Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT

Researchers studying cybersecurity have found a malicious package on the npm package registry that poses as a library for identifying Ethereum smart contract vulnerabilities but actually installs Quasar RAT, an open-source remote access trojan, on developer PCs.

On December 18, 2024, the highly obfuscated package, ethereumvulncontracthandler, was posted to npm by a user going by the pseudonym “solidit-dev-416.” It is still accessible for download as of this writing. So far, it has been downloaded sixty-six times.

In an investigation released last month, Socket security researcher Kirill Boychenko said that when the RAT is installed, it obtains a malicious script from a distant server and discreetly runs it to install it on Windows systems read more about Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *