Four packages in the NPM repository were found to be transmitting user data.

In the NPM repository identified malicious activity was detected in four packages, which included a preinstall script that sent a comment with information about the IP address, location, username, CPU model, and user's home directory to GitHub before the package was installed. Malicious code was found in the packages electorn (255 downloads), lodashs (78 downloads), loadyaml (48 downloads) and loadyml (37 downloads).

Four packages in the NPM repository were found to be transmitting user data.

The problematic packages were hosted on NPM from August 17 to 24 for distribution using typesquatting, i.e., with names similar to those of other popular libraries, anticipating that the user would make a typo while entering the name or not notice the differences when choosing a module from the list. Judging by the number of downloads, about 400 users fell for this trick, most of whom confused electorn with electron. Currently, the packages electorn and loadyaml already will be removed have been removed by the NPM administration, while the packages lodashs and loadyml were deleted by the author.

The motives of the attackers are unknown, but it is assumed that the leak of information through GitHub (the comment was sent via Issue and deleted within a day) could have been carried out as part of an experiment to assess the effectiveness of the method, or a multi-stage attack was planned, in which the first stage involved collecting data on victims, and the second stage, which was not realized due to blocking, intended to release an update that included more dangerous malicious code or a backdoor in the new release.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster