Security News

Malicious NPM packages target Amazon, Slack with new dependency attacks
2021-03-02 05:14

Threat actors are targeting Amazon, Zillow, Lyft, and Slack NodeJS apps using a new 'Dependency Confusion' vulnerability to steal Linux/Unix password files and open reverse shells back to the attackers. When hosted on public repositories, including npm, PyPI, and RubyGems, dependency managers would use the packages on the public repo rather than the company's internal packages when building the application.

Discord-Stealing Malware Invades npm Packages
2021-01-22 18:35

The packages represent a supply-chain threat given that they may be used as building blocks in various web applications; any applications corrupted by the code can steal tokens and other information from Discord users, researchers said. There is also "Clear evidence that the malware campaign was using a Discord bot to generate fake download counts for the packages to make them appear more popular to potential users," according to researchers at Sonatype.

Malicious NPM packages used to install njRAT remote access trojan
2020-12-01 14:00

New malicious NPM packages have been discovered that install the njRAT remote access trojan that allows hackers to gain control over a computer. NPM is a JavaScript package manager that allows developers and users to download packages and integrate them into their projects.

Malicious NPM project steals Discord accounts, browser info
2020-11-09 17:37

A heavily obfuscated and malicious NPM project is used to steal Discord user tokens and browser information from unsuspecting users. Due to this open system, it is becoming common for malicious actors to upload malicious modules that steal data, download and execute programs, or perform malicious behavior when used in other projects.

NPM nukes NodeJS malware opening Windows, Linux reverse shells
2020-10-16 11:44

These 4 packages had collected over 1,000 total downloads over the course of the last few months up until being removed by NPM yesterday. Although the malicious packages were spotted and removed by NPM, I was able to dig into Sonatype's automated malware detection system archives to obtain copies of their source code, as it had existed on NPM downloads.

Malicious npm package taken down after Microsoft warning
2020-01-15 11:32

Criminals have been caught trying to sneak a malicious package on to the popular Node.js platform npm. The problem package, 1337qq-js, was uploaded to npm on 31 December, after which it was downloaded at least 32 times according to figures from npm-stat.

Npm Patches Vulnerability Allowing Access to User Files
2019-12-16 16:52

JavaScript package manager npm last week addressed a vulnerability that could allow a publisher to access files on a user’s system. The issue impacts versions of npm prior to 6.13.3 and versions...

Npm patches two serious bugs
2019-12-16 10:57

JavaScript package users have been warned to update due to a bug that could enable an attacker to infect them with malicious applications.

NPM swats path traversal bug that lets evil packages modify, steal files. That's bad for JavaScript crypto-wallets
2019-12-13 02:05

Trio of vulnerabilities made registry full of uncertain code even more of a risk On Wednesday, NPM, Inc, the California-based biz that has taken it upon itself to organize the world's JavaScript...

Malicious code ousted from PureScript's npm installer – but who put it there in the first place?
2019-07-15 06:04

Account hijacking claimed by some but it may just be a developer behaving badly Another JavaScript package in the npm registry - the installer for PureScript - has been tampered with, leading...