Tag: Malicious NPM Packages

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
News

36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants

36 malicious packages that pose as Strapi CMS plugins but have various payloads to enable Redis and PostgreSQL exploitation, deploy reverse shells, harvest passwords, and drop a permanent implant have been found by cybersecurity experts in the npm registry. According to SafeDep, each package utilizes version 3.6.8 to appear as a mature Strapi v3 community plugin, has three files (package.json, index.js, and postinstall.js), and lacks a description, repository, or webpage. The same naming technique is used for all identified npm packages, beginning with "strapi-plugin-" and followed by terms like "cron," "database," or "server" to trick unwary developers into downloading them. It's important to remember that the official Strapi plugins are scoped at ".strapi/." The packages listed...
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
News

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

According to cybersecurity researchers, there is an ongoing "Shai-Hulud-like" supply chain worm campaign that has used a group of at least 19 malicious npm packages to facilitate cryptocurrency key theft and credential harvesting. The supply chain security firm Socket has given the campaign the code name SANDWORM_MODE. Similar to previous Shai-Hulud attack waves, the malicious code included in the packages has the ability to access tokens, environment secrets, and API keys from developer environments, syphon off system information, and automatically spread by abusing GitHub and npm identities to increase its reach. In addition to adding GitHub API exfiltration with DNS fallback, hook-based persistence, SSH propagation fallback, MCP server injection with embedded prompt injection tar...
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials
News

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

Details of a "sustained and targeted" spear-phishing attack that published more than two dozen packages to the npm registry to enable credential theft have been made public by cybersecurity researchers. According to Socket, the activity, which included uploading 27 npm packages from six distinct npm aliases, has mostly targeted sales and commercial staff at critical infrastructure-adjacent firms in the United States and Allied countries. Researchers Nicholas Anderson and Kirill Boychenko reported that a five-month operation transformed 27 npm packages into robust hosting for browser-run lures that imitate Microsoft sign-in and document-sharing portals, targeting 25 companies in the manufacturing, industrial automation, plastics, and healthcare sectors for credential theft. The na...
Malicious NPM packages fetch infostealer for Windows, Linux, macOS
News

Malicious NPM packages fetch infostealer for Windows, Linux, macOS

An information-stealing component that gathers private information from Windows, Linux, and macOS systems is downloaded by ten malicious packages that imitate genuine software projects in the npm registry. Because of several levels of obfuscation that enabled them evade common static analysis tools, the packages, which were posted to npm on July 4, went unnoticed for a considerable amount of time. Researchers at the cybersecurity firm Socket claim that the ten packages collected login credentials from browsers, authentication services, and system keyrings, and they counted close to 10,000 downloads. At the time of writing, the packages are still available, despite Socket reporting them to npm read more about Malicious NPM packages fetch infostealer for Windows Linux macOS. Get...
Malicious npm Packages Impersonate Flashbots Steal Ethereum Wallet Keys
News

Malicious npm Packages Impersonate Flashbots Steal Ethereum Wallet Keys

Four new malicious packages that can steal Ethereum developers' cryptocurrency wallet credentials have been found in the npm package repository. According to an investigation by Socket researcher Kush Pandya, the packages pose as trustworthy cryptographic tools and Flashbots MEV infrastructure while surreptitiously transferring private keys and mnemonic seeds to a Telegram bot under the threat actor's control. One person, "flashbotts," uploaded the packages to npm; the oldest library was posted as early as September 2023. August 19, 2025 was the date of the most current upload. The packages in question are mentioned below, and as of this writing, they are all still downloadable: @flashbotts/ethers-provider-bundle (52 Downloads) flashbot-sdk-eth (467 Downloads) sdk-ethers (...
BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers
News

BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers

A known malware known as BeaverTail, a JavaScript downloader and information stealer connected to an ongoing North Korean effort known as Contagious Interview, was discovered to be present in three malicious packages uploaded to the npm repository in September 2024. Tenacious Pungsan, also known as CL-STA-0240 and Famous Chollima, is the name under which the Datadog Security Research team is keeping an eye on the activity. The following list contains the names of the harmful packages that can no longer be downloaded from the package registry read more about BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers. passports-js, a backdoored copy of the passport (118 downloads) bcrypts-js, a backdoored copy of bcryptjs (81 downloads) blockscan-api, a bac...
Malicious npm Packages Mimicking ‘noblox.js’ Compromise Roblox Developers’ Systems
News

Malicious npm Packages Mimicking ‘noblox.js’ Compromise Roblox Developers’ Systems

A sustained campaign aimed at compromising devices using fake npm packages is aimed at Roblox developers, highlighting the ongoing practice of threat actors taking advantage of the confidence placed in the open-source ecosystem to distribute malware. According to a technical analysis by Checkmarx researcher Yehuda Gelb, attackers have released dozens of packages that are intended to steal confidential information and corrupt systems by imitating the well-known 'noblox.js' library. ReversingLabs originally reported on the campaign's details in August 2023. At the time, the campaign was delivering a stealer known as Luna Token Grabber, which the company said was a rerun of an assault that had been discovered two years prior in October 2021 read more about Malicious npm Packages Mimick...
Malicious npm Packages Found Using Image Files to Hide Backdoor Code
News

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

On the npm package registry, two malicious packages that hid backdoor code to carry out malicious commands supplied from a remote server have been discovered by cybersecurity researchers. Img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy are the packages in concern; they have been downloaded 190 and 48 times, respectively. The npm security team has taken them down as of this writing. Software supply chain security company Phylum stated in an analysis that "they contained sophisticated command and control functionality hidden in image files that would be executed during package installation." The packages come with a patched version of the "index.js" file to run a JavaScript file read more about Malicious npm Packages Found Using Image Files to Hide Backdoor ...
Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub
News

Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

It has been observed that two malicious packages that were found on the npm package registry use GitHub as a means of storing SSH keys that are encrypted with Base64 and were taken from developer workstations that they were installed on. The npm maintainers removed the modules warbeast2000 and kodiak2k, which had received 412 and 1,281 downloads, respectively, at the beginning of the month. The date of the most recent downloads was January 21, 2024. ReversingLabs, a software supply chain security business, uncovered the finding and said that over 30 variants of Kodiak2k and eight variations of Warbeast2000 were available. Each module can get and run a distinct JavaScript file read more Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub. Get up to date ...