Skip to content
  • Kategorien
  • Aktuell
  • Tags
  • Beliebt
  • World
  • Benutzer
  • Gruppen
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Standard: (Kein Skin)
  • Kein Skin
Einklappen

other.li Forum

  1. Übersicht
  2. Uncategorized
  3. Malicious javascript compromise on npmjs.com

Malicious javascript compromise on npmjs.com

Geplant Angeheftet Gesperrt Verschoben Uncategorized
13 Beiträge 1 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    schrieb zuletzt editiert von
    #1

    Malicious javascript compromise on npmjs.com

    These packages, about a billion downloads prior

    supports-hyperlinks
    chalk-template
    simple-swizzle
    slice-ansi
    error-ex
    is-arrayish
    wrap-ansi
    backslash
    color-string
    color-convert
    color
    color-name

    Thread follows.

    gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      Malicious javascript compromise on npmjs.com

      These packages, about a billion downloads prior

      supports-hyperlinks
      chalk-template
      simple-swizzle
      slice-ansi
      error-ex
      is-arrayish
      wrap-ansi
      backslash
      color-string
      color-convert
      color
      color-name

      Thread follows.

      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      schrieb zuletzt editiert von
      #2

      Example change and download stats on one of the 12 packages changed, incident started about 2 hours ago.

      gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        Example change and download stats on one of the 12 packages changed, incident started about 2 hours ago.

        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.socialG This user is from outside of this forum
        gossithedog@cyberplace.social
        schrieb zuletzt editiert von
        #3

        Example copy of one of the inserted JS: https://pastebin.com/bwLZrq02

        gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          Example copy of one of the inserted JS: https://pastebin.com/bwLZrq02

          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.socialG This user is from outside of this forum
          gossithedog@cyberplace.social
          schrieb zuletzt editiert von
          #4

          Just reported to NPM, they work on it.

          gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            Just reported to NPM, they work on it.

            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.socialG This user is from outside of this forum
            gossithedog@cyberplace.social
            schrieb zuletzt editiert von
            #5

            Derek's caught it too https://infosec.exchange/@derekheld/115169311485030806

            gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              Derek's caught it too https://infosec.exchange/@derekheld/115169311485030806

              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.socialG This user is from outside of this forum
              gossithedog@cyberplace.social
              schrieb zuletzt editiert von
              #6

              It's a cryptocurrency wallet drainer, RIP a load of devops dudes crypto.

              gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                It's a cryptocurrency wallet drainer, RIP a load of devops dudes crypto.

                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.socialG This user is from outside of this forum
                gossithedog@cyberplace.social
                schrieb zuletzt editiert von
                #7

                NPM on it, some packages nuked, more being nuked

                gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  NPM on it, some packages nuked, more being nuked

                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.socialG This user is from outside of this forum
                  gossithedog@cyberplace.social
                  schrieb zuletzt editiert von
                  #8

                  If you want an idea of scale of trojan attempt - 'color' alone had 32m downloads in a week, the combined attempt was pushing a billion due to upstream dependencies.

                  Hunt tip: look for registry.npmjs.org in proxy logs, package names are in the URLs.

                  gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    If you want an idea of scale of trojan attempt - 'color' alone had 32m downloads in a week, the combined attempt was pushing a billion due to upstream dependencies.

                    Hunt tip: look for registry.npmjs.org in proxy logs, package names are in the URLs.

                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.socialG This user is from outside of this forum
                    gossithedog@cyberplace.social
                    schrieb zuletzt editiert von
                    #9

                    additional backdoored packages

                    ansi-styles
                    debug
                    chalk
                    supports-color
                    strip-ansi
                    ansi-regex
                    has-ansi

                    gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      additional backdoored packages

                      ansi-styles
                      debug
                      chalk
                      supports-color
                      strip-ansi
                      ansi-regex
                      has-ansi

                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.socialG This user is from outside of this forum
                      gossithedog@cyberplace.social
                      schrieb zuletzt editiert von
                      #10

                      Weekly download stats for impacted packages prior to incident

                      ansi-styles (371.41m)
                      debug (357.6m)
                      backslash (0.26m)
                      chalk-template (3.9m)
                      supports-hyperlinks (19.2m)
                      has-ansi (12.1m)
                      simple-swizzle (26.26m)
                      color-string (27.48m)
                      error-ex (47.17m)
                      color-name (191.71m)
                      is-arrayish (73.8m)
                      slice-ansi (59.8m)
                      color-convert (193.5m)
                      wrap-ansi (197.99m)
                      ansi-regex (243.64m)
                      supports-color (287.1m)
                      strip-ansi (261.17m)
                      chalk (299.99m)

                      Total 2674m

                      gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        Weekly download stats for impacted packages prior to incident

                        ansi-styles (371.41m)
                        debug (357.6m)
                        backslash (0.26m)
                        chalk-template (3.9m)
                        supports-hyperlinks (19.2m)
                        has-ansi (12.1m)
                        simple-swizzle (26.26m)
                        color-string (27.48m)
                        error-ex (47.17m)
                        color-name (191.71m)
                        is-arrayish (73.8m)
                        slice-ansi (59.8m)
                        color-convert (193.5m)
                        wrap-ansi (197.99m)
                        ansi-regex (243.64m)
                        supports-color (287.1m)
                        strip-ansi (261.17m)
                        chalk (299.99m)

                        Total 2674m

                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.socialG This user is from outside of this forum
                        gossithedog@cyberplace.social
                        schrieb zuletzt editiert von
                        #11

                        Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

                        gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                        0
                        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                          Phishing email sent to maintainers, they basically targeted people with 2FA by getting them to.. reset their 2FA.

                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.socialG This user is from outside of this forum
                          gossithedog@cyberplace.social
                          schrieb zuletzt editiert von
                          #12

                          Developer confirms they fell for phishing email

                          It looks like others have too, found one other compromised repo from a different user, will have a dig tomorrow as bored of cyber tonight.

                          https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y

                          gossithedog@cyberplace.socialG 1 Antwort Letzte Antwort
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            Developer confirms they fell for phishing email

                            It looks like others have too, found one other compromised repo from a different user, will have a dig tomorrow as bored of cyber tonight.

                            https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y

                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.socialG This user is from outside of this forum
                            gossithedog@cyberplace.social
                            schrieb zuletzt editiert von
                            #13

                            For anybody confused about how this happens, basically:

                            - For about the past 15 years every business has been developing apps by pulling in 178 interconnected libraries written by 24 people in a shed in Skegness

                            - For about the past 2 years orgs have been buying AI vibe coding tools, where some exec screams "make online shop" into a computer and 389 libraries are added and an app is farted out

                            The output = if you want to own the world's companies, just phish one guy in Skegness

                            1 Antwort Letzte Antwort
                            0
                            • monkee@other.liM monkee@other.li shared this topic
                            Antworten
                            • In einem neuen Thema antworten
                            Anmelden zum Antworten
                            • Älteste zuerst
                            • Neuste zuerst
                            • Meiste Stimmen


                            • Anmelden

                            • Anmelden oder registrieren, um zu suchen
                            • Erster Beitrag
                              Letzter Beitrag
                            0
                            • Kategorien
                            • Aktuell
                            • Tags
                            • Beliebt
                            • World
                            • Benutzer
                            • Gruppen