Security News
data:image/s3,"s3://crabby-images/15624/15624b9a6da38994cbd2f0efb790c68308e1556c" alt="Hackers Flood NPM with Bogus Packages Causing a DoS Attack"
Threat actors are flooding the npm open source package repository with bogus packages that briefly even resulted in a denial-of-service attack. "The threat actors create malicious websites and publish empty packages with links to those malicious websites, taking advantage of open-source ecosystems' good reputation on search engines," Checkmarx's Jossef Harush Kadouri said in a report published last week.
data:image/s3,"s3://crabby-images/adaf2/adaf254f363e267b4402de7851ba037958a22e83" alt="Flood of malicious packages results in NPM registry DoS"
Attackers are exploiting the good reputation and "Openness" of the popular public JavaScript software registry NPM to deliver malware and scams, but are also simultaneously and inadvertently launching DoS attacks against the service. Malicious package on NPM pointing to a site serving malware.
data:image/s3,"s3://crabby-images/826bf/826bfb307b7126c8258fcf0d939623b3550a8236" alt="NPM JavaScript packages abused to create scambait links in bulk"
They existed simply as placeholders for README files that included the final links that the crooks wanted people to click on. These links typically including referral codes that would net the scammers a modest reward, even if the person clicking through was doing so simply to see what on earth was going on.
data:image/s3,"s3://crabby-images/8bb2d/8bb2d7f2c8f49437182b51a9d9df97d18d7374af" alt="Attackers Flood NPM Repository with Over 15,000 Spam Packages Containing Phishing Links"
In what's a continuing assault on the open source ecosystem, over 15,000 spam packages have flooded the npm repository in an attempt to distribute phishing links. "The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report.
data:image/s3,"s3://crabby-images/b78f7/b78f7971b3f9199503da91abc48c1e0c7980d2a3" alt="Researchers Hijack Popular NPM Package with Millions of Downloads"
A popular npm package with more than 3.5 million weekly downloads has been found vulnerable to an account takeover attack. "The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password," software supply chain security company Illustria said in a report.
data:image/s3,"s3://crabby-images/553e1/553e1e8f0c3084be7f701c07e476118bb3975535" alt="NPM packages posing as speed testers install crypto miners instead"
A new set of 16 malicious NPM packages are pretending to be internet speed testers but are, in reality, coinminers that hijack the compromised computer's resources to mine cryptocurrency for the threat actors. The packages were uploaded onto NPM, an online repository containing over 2.2 million open-source JavaScript packages shared among software developers to speed up the coding process.
data:image/s3,"s3://crabby-images/c2b30/c2b309951a82829aa5992059e21eef273f595515" alt="Researchers Find a Way Malicious NPM Libraries Can Evade Vulnerability Detection"
New findings from cybersecurity firm JFrog show that malware targeting the npm ecosystem can evade security checks by taking advantage of an "Unexpected behavior" in the npm command line interface tool. Npm CLI's install and audit commands have built-in capabilities to check a package and all of its dependencies for known vulnerabilities, effectively acting as a warning mechanism for developers by highlighting the flaws.
data:image/s3,"s3://crabby-images/00c28/00c28b6f7821ebf4d18841420ad9ca25f22dee7e" alt="Researchers Find a Way Malicious NPM Libraries Can Evade Vulnerability Detection"
New findings from cybersecurity firm JFrog show that malware targeting the npm ecosystem can evade security checks by taking advantage of an "Unexpected behavior" in the npm command line interface tool. Npm CLI's install and audit commands have built-in capabilities to check a package and all of its dependencies for known vulnerabilities, effectively acting as a warning mechanism for developers by highlighting the flaws.
data:image/s3,"s3://crabby-images/6d747/6d7471108a1a2a5cf0958561f8fccd6bd4e18fc4" alt="RomCom RAT malware campaign impersonates KeePass, SolarWinds NPM, Veeam"
The threat actor behind the RomCom RAT has refreshed its attack vector and is now abusing well-known software brands for distribution. In a new campaign discovered by BlackBerry, the RomCom threat actors were found creating websites that clone official download portals for SolarWinds Network Performance Monitor, KeePass password manager, and PDF Reader Pro, essentially disguising the malware as legitimate programs.
data:image/s3,"s3://crabby-images/d93b2/d93b22017a1cabc416bb094d26b47f3e9ec0538f" alt="New Timing Attack Against NPM Registry API Could Expose Private Packages"
A novel timing attack discovered against the npm's registry API can be exploited to potentially disclose private packages used by organizations, putting developers at risk of supply chain threats. The Scoped Confusion attack banks on analyzing the time it takes for the npm API to return an HTTP 404 error message when querying for a private package, and measuring it against the response time for a non-existing module.