iTnews Asia
  • Home
  • News
  • Security

Malware once again a headache for npm

Malware once again a headache for npm

Fortiguard finds data-thieving packages.

By Richard Chirgwin on Oct 4, 2023 10:32AM

Fortiguard Labs is warning of a bunch of malicious packages it found in Node Package Manager (npm), the largest JavaScript software registry.

In an October 2 blog post, Fortiguard’s Jin Lee and Jenna Wang said the packages aim “to steal sensitive data, such as system or user information, via a webhook or file-sharing link”.

Lee and Wang said they identified some packages that, “while obfuscated, exfiltrate sensitive data”. 

That included “Kubernetes configurations, SSH keys, and other critical information. It also gathers basic system fingerprinting details, like username, IP address, and hostname,” they said.

The packages mostly had benign-looking names like “webpack”, “fixedwidthtable”, and “virtualsearchtable”.

A second set of packages “send HTTP GET requests to specific URLs, scanning for sensitive files and directories containing valuable intellectual property and configuration data, which is then extracted and uploaded to an FTP server.”

Source code and configuration files were captured by these packages, along with directories containing sensitive information like application and service credentials.

In all, Fortiguard identified nine groups of malicious npm packages with similar behaviours.

The nefarious activity was mostly hidden in install scripts that ran whenever the malicious package ran, Fortiguard said.

Malware remains a persistent problem for public software registries; npm was found to be hosting bad actors’ packages last year, and again earlier this year.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
fortiguard npm security software

Related Articles

  • Why is fragmentation the next big cybersecurity risk?
  • The maritime sector is now in the crosshairs of cybercriminals
  • Thai Airways launches digital loyalty transformation
  • Tips on how to harness AI to transform your DDoS protection into proactive cyber defence
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

The maritime sector is now in the crosshairs of cybercriminals

The maritime sector is now in the crosshairs of cybercriminals

Why is fragmentation the next big cybersecurity risk?

Why is fragmentation the next big cybersecurity risk?

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Tips on how to harness AI to transform your DDoS protection into proactive cyber defence

Malaysia secures communications for the upcoming ASEAN Summit

Malaysia secures communications for the upcoming ASEAN Summit

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.