25 malicious packages have been identified in the NPM repository, which were distributed using typosquatting, i.e., by using names similar to popular libraries, expecting that users would make a typo when typing the name or not notice the differences while selecting a module from the list.
- 17 packages included malicious code to search for Discord tokens in the local file system and send them to the attackers' server. In most cases, the malicious changes were camouflaged through the delivery of modified variants of legitimate libraries such as discord.js and colors.
- node-colors-sync
- color-self
- color-self-2
- lemaaa
- adv-discord-utility
- tools-for-discord
- purple-bitch
- purple-bitchs
- noblox.js-addons
- discord-selfbot-tools
- discord.js-aployscript-v11
- discord.js-selfbot-aployscript
- discord.js-selfbot-aployed
- discord.js-discord-selfbot-v4
- colors-beta
- vera.js
- discord-protection
- 5 packages included code to send the contents of environment variables, which could include access keys, tokens, or passwords to continuous integration systems or cloud environments such as AWS.
- wafer-text
- wafewafer-templater-countdown
- wafer-template
- wafer-darla
- mynewpkg
- 2 packages (markedjs, crypto-standarts) included a Trojan for organizing remote access to the user's system, allowing arbitrary code execution in Python (Python remote code injector).
- 1 package (kakakaakaaa11aa) included a backdoor for remote system control (Connectback shell).
Source: opennet.ru
