{"id":106945,"date":"2023-02-26T12:49:02","date_gmt":"2023-02-26T10:49:03","guid":{"rendered":"https:\/\/prohoster.info\/?p=106945"},"modified":"2023-02-27T12:02:06","modified_gmt":"2023-02-27T10:02:06","slug":"v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","title":{"rendered":"Se han encontrado 15,000 paquetes de phishing y spam en NPM.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha registrado un ataque a los usuarios del cat\u00e1logo NPM, como resultado del cual el 20 de febrero se publicaron m\u00e1s de 15,000 paquetes en el repositorio NPM, en cuyos archivos README hab\u00eda enlaces a sitios de phishing o enlaces de referencia que ofrec\u00edan comisiones por clics. En el an\u00e1lisis de los paquetes se identificaron 190 enlaces \u00fanicos de phishing o publicidad, abarcando 31 dominios.     <\/p>\n<p>Los nombres de los paquetes fueron elegidos para atraer el inter\u00e9s de los usuarios comunes, por ejemplo, \u2018free-tiktok-followers\u2019, \u2018free-xbox-codes\u2019, \u2018instagram-followers-free\u2019, etc. Se calcul\u00f3 que estos paquetes spam llenar\u00edan la lista de actualizaciones recientes en la p\u00e1gina principal de NPM. En la descripci\u00f3n de los paquetes, se inclu\u00edan enlaces que promet\u00edan giveaways gratuitos, regalos, trucos para juegos, as\u00ed como servicios gratuitos para aumentar seguidores y likes en redes sociales como TikTok e Instagram. Este no es el primer ataque de este tipo; en diciembre se registr\u00f3 la publicaci\u00f3n de 144 mil paquetes spam en los cat\u00e1logos de NuGet, NPM y PyPi.        <center><img decoding=\"async\" alt=\"Se han encontrado 15,000 paquetes de phishing y spam en NPM.\" src=\"\/wp-content\/uploads\/2023\/02\/434214f596ba6d4174a3f0a8eae982e4.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>    <\/p>\n<p>El contenido de los paquetes fue generado autom\u00e1ticamente mediante un script de Python, que aparentemente se dej\u00f3 inadvertidamente en los paquetes e inclu\u00eda credenciales de trabajo utilizadas durante el ataque. Los paquetes fueron publicados bajo m\u00faltiples cuentas diferentes utilizando m\u00e9todos que complican el rastreo de los registros y la identificaci\u00f3n r\u00e1pida de los paquetes problem\u00e1ticos.      <\/p>\n<p>Adem\u00e1s de las actividades fraudulentas en los repositorios de NPM y PyPi, tambi\u00e9n se han detectado varios intentos de publicaci\u00f3n de paquetes maliciosos:  <\/p>\n<ul>\n<li class=\"l\"> Se encontraron 451 paquetes maliciosos en el repositorio de PyPI, que se ocultaban detr\u00e1s de algunas bibliotecas populares mediante type-squatting (asignaci\u00f3n de nombres similares que difieren por caracteres individuales, como vper en lugar de vyper, bitcoinnlib en lugar de bitcoinlib, ccryptofeed en lugar de cryptofeed, ccxtt en lugar de ccxt, cryptocommpare en lugar de cryptocompare, seleium en lugar de selenium, pinstaller en lugar de pyinstaller, etc.). Los paquetes inclu\u00edan c\u00f3digo ofuscado para robar criptomonedas, que identificaba la presencia de identificadores de billeteras en el portapapeles y los reemplazaba por la billetera del atacante (se supone que la v\u00edctima no notar\u00e1 que el n\u00famero de billetera copiado es diferente al realizar el pago). La sustituci\u00f3n fue llevada a cabo por una extensi\u00f3n integrada en el navegador, que se ejecutaba en el contexto de cada p\u00e1gina web visitada.\n<li class=\"l\"> Se ha identificado una serie de bibliotecas HTTP maliciosas en el repositorio de PyPI. La actividad maliciosa se encontr\u00f3 en 41 paquetes, cuyos nombres fueron seleccionados utilizando m\u00e9todos de type-squatting y que recordaban a bibliotecas populares (aio5, requestst, ulrlib, urllb, libhttps, piphttps, httpxv2, etc.). El contenido estaba estilizado para parecerse a bibliotecas HTTP funcionales o copi\u00f3 el c\u00f3digo de bibliotecas existentes, y en la descripci\u00f3n se inclu\u00edan afirmaciones sobre ventajas y comparaciones con bibliotecas HTTP leg\u00edtimas. La actividad maliciosa se reduc\u00eda a cargar malware en el sistema o a recopilar y enviar datos confidenciales.\n<li class=\"l\"> Se identificaron 16 paquetes de JavaScript en NPM (speedte*, trova*, lagra), que adem\u00e1s de la funcionalidad declarada (pruebas de ancho de banda) conten\u00edan c\u00f3digo para minar criptomonedas sin el conocimiento del usuario.\n<li class=\"l\"> Se identificaron 691 paquetes maliciosos en NPM. La mayor parte de los paquetes problem\u00e1ticos se hac\u00edan pasar por proyectos de Yandex (yandex-logger-sentry, yandex-logger-qloud, yandex-sendsms, etc.) e inclu\u00edan c\u00f3digo para enviar informaci\u00f3n confidencial a fuentes externas. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/\"   title=\"servidores\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1951\">servidores<\/a>Se supone que quienes publicaron los paquetes intentaron lograr que se sustituyera su propia dependencia al compilar proyectos en Yandex (m\u00e9todo de reemplazo de dependencias internas). En el repositorio de PyPI, los mismos investigadores encontraron 49 paquetes (reqsystem, httpxfaster, aio6, gorilla2, httpsos, pohttp, etc.) con c\u00f3digo malicioso ofuscado, que carga y ejecuta un archivo ejecutable desde una fuente externa. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/server\/dts-los-angeles\/\"   title=\"servidores\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3894\">servidores<\/a>.       <\/ul>\n<p>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=58710\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438 \u0440\u0435\u0444\u0435\u0440\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0441\u044b\u043b\u043a\u0438, \u0437\u0430 \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u044b \u043f\u043e \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0432\u044b\u043f\u043b\u0430\u0447\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u043e\u0442\u0447\u0438\u0441\u043b\u0435\u043d\u0438\u044f. \u0412 \u0445\u043e\u0434\u0435 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445 \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 190 \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u044b\u0445 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0445 \u0438\u043b\u0438 \u0440\u0435\u043a\u043b\u0430\u043c\u043d\u044b\u0445 \u0441\u0441\u044b\u043b\u043e\u043a, \u043e\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 31 \u0434\u043e\u043c\u0435\u043d. \u0418\u043c\u0435\u043d\u0430 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":106946,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-106945","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 NPM \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u0444\u0438\u0448\u0438\u043d\u0433\u0430 \u0438 \u0441\u043f\u0430\u043c\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-02-26T10:49:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-02-27T10:02:06+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Se han detectado 15,000 paquetes de phishing y spam en NPM | ProHoster","description":"Se ha registrado un ataque a los usuarios del cat\u00e1logo NPM, como resultado del cual, el 20 de febrero se publicaron m\u00e1s de 15,000 paquetes en el repositorio de NPM, cuyos archivos README conten\u00edan enlaces a sitios de phishing.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 NPM \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0434\u043b\u044f \u0444\u0438\u0448\u0438\u043d\u0433\u0430 \u0438 \u0441\u043f\u0430\u043c\u0430 | ProHoster","og:description":"\u0417\u0430\u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0430 NPM, \u0432 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u043a\u043e\u0442\u043e\u0440\u043e\u0439 20 \u0444\u0435\u0432\u0440\u0430\u043b\u044f \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438 NPM \u0431\u044b\u043b\u043e \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u043e \u0431\u043e\u043b\u0435\u0435 15 \u0442\u044b\u0441\u044f\u0447 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432 README-\u0444\u0430\u0439\u043b\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u043e\u0432\u0430\u043b\u0438 \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0444\u0438\u0448\u0438\u043d\u0433\u043e\u0432\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/v-npm-vyyavleno-15-tysyach-paketov-dlya-fishinga-i-spama","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-02-26T10:49:03+00:00","article:modified_time":"2023-02-27T10:02:06+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"106945","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-09 16:53:52","updated":"2026-02-22 15:31:11","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/106945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=106945"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/106945\/revisions"}],"predecessor-version":[{"id":162422,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/106945\/revisions\/162422"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media\/106946"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=106945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=106945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=106945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}