{"id":106945,"date":"2023-02-26T12:49:02","date_gmt":"2023-02-26T10:49:03","guid":{"rendered":"https:\/\/prohoster.info\/?p=106945"},"modified":"2023-02-27T12:02:06","modified_gmt":"2023-02-27T10:02:06","slug":"v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","title":{"rendered":"NPM has identified 15,000 packages for phishing and spam.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>An attack on users of the NPM directory has been recorded, resulting in over 15,000 packages being posted to the NPM repository on February 20, with README files containing links to phishing sites or referral links that offer commissions for clicks. Analysis revealed 190 unique phishing or advertising links covering 31 domains within the packages.     <\/p>\n<p>Package names were chosen to attract the interest of the general public, such as &#171;free-tiktok-followers&#187;, &#171;free-xbox-codes&#187;, &#171;instagram-followers-free&#187;, etc. The idea was to fill the recent updates list on the NPM homepage with spammy packages. The package descriptions included links promising free giveaways, gifts, game cheats, as well as free services to boost followers and likes on social networks like TikTok and Instagram. This is not the first such attack; in December, 144,000 spam packages were published in the NuGet, NPM, and PyPi directories.        <center><img decoding=\"async\" alt=\"NPM has identified 15,000 packages for phishing and spam.\" src=\"\/wp-content\/uploads\/2023\/02\/434214f596ba6d4174a3f0a8eae982e4.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>The content of the packages was generated automatically using a Python script that, apparently due to oversight, was left in the packages and included working credentials used during the attack. The packages were published under numerous different accounts using methods that complicated the tracing of the source and the quick identification of problematic packages.      <\/p>\n<p>In addition to fraudulent activities, several attempts to publish malicious packages have also been detected in the NPM and PyPi repositories:  <\/p>\n<ul>\n<li class=\"l\"> The PyPI repository has found 451 malicious packages that disguised themselves as popular libraries using typosquatting (assigning similar names differing by individual characters, e.g., vper instead of vyper, bitcoinnlib instead of bitcoinlib, ccryptofeed instead of cryptofeed, ccxtt instead of ccxt, cryptocommpare instead of cryptocompare, seleium instead of selenium, pinstaller instead of pyinstaller, etc.). The packages included obfuscated code for stealing cryptocurrency, which identified the presence of cryptocurrency wallet IDs in the clipboard and replaced them with the attacker\u2019s wallet (it is assumed that the victim would not notice that the wallet number being transferred through the clipboard was different when making a payment). The replacement was carried out by a browser extension embedded in the context of each viewed web page.\n<li class=\"l\"> A series of malicious HTTP libraries have been identified in the PyPI repository. Malicious activity was found in 41 packages, whose names were chosen using typosquatting methods and resembled popular libraries (aio5, requestst, ulrlib, urllb, libhttps, piphttps, httpxv2, etc.). The content was styled to look like working HTTP libraries or copied the code of existing libraries, and the description included claims of advantages and comparisons with legitimate HTTP libraries. The malicious activity was either aimed at downloading malware to the system or collecting and sending confidential data.\n<li class=\"l\"> 16 JavaScript packages (speedte*, trova*, lagra) have been identified in NPM that, in addition to their declared functionality (bandwidth testing), also contained code for mining cryptocurrency without the user\u2019s knowledge.\n<li class=\"l\"> 691 malicious packages have been identified in NPM. Most of the problematic packages pretended to be Yandex projects (yandex-logger-sentry, yandex-logger-qloud, yandex-sendsms, etc.) and included code for sending confidential information to external sources. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/\"   title=\"servers\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1951\">servers<\/a>It is believed that the package uploaders attempted to achieve substitution of their own dependencies during Yandex project builds (a method of substituting internal dependencies). In the PyPI repository, the same researchers found 49 packages (reqsystem, httpxfaster, aio6, gorilla2, httpsos, pohttp, etc.) with obfuscated malicious code that downloads and executes a file from external sources. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3894\">server<\/a>.       <\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58710\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438 \u0440\u0435\u0444\u0435\u0440\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0441\u044b\u043b\u043a\u0438, \u0437\u0430 \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u044b \u043f\u043e \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0432\u044b\u043f\u043b\u0430\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u043e\u0442\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u044f. \u0412 \u0445\u043e\u0434\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 190 \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u044b\u0445 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0445 \u0438\u043b\u0438 \u0440\u0435\u043a\u043b\u0430\u043c\u043d\u044b\u0445 \u0441\u0441\u044b\u043b\u043e\u043a, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 31 \u0434\u043e\u043c\u0435\u043d. \u0418\u043c\u0435\u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":106946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 NPM \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u0444\u0438\u0448\u0438\u043d\u0433\u0430 \u0438 \u0441\u043f\u0430\u043c\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-02-26T10:49:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-02-27T10:02:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 15,000 phishing and spam packages discovered in NPM | ProHoster","description":"An attack on users of the NPM directory has been recorded, resulting in more than 15,000 packages being uploaded to the NPM repository on February 20, which contained links to phishing sites in their README files.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 NPM \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u0444\u0438\u0448\u0438\u043d\u0433\u0430 \u0438 \u0441\u043f\u0430\u043c\u0430 | ProHoster","og:description":"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-02-26T10:49:03+00:00","article:modified_time":"2023-02-27T10:02:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"106945","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 16:53:52","updated":"2026-02-22 15:31:11","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/106945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=106945"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/106945\/revisions"}],"predecessor-version":[{"id":162422,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/106945\/revisions\/162422"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/106946"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=106945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=106945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=106945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}