The accompanying NPM package axios, which recently received malicious updates, revealed details of an attack in which the attackers gained access to its computer and all credentials. The attack was carried out using a typical social engineering method that had previously been used to compromise developers of cryptocurrency wallets and AI platforms.
The attacker impersonated the founder of a well-known company and offered to organize a joint project. Initially, the accomplice was invited to a Slack workspace that looked realistic, containing channels with messages from LinkedIn, as well as fake profiles of company employees and representatives of other open projects.
After a while, a group discussion was scheduled on the MS Teams platform. During the meeting, technical difficulties arose, attributed to the absence of a necessary add-on on the accomplice's side. The accomplice installed the missing component, which turned out to be malware, providing the attackers with remote access to the system. It was noted that everything was professionally orchestrated and looked plausible.
Source: opennet.ru
