Attackers Gain Control of DuckDB Project NPM Packages and Publish Malicious Releases

The story of the compromise of 18 NPM packages, which together account for more than 2 billion downloads per week, has continued. A similar phishing attack was detected for the credentials of the DuckDB project, which maintains NPM packages. Versions with malicious code were also created for DuckDB packages, which substituted the details when making payments via cryptocurrency, but the attack was immediately detected and only a few downloads of malicious packages were recorded. At the same time, according to preliminary data, the packages with a malicious insert, published during the attack on 18 NPM packages announced yesterday, managed to be downloaded more than 2.5 million times.

Packages compromised in the second phishing attack:

PackagePeak Downloads Per WeekNumber of DependenciesDuckdb Malicious Version242K611.3.3 @duckdb/duckdb-wasm170K431.3.3 @duckdb/node-api81K336.2.2 @duckdb/node-bindings82K11.29.2 @coveops/abi55102.0.1


Source: opennet.ru
Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster