RubyGemsis avastatud 724 pahavara paketti

ReversingLabs avalikustas analĂŒĂŒsi tulemused tĂŒĂŒpsĂ”natuure RubyGems'i repositooriumis. Tavaliselt kasutatakse tĂŒĂŒbihĂ€gusust pahatahtlike paketide levitamiseks, arvates, et tĂ€helepanematu arendaja teeb otsingu kĂ€igus trĂŒkivea vĂ”i ei pane tĂ€hele erinevusi. Uuringu kĂ€igus tuvastati ĂŒle 700 paketi, mille nimed sarnanevad populaarsete pakettidega ja erinevad vaid vĂ€ikeste detailide poolest, nĂ€iteks sarnaste tĂ€htede asendamise vĂ”i allajoonimise kasutamisega sidekriipsu asemel.

Rohkem kui 400 paketist leiti komponente, mis kahtlustatakse pahatahtlike tegevuste sooritamises. Eriti leidus seal fail aaa.png, mis sisaldas PE formaadis kÀivitatavat koodi. Loomulikult olid need paketid seotud kahe kontoga, mille kaudu oli ajavahemikus 16. kuni 25. veebruar 2020 RubyGems'is paigutatud 724 pahatahtlikku paketti, mis kokku laaditi umbes 95 tuhat korda. Uurijad teavitasid RubyGems'i haldust ja tuvastatud pahatahtlikud paketid on juba eemaldatud repositooriumist.

Tuvastatud probleemsete paketide seas oli kĂ”ige populaarsem "atlas-client", mis esmapilgul on peaaegu eristamatu legitiimsest paketist "atlas_client". Mainitud paketti laaditi 2100 korda (tavapĂ€rane pakett laaditi samal ajal 6496 korda, st, et kasutajad eksisid peaaegu 25% juhtudest). ÜlejÀÀnud paketid laaditi keskmiselt 100-150 korda ja maskeeriti teiste pakettide alla sarnase allajoonimise ja sidekriipsu asendamise tehnikat kasutades (nĂ€iteks, sealhulgas pahatahtlikud paketid: appium-lib, action-mailer_cache_delivery, activemodel_validators, asciidoctor_bibliography, assets-pipeline, apress_validators, ar_octopus-replication-tracking, aliyun-open_search, aliyun-mns, ab_split, apns-polite).

Malicious packages included a PNG file, in which instead of an image there was an executable file for the Windows platform. The file was created using the Ocra Ruby2Exe utility and included a self-extracting archive with a Ruby script and the Ruby interpreter. Upon installation of the package, the png file was renamed to exe and launched. During execution, a VBScript file was created and added to the autostart. The specified malicious VBScript continuously analyzed the clipboard contents for information resembling cryptocurrency wallet addresses and, upon detection, replaced the wallet number expecting that the user would not notice the difference and would transfer funds to the wrong wallet.

The conducted research showed that it is not difficult to add malicious packages to one of the most popular repositories, and these packages can remain unnoticed despite a significant number of downloads. It should be noted that the problem ei is specific jaoks to RubyGems and also concerns other popular repositories. For instance, last year the same researchers tuvastasid in the NPM repository a malicious package bb-builder was found, using a similar technique to launch an executable file to steal passwords. Before that, the backdoor was lahendus in the dependency to the NPM package event-stream, and the malicious code was downloaded about 8 million times. Malicious packages also periodically pop up in the PyPI repository.

Allikas: opennet.ru

Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne hostimine veebilehtede jaoks DDoS-i kaitsega, VPS VDS serverid | ProHoster