandya said that means the threat remains persistent, although in an email he also wrote: “Since all activation dates have passed (June 2023–August 2024), any developer following normal package usage today would immediately trigger destructive payloads including system shutdowns, file deletion, and JavaScript prototype corruption.”

Interestingly, the NPM user who submitted the malicious packages, using the registration email address 1634389031@qq[.]com, also uploaded working packages with no malicious functions found in them. The approach of submitting both harmful and useful packages helped create a “facade of legitimacy” that increased the chances the malicious packages would go unnoticed, Pandya said. Questions emailed to that address received no response.

The malicious packages targeted users of some of the largest ecosystems for JavaScript developers, including React, Vue, and Vite. The specific packages were:

Anyone who installed any of these packages should carefully inspect their systems to make sure they’re no longer running. These packages perfectly mimic legitimate development tools, so it may be easy for them to have remained undetected.



Source link

━ more like this

Xbox’s VR headset with Meta could release sooner than we thought

Xbox has come a long way since its humble beginnings as a chunky console. It's recently taken on the form of an Asus...

Chinese company Netease is making an AAA action-adventure game called ‘Blood Message’

NetEase, the Chinese video game company that published Marvel Rivals and Bungie's Destiny: Rising, has announced its first single-player AAA game. It's a...

Tesla inaugural Robotaxi rides will have a human ‘safety monitor’ on board

A select few will soon get to experience Tesla's robotaxi service for the first time, but they won't be alone in the car....

Amazon Prime Day 2025: The best early deals you can shop now, dates and everything else you need to know

Amazon Prime Day 2025 will be here soon on July 8-11, but as to be expected, you can already find some decent sales...
spot_img