Ngama-17 eepakethe eziyingozi ezichongiweyo kwindawo yokugcina ye-NPM

Indawo yokugcina ye-NPM ichonge iipakethe ezikhohlakeleyo ezili-17 ezasasazwa kusetyenziswa uhlobo lwe-squatting, okt. ngonikezelo lwamagama afanayo namagama amathala eencwadi adumileyo ngolindelo lokuba umsebenzisi uya kwenza ukuchwetheza xa echwetheza igama okanye akayi kuqaphela umahluko xa ukhetha umnqongo kuluhlu.

ΠŸΠ°ΠΊΠ΅Ρ‚Ρ‹ discord-selfbot-v14, discord-lofy, discordsystem ΠΈ discord-vilao использовали ΠΌΠΎΠ΄ΠΈΡ„ΠΈΡ†ΠΈΡ€ΠΎΠ²Π°Π½Π½Ρ‹ΠΉ Π²Π°Ρ€ΠΈΠ°Π½Ρ‚ Π»Π΅Π³ΠΈΡ‚ΠΈΠΌΠ½ΠΎΠΉ Π±ΠΈΠ±Π»ΠΈΠΎΡ‚Π΅ΠΊΠΈ discord.js, ΠΏΡ€Π΅Π΄ΠΎΡΡ‚Π°Π²Π»ΡΡŽΡ‰Π΅ΠΉ Ρ„ΡƒΠ½ΠΊΡ†ΠΈΠΈ для взаимодСйствия с API Discord. ВрСдоносныС ΠΊΠΎΠΌΠΏΠΎΠ½Π΅Π½Ρ‚Ρ‹ Π±Ρ‹Π»ΠΈ ΠΈΠ½Ρ‚Π΅Π³Ρ€ΠΈΡ€ΠΎΠ²Π°Π½Ρ‹ Π² ΠΎΠ΄ΠΈΠ½ ΠΈΠ· Ρ„Π°ΠΉΠ»ΠΎΠ² ΠΏΠ°ΠΊΠ΅Ρ‚Π° ΠΈ Π²ΠΊΠ»ΡŽΡ‡Π°Π»ΠΈ ΠΎΠΊΠΎΠ»ΠΎ 4000 строк ΠΊΠΎΠ΄Π°, Π·Π°ΠΏΡƒΡ‚Π°Π½Π½ΠΎΠ³ΠΎ с использованиСм искаТСния ΠΈΠΌΡ‘Π½ ΠΏΠ΅Ρ€Π΅ΠΌΠ΅Π½Π½Ρ‹Ρ…, ΡˆΠΈΡ„Ρ€ΠΎΠ²Π°Π½ΠΈΡ строк ΠΈ Π½Π°Ρ€ΡƒΡˆΠ΅Π½ΠΈΡ форматирования ΠΊΠΎΠ΄Π°. Код сканировал Π»ΠΎΠΊΠ°Π»ΡŒΠ½ΡƒΡŽ Π€Π‘ Π½Π° ΠΏΡ€Π΅Π΄ΠΌΠ΅Ρ‚ Ρ‚ΠΎΠΊΠ΅Π½ΠΎΠ² Discord ΠΈ Π² случаС выявлСния отправлял ΠΈΡ… Π½Π° umncedisi abangeneleli.

Iphakheji yempazamo yokulungisa ibibangwa ukuba ilungisa iibugs kwiDiscord selfbot, kodwa ibandakanya usetyenziso lweTrojan olubizwa ngokuba yiPirateStealer eba amanani ekhadi letyala kunye neeakhawunti ezinxulumene neDiscord. Ilungu eliyingozi lenziwe lasebenza ngokufaka ikhowudi yeJavaScript kumxhasi weDiscord.

Iphakheji ye-prerequests-xcode iquka iTrojan yokulungelelanisa ukufikelela kude kwinkqubo yomsebenzisi, ngokusekelwe kwisicelo seDiscordRAT Python.

Kukholelwa ukuba abahlaseli banokufuna ukufikelela kwiiseva zeDiscord ukuze bafake iindawo zokulawula i-botnet, njenge-proxy yokukhuphela ulwazi kwiinkqubo eziphazamisekileyo, ukugubungela ukuhlaselwa, ukusabalalisa i-malware phakathi kwabasebenzisi be-Discord, okanye ukuthengisa ii-akhawunti zeprimiyamu.

Iipakethe zibopha iwafer, iwafer-autocomplete, wafer-beacon, wafer-caas, wafer-toggle, wafer-geolocation, wafer-image, wafer-form, wafer-lightbox, octavius-public kunye nemrg-umyalezo-broker ibandakanya ikhowudi ukuthumela imixholo yezinto eziguquguqukayo zemo engqongileyo, ezinokuthi, umzekelo, zibandakanye izitshixo zokufikelela, amathokheni okanye amagama ayimfihlo kwiinkqubo eziqhubekayo zokudibanisa okanye iimeko zefu ezifana ne-AWS.

umthombo: opennet.ru

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS πŸ”₯ Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster