Skip to content
  • Kategorien
  • Aktuell
  • Tags
  • Beliebt
  • World
  • Benutzer
  • Gruppen
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Standard: (Kein Skin)
  • Kein Skin
Einklappen

other.li Forum

  1. Übersicht
  2. Uncategorized
  3. Malicious javascript compromise on npmjs.com

Malicious javascript compromise on npmjs.com

Geplant Angeheftet Gesperrt Verschoben Uncategorized
13 Beiträge 1 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

    Example copy of one of the inserted JS: https://pastebin.com/bwLZrq02

    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    schrieb zuletzt editiert von
    #4

    Just reported to NPM, they work on it.

    gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Just reported to NPM, they work on it.

      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      schrieb zuletzt editiert von
      #5

      Derek's caught it too https://infosec.exchange/@derekheld/115169311485030806

      gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Derek's caught it too https://infosec.exchange/@derekheld/115169311485030806

        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        schrieb zuletzt editiert von
        #6

        It's a cryptocurrency wallet drainer, RIP a load of devops dudes crypto.

        gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          It's a cryptocurrency wallet drainer, RIP a load of devops dudes crypto.

          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          schrieb zuletzt editiert von
          #7

          NPM on it, some packages nuked, more being nuked

          gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            NPM on it, some packages nuked, more being nuked

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            schrieb zuletzt editiert von
            #8

            If you want an idea of scale of trojan attempt - 'color' alone had 32m downloads in a week, the combined attempt was pushing a billion due to upstream dependencies.

            Hunt tip: look for registry.npmjs.org in proxy logs, package names are in the URLs.

            gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              If you want an idea of scale of trojan attempt - 'color' alone had 32m downloads in a week, the combined attempt was pushing a billion due to upstream dependencies.

              Hunt tip: look for registry.npmjs.org in proxy logs, package names are in the URLs.

              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.social
              schrieb zuletzt editiert von
              #9

              additional backdoored packages

              ansi-styles
              debug
              chalk
              supports-color
              strip-ansi
              ansi-regex
              has-ansi

              gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                additional backdoored packages

                ansi-styles
                debug
                chalk
                supports-color
                strip-ansi
                ansi-regex
                has-ansi

                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                schrieb zuletzt editiert von
                #10

                Weekly download stats for impacted packages prior to incident

                ansi-styles (371.41m)
                debug (357.6m)
                backslash (0.26m)
                chalk-template (3.9m)
                supports-hyperlinks (19.2m)
                has-ansi (12.1m)
                simple-swizzle (26.26m)
                color-string (27.48m)
                error-ex (47.17m)
                color-name (191.71m)
                is-arrayish (73.8m)
                slice-ansi (59.8m)
                color-convert (193.5m)
                wrap-ansi (197.99m)
                ansi-regex (243.64m)
                supports-color (287.1m)
                strip-ansi (261.17m)
                chalk (299.99m)

                Total 2674m

                gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  Weekly download stats for impacted packages prior to incident

                  ansi-styles (371.41m)
                  debug (357.6m)
                  backslash (0.26m)
                  chalk-template (3.9m)
                  supports-hyperlinks (19.2m)
                  has-ansi (12.1m)
                  simple-swizzle (26.26m)
                  color-string (27.48m)
                  error-ex (47.17m)
                  color-name (191.71m)
                  is-arrayish (73.8m)
                  slice-ansi (59.8m)
                  color-convert (193.5m)
                  wrap-ansi (197.99m)
                  ansi-regex (243.64m)
                  supports-color (287.1m)
                  strip-ansi (261.17m)
                  chalk (299.99m)

                  Total 2674m

                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  schrieb zuletzt editiert von
                  #11

                  Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

                  gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    schrieb zuletzt editiert von
                    #12

                    Developer confirms they fell for phishing email

                    It looks like others have too, found one other compromised repo from a different user, will have a dig tomorrow as bored of cyber tonight.

                    https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y

                    gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      Developer confirms they fell for phishing email

                      It looks like others have too, found one other compromised repo from a different user, will have a dig tomorrow as bored of cyber tonight.

                      https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y

                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      schrieb zuletzt editiert von
                      #13

                      For anybody confused about how this happens, basically:

                      - For about the past 15 years every business has been developing apps by pulling in 178 interconnected libraries written by 24 people in a shed in Skegness

                      - For about the past 2 years orgs have been buying AI vibe coding tools, where some exec screams "make online shop" into a computer and 389 libraries are added and an app is farted out

                      The output = if you want to own the world's companies, just phish one guy in Skegness

                      1 Antwort Letzte Antwort
                      0
                      • monkee@other.liM monkee@other.li shared this topic
                      Antworten
                      • In einem neuen Thema antworten
                      Anmelden zum Antworten
                      • Älteste zuerst
                      • Neuste zuerst
                      • Meiste Stimmen


                      • Anmelden

                      • Anmelden oder registrieren, um zu suchen
                      • Erster Beitrag
                        Letzter Beitrag
                      0
                      • Kategorien
                      • Aktuell
                      • Tags
                      • Beliebt
                      • World
                      • Benutzer
                      • Gruppen