HomeinetNpm contained malware that uploaded user data to GitHub

Npm contained malware that uploaded user data to GitHub

Four JavaScript npms contained malware that collected user data and uploaded it to a public page on GitHub.

The four packages where this malicious code was detected were:

  • electorn: 255 downloads
  • lodashs: 78 downloads
  • loadyaml: 48 downloads
  • loadyml: 37 downloads

All four packages were developed by the same user (simplelive12) and uploaded to the npm portal in August. Two packages (lodashs, loadyml) were removed by the author shortly after publication, but had already infected some users.

The remaining packages, electorn and loadyaml, were removed last week, on October 1, by the security after a report from Sonatype, a company that monitors “public package repositories” as part of DevSecOps (a set of practices that combines software development and IT operations).

GitHub malware

According to Sonatype security researcher Ax Sharma, the four malicious packages used a technique known as typosquatting to install themselves.

All four had similar names to the most popular packages and were based on users making mistakes when typing the name of a popular package.

When a developer accidentally installed one of the four malicious packages, the malicious code collected the developer's IP address , country, city , computer username , home directory path, and CPU model information and published this information as a new comment in the "Issues" section of a GitHub repository.

Sharma said the data will not remain on GitHub for a long time and will be purged every 24 hours.

Although we may not know what the ultimate goal of this campaign was, it is very likely that we are seeing a reconnaissance operation.

Information such as IP addresses, usernames, and home directory paths can reveal whether a user is working from home or in a corporate environment. Data such as home directory path and CPU can also help attackers develop malware for a specific architecture.

All the attacker would have to do was push a subsequent update to the electorn and loadyaml packages with additional malicious code.

It is recommended that developers review their project's dependencies and see if they accidentally used one of the four packages.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS