Tag: Legitimate Tools

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools
News

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools

Malicious typosquats of legitimate npm packages, like typescript-eslint and @types/node, have been uploaded by threat actors and have amassed thousands of downloads on the package registry. The fake versions, called types-node and @typescript_eslinter/eslint, are designed to retrieve second-stage payloads and download a trojan, respectively. The effort made by malicious actors to pass off these two libraries as authentic is significant, even though typosquatting assaults are not new, according to an analysis released on Wednesday by Sonatype's Ax Sharma. Additionally, the high download numbers for packages like "types-node" are indicators that threat actors may be inflating these counts to increase the credibility of their harmful components read more about Thousands Download Mal...