Destructive malware available in NPM repo went unnoticed for 2 years

Date:

Share:



Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to begin in July of that year was given no termination date. Pandya said that means the threat remains persistent, although in an email he also wrote: “Since all activation dates have passed (June 2023–August 2024), any developer following normal package usage today would immediately trigger destructive payloads including system shutdowns, file deletion, and JavaScript prototype corruption.”

Interestingly, the NPM user who submitted the malicious packages, using the registration email address 1634389031@qq[.]com, also uploaded working packages with no malicious functions found in them. The approach of submitting both harmful and useful packages helped create a “facade of legitimacy” that increased the chances the malicious packages would go unnoticed, Pandya said. Questions emailed to that address received no response.

The malicious packages targeted users of some of the largest ecosystems for JavaScript developers, including React, Vue, and Vite. The specific packages were:

Anyone who installed any of these packages should carefully inspect their systems to make sure they’re no longer running. These packages perfectly mimic legitimate development tools, so it may be easy for them to have remained undetected.



Source link

━ more like this

Playdate Season 2 review: Shadowgate PD and CatchaDiablos

Earlier in this Playdate season, I commented in a review that I "love a game that pisses me off a little." Well, I...

Six US Air Force nuclear capable bombers deploy as tensions boil in the Middle East – London Business News | Londonlovesbusiness.com

The US Air Force has deployed six B-2 stealth heavy strategic bombers as Iran tensions reach their highest point in history. The six stealth...

Russia issues a ‘catastrophic’ warning as Trump has not ruled out using nuclear weapons in Iran – London Business News | Londonlovesbusiness.com

The US President has not ruled out using nuclear weapons in Iran to attack the Fordow nuclear enrichment site which is deep underground. The...

Our favorite Levoit air purifier is $37 off in this early Prime Day deal

We now know that the 2025 edition of Amazon's blockbuster Prime Day sales event will start on July 8, and it's set to...

How a data center company uses stranded renewable energy

“Decisions around where...
spot_img