Destructive malware available in NPM repo went unnoticed for 2 years

Date:

Share:



Some of the payloads were limited to detonate only on specific dates in 2023, but in some cases a phase that was scheduled to begin in July of that year was given no termination date. Pandya said that means the threat remains persistent, although in an email he also wrote: “Since all activation dates have passed (June 2023–August 2024), any developer following normal package usage today would immediately trigger destructive payloads including system shutdowns, file deletion, and JavaScript prototype corruption.”

Interestingly, the NPM user who submitted the malicious packages, using the registration email address 1634389031@qq[.]com, also uploaded working packages with no malicious functions found in them. The approach of submitting both harmful and useful packages helped create a “facade of legitimacy” that increased the chances the malicious packages would go unnoticed, Pandya said. Questions emailed to that address received no response.

The malicious packages targeted users of some of the largest ecosystems for JavaScript developers, including React, Vue, and Vite. The specific packages were:

Anyone who installed any of these packages should carefully inspect their systems to make sure they’re no longer running. These packages perfectly mimic legitimate development tools, so it may be easy for them to have remained undetected.



Source link

━ more like this

The Space Invaders movie is apparently still happening

It's been a few years since we last heard anything about that is reportedly in the works, but a new report suggests...

DJI repurposed its drones’ obstacle detection tech for robot vacuums

DJI's obstacle avoidance system could be just as useful on land as it is in the air. DJI, known for its dominance in...

OpenAI brings GPT-4o back online after users melt down over the new model

Following the rollout of OpenAI's latest GPT-5 model earlier this week, a certain user base was adamantly calling for the return of the...

Apple’s MacBook Air M4 is on sale for up to 20 percent off

Whether you need a new MacBook for the upcoming semester or you've just been itching to upgrade from an older machine, now's a...

Watch NASA’s SpaceX Crew-10 astronauts return to Earth

The astronauts part of SpaceX's Crew-10 mission are on their way back home. Their Dragon capsule called Endurance is scheduled to splash down...
spot_img