{"id":103932,"date":"2022-05-02T15:37:01","date_gmt":"2022-05-02T13:37:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi"},"modified":"2022-05-02T15:37:01","modified_gmt":"2022-05-02T13:37:01","slug":"opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi","title":{"rendered":"A fost publicat un analizor care a identificat 200 de pachete malware \u00een NPM \u0219i PyPI","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Fondul OpenSSF (Open Source Security Foundation), \u00eenfiin\u021bat de Linux Foundation \u0219i destinat s\u0103 \u00eembun\u0103t\u0103\u021beasc\u0103 securitatea software-ului open source, a lansat un proiect deschis numit Package Analysis, care dezvolt\u0103 un sistem de analiz\u0103 a prezen\u021bei codului d\u0103un\u0103tor \u00een pachete. Codul proiectului este scris \u00een limbajul Go \u0219i este distribuit sub licen\u021ba Apache 2.0. Analiza preliminar\u0103 a depozitelor NPM \u0219i PyPI utiliz\u00e2nd instrumentele propuse a permis identificarea a peste 200 de pachete d\u0103un\u0103toare anterior neobservate.    <\/p>\n<p>Majoritatea problemelor identificate cu pachetele d\u0103un\u0103toare manipuleaz\u0103 intersec\u021bia numelui cu dependen\u021bele interne nepublicate ale proiectelor (atac dependency confusion) sau utilizeaz\u0103 metode de type squatting (atribuit nume similare celor ale bibliotecilor populare), precum \u0219i execut\u0103 scripturi \u00een timpul instal\u0103rii care acceseaz\u0103 gazde externe. Potrivit dezvoltatorilor Package Analysis, cea mai mare parte a pachetelor problematice identificate sunt cel mai probabil create de cercet\u0103tori \u00een securitate care particip\u0103 la programele de recompens\u0103 pentru descoperirea vulnerabilit\u0103\u021bilor (bug bounty), deoarece datele trimise sunt limitate la numele de utilizator \u0219i sistem, iar ac\u021biunile sunt efectuate explicit, f\u0103r\u0103 \u00eencerc\u0103ri de a ascunde comportamentul lor.      <\/p>\n<p>Din pachetele cu activitate d\u0103un\u0103toare se remarc\u0103:  <\/p>\n<ul>\n<li class=\"l\"> Pachetul PyPI discordcmd, \u00een care au fost \u00eenregistrate trimiterea de cereri atipice c\u0103tre raw.githubusercontent.com, Discord API \u0219i ipinfo.io. Acest pachet desc\u0103rca codul unui backdoor de pe GitHub \u0219i \u00eel instala \u00een directorul clientului Windows Discord, dup\u0103 care lansa un proces de c\u0103utare a token-urilor Discord \u00een sistemul de fi\u0219iere \u0219i le trimitea c\u0103tre un server Discord extern, controlat de atacatori.\n<li class=\"l\"> Pachetul NPM colorsss, care a \u00eencercat de asemenea s\u0103 transmit\u0103 c\u0103tre exterior <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ro\/server\/\"   title=\"serverul\" data-wpil-keyword-link=\"linked\">serverul<\/a> token-uri din contul de Discord.\n<li class=\"l\"> Pachetul NPM @roku-web-core\/ajax \u2014 \u00een timpul instal\u0103rii, a trimis date despre sistem \u0219i a pornit un handler (reverse shell) care accept\u0103 conexiuni externe \u0219i execut\u0103 comenzi.\n<li class=\"l\"> Pachetul PyPI secrevthree \u2014 a pornit un reverse shell la importul unui anumit modul.\n<li class=\"l\"> Pachetul NPM random-vouchercode-generator \u2014 dup\u0103 importul bibliotecii, a trimis o cerere c\u0103tre un server extern, care returna comanda \u0219i timpul la care trebuie s\u0103 fie executat\u0103.      <\/ul>\n<p>Analiza pachetelor se refer\u0103 la examinarea codurilor surs\u0103 din pachetele pentru instalarea conexiunilor de re\u021bea, accesarea fi\u0219ierelor \u0219i executarea comenzilor. De asemenea, se monitorizeaz\u0103 schimbarea st\u0103rii pachetelor pentru a determina ad\u0103ugarea de inser\u021bii mali\u021bioase \u00eentr-o versiune ini\u021bial considerat\u0103 inofensiv\u0103 a software-ului. Pentru monitorizarea apari\u021biei de noi pachete \u00een repozitorii \u0219i efectuarea de modific\u0103ri \u00een pachetele deja plasate se utilizeaz\u0103 instrumentul Package Feeds, care standardizeaz\u0103 lucrul cu repozitorii NPM, PyPI, Go, RubyGems, Packagist, NuGet \u0219i Crate.      <\/p>\n<p>Analiza pachetelor include trei componente de baz\u0103, care pot fi utilizate at\u00e2t \u00eempreun\u0103, c\u00e2t \u0219i separat:   <\/p>\n<ul>\n<li class=\"l\"> Scheduler-ul care ini\u021biaz\u0103 lucr\u0103rile de analiz\u0103 a pachetelor pe baza datelor din Package Feeds.\n<li class=\"l\"> Analizorul, care verific\u0103 direct pachetul \u0219i evalueaz\u0103 comportamentul acestuia folosind metode de analiz\u0103 static\u0103 \u0219i urm\u0103rire dinamic\u0103. Verificarea are loc \u00eentr-un mediu izolat.\n<li class=\"l\"> \u00cenc\u0103rc\u0103torul, care plaseaz\u0103 rezultatele verific\u0103rii \u00een stocarea BigQuery.    <\/ul>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=57123\">opennet.ro<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0424\u043e\u043d\u0434 OpenSSF (Open Source Security Foundation), \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0435\u0439 Linux Foundation \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 Package Analysis, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0443 \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u043d\u0430\u043b\u0438\u0447\u0438\u044f \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u043f\u0430\u043a\u0435\u0442\u0430\u0445. \u041a\u043e\u0434 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Go \u0438 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 Apache 2.0. \u041f\u0440\u0435\u0434\u0432\u0430\u0440\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0440\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432 NPM \u0438 PyPI \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u043b\u043e \u0432\u044b\u044f\u0432\u0438\u0442\u044c \u0431\u043e\u043b\u0435\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-103932","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0424\u043e\u043d\u0434 OpenSSF (Open Source Security Foundation), \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0435\u0439 Linux Foundation \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 Package Analysis, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0443.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0430\u0442\u043e\u0440, \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 200 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM \u0438 PyPI | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0424\u043e\u043d\u0434 OpenSSF (Open Source Security Foundation), \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0435\u0439 Linux Foundation \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 Package Analysis, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0443.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2022-05-02T13:37:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-05-02T13:37:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Analizorul a identificat 200 de pachete mali\u021bioase \u00een NPM \u0219i PyPI | ProHoster","description":"Funda\u021bia OpenSSF (Open Source Security Foundation), format\u0103 de organiza\u021bia Linux Foundation, dedicat\u0103 \u00eembun\u0103t\u0103\u021birii securit\u0103\u021bii software-ului deschis, a prezentat proiectul deschis Package Analysis, care dezvolt\u0103 sistemul.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0430\u043d\u0430\u043b\u0438\u0437\u0430\u0442\u043e\u0440, \u0432\u044b\u044f\u0432\u0438\u0432\u0448\u0438\u0439 200 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0432 NPM \u0438 PyPI | ProHoster","og:description":"\u0424\u043e\u043d\u0434 OpenSSF (Open Source Security Foundation), \u0441\u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0435\u0439 Linux Foundation \u0438 \u043d\u0430\u0446\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0433\u043e \u041f\u041e, \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 Package Analysis, \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0443.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/opublikovan-analizator-vyyavivshij-200-vredonosnyh-paketov-v-npm-i-pypi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2022-05-02T13:37:01+00:00","article:modified_time":"2022-05-02T13:37:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"103932","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-25 10:46:15","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2022-05-02 13:37:58","updated":"2026-01-25 10:46:15","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/103932","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=103932"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/103932\/revisions"}],"predecessor-version":[{"id":172983,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/103932\/revisions\/172983"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=103932"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=103932"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=103932"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}