Security News
data:image/s3,"s3://crabby-images/2bca4/2bca431110f0c9d41bcc781ba529ce3bf9809cdb" alt="North Korean Hackers Suspected in New Wave of Malicious npm Packages"
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malevolent modules. Software supply chain security firm Phylum told The Hacker News the activity exhibits similar behaviors to that of a previous attack wave uncovered in June, which has since been linked to North Korean threat actors.
data:image/s3,"s3://crabby-images/0fe6d/0fe6de19a740a3cb57c46fdaa025550e94b27933" alt="Malicious npm Packages Found Exfiltrating Sensitive Data from Developers"
Cybersecurity researchers have discovered a new bunch of malicious packages on the npm package registry that are designed to exfiltrate sensitive developer information. Software supply chain firm...
data:image/s3,"s3://crabby-images/09248/09248059c60d3f644011fa0fb0adc4c2a0420b4f" alt="New Python tool checks NPM packages for manifest confusion issues"
A security researcher and system administrator has developed a tool that can help users check for manifest mismatches in packages from the NPM JavaScript software registry. The problem is with the inconsistent information between a package's manifest data as displayed in the NPM registry and the data present in the 'package.
data:image/s3,"s3://crabby-images/b3a68/b3a68431556dff4be81dc48546d83f8933f5e1c4" alt="NPM ecosystem at risk from “Manifest Confusion” attacks"
Manifest confusion occurs there is an inconsistency between a package's manifest information presented on the npm registry and the actual 'package. Json' file in the tarball of the published npm package used when the package is installed.
data:image/s3,"s3://crabby-images/32ac0/32ac0bf7a323ae94fadc2c759c0fc0f4c0c73042" alt="Warning: JavaScript registry npm vulnerable to 'manifest confusion' abuse"
The npm Public Registry, a database of JavaScript packages, fails to compare npm package manifest data with the archive of files that data describes, creating an opportunity for the installation and execution of malicious files. "The npm Public Registry does not validate manifest information with the contents of the package tarball, relying instead on npm-compatible clients to interpret and enforce validation/consistency," Clarke explains.
data:image/s3,"s3://crabby-images/91a22/91a2258c7f77f39cdbec57835118548259824152" alt="New Ongoing Campaign Targets npm Ecosystem with Unique Execution Chain"
Cybersecurity researchers have discovered a new ongoing campaign aimed at the npm ecosystem that leverages a unique execution chain to deliver an unknown payload to targeted systems. "The packages in question seem to be published in pairs, each pair working in unison to fetch additional resources which are subsequently decoded and/or executed," software supply chain security firm Phylum said in a report released last week.
data:image/s3,"s3://crabby-images/7294e/7294eb7e70480b4a46c72ed28660a0b2af210ad9" alt="npm packages caught serving TurkoRAT binaries that mimic NodeJS"
Researchers have discovered multiple npm packages named after NodeJS libraries that even pack a Windows executable that resembles NodeJS but instead drops a sinister trojan. These packages, given their stealthiness and a very low detection rate, had been present on npm for over two months prior to their detection by the researchers.
data:image/s3,"s3://crabby-images/3eadb/3eadb9a5f870c0c8b8b50da7335fc3de3c4008d9" alt="npm packages hide TurkoRAT malware in what looks like a NodeJS EXE"
Researchers have discovered multiple npm packages named after NodeJS libraries that even pack a Windows executable that resembles NodeJS but instead drops a sinister trojan. These packages, given their stealthiness and a very low detection rate, had been present on npm for over two months prior to their detection by the researchers.
data:image/s3,"s3://crabby-images/050a9/050a9eb0f57b393b4cab089592bba04b491d28c8" alt="Developer Alert: NPM Packages for Node.js Hiding Dangerous TurkoRat Malware"
Two malicious packages discovered in the npm package repository have been found to conceal an open source information stealer malware called TurkoRat. The findings once again underscore the ongoing risk of threat actors orchestrating supply chain attacks via open source packages and baiting developers into downloading potentially untrusted code.
data:image/s3,"s3://crabby-images/897ae/897aecf88328f29898f7041f1b316978b9674ff3" alt="GitHub debuts pedigree check for npm packages via Actions"
Developers who use GitHub Actions to build software packages for the npm registry can now add a command flag that will publish details about the code's origin. It's often used by software developers to mechanize the build process for packages distributed through the company's npm registry, which hosts more than two million of these modular libraries.