iTnews Asia
  • Home
  • News
  • Security

Malware once again a headache for npm

Malware once again a headache for npm

Fortiguard finds data-thieving packages.

By Richard Chirgwin on Oct 4, 2023 10:32AM

Fortiguard Labs is warning of a bunch of malicious packages it found in Node Package Manager (npm), the largest JavaScript software registry.

In an October 2 blog post, Fortiguard’s Jin Lee and Jenna Wang said the packages aim “to steal sensitive data, such as system or user information, via a webhook or file-sharing link”.

Lee and Wang said they identified some packages that, “while obfuscated, exfiltrate sensitive data”. 

That included “Kubernetes configurations, SSH keys, and other critical information. It also gathers basic system fingerprinting details, like username, IP address, and hostname,” they said.

The packages mostly had benign-looking names like “webpack”, “fixedwidthtable”, and “virtualsearchtable”.

A second set of packages “send HTTP GET requests to specific URLs, scanning for sensitive files and directories containing valuable intellectual property and configuration data, which is then extracted and uploaded to an FTP server.”

Source code and configuration files were captured by these packages, along with directories containing sensitive information like application and service credentials.

In all, Fortiguard identified nine groups of malicious npm packages with similar behaviours.

The nefarious activity was mostly hidden in install scripts that ran whenever the malicious package ran, Fortiguard said.

Malware remains a persistent problem for public software registries; npm was found to be hosting bad actors’ packages last year, and again earlier this year.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
fortiguard npm security software

Related Articles

  • AI governance must evolve alongside adoption in APAC
  • 2026 a pivotal year for enterprises to deliver real value from AI
  • AI is triggering a structural reset in enterprise IT strategy
  • Beware the pitfalls of using a ‘DIY security’ approach
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Beware the pitfalls of using a ‘DIY security’ approach

Beware the pitfalls of using a ‘DIY security’ approach

AI transforms cyberattacks, but human trust remains the weakest link

AI transforms cyberattacks, but human trust remains the weakest link

Zuellig Pharma launches Asia's first healthcare data exchange platform

Zuellig Pharma launches Asia's first healthcare data exchange platform

Toyota's Indian unit warns of a possible customer data breach

Toyota's Indian unit warns of a possible customer data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.