Tag: supply chain security

Malicious npm Packages Found Using Image Files to Hide Backdoor Code
News

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

On the npm package registry, two malicious packages that hid backdoor code to carry out malicious commands supplied from a remote server have been discovered by cybersecurity researchers. Img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy are the packages in concern; they have been downloaded 190 and 48 times, respectively. The npm security team has taken them down as of this writing. Software supply chain security company Phylum stated in an analysis that "they contained sophisticated command and control functionality hidden in image files that would be executed during package installation." The packages come with a patched version of the "index.js" file to run a JavaScript file read more about Malicious npm Packages Found Using Image Files to Hide Backdoor ...