In the NPM repository malicious activity was detected in four packages, which included a preinstall script that sent a comment with information about the IP address, location, username, CPU model, and user's home directory to GitHub before the package was installed. Malicious code was found in the packages (255 downloads), (78 downloads), (48 downloads) and (37 downloads).
The problematic packages were hosted on NPM from August 17 to 24 for distribution using , i.e., with names similar to those of other popular libraries, anticipating that the user would make a typo while entering the name or not notice the differences when choosing a module from the list. Judging by the number of downloads, about 400 users fell for this trick, most of whom confused electorn with electron. Currently, the packages electorn and loadyaml have been removed by the NPM administration, while the packages lodashs and loadyml were deleted by the author.
The motives of the attackers are unknown, but it is assumed that the leak of information through GitHub (the comment was sent via Issue and deleted within a day) could have been carried out as part of an experiment to assess the effectiveness of the method, or a multi-stage attack was planned, in which the first stage involved collecting data on victims, and the second stage, which was not realized due to blocking, intended to release an update that included more dangerous malicious code or a backdoor in the new release.
Source: opennet.ru
