HomeSecurityNPM: 'Supposed' speed tester packages installed crypto miners!

NPM: 'Supposed' speed tester packages installed crypto miners!

Security researchers at Check Point recently discovered 16 malicious NPM packages that claimed to be online speed testers, but were actually doing what most people know – crypto mining.

 NPM is an online repository that contains over 2.2 million open source JavaScript packages.

See also: MortalKombat ransomware: Targeting systems in the US

NPM: 'Supposed' speed tester packages installed crypto miners!
NPM: 'Supposed' speed tester packages installed crypto miners!

The packages, which were uploaded to NPM on January 17, 2023, are the work of a user named “trendava.” The purpose of these packages is to grab available resources from infected computers and start crypto mining for their own benefit. The NPM platform removed these packages the very next day after being notified by Check Point, but the presence of these attacks in the supply chain highlights the importance of software developers thoroughly checking the code in any package they may use in their programs. Most of the packages all had names that resembled speed testers. However, Check Point analysts found that each package uses different coding and methods to complete its “plans”. For example, the “ speedtestspa ” package downloads a utility file from GitLab to connect to a mining pool, while “ speedtestkas ” includes the malicious utility file. The “speedtestbom” package tries to hide the address of the mining pool. In contrast, the “ speedtesto ” package includes the code of a genuine speed testing program, which offers the promised functionality to the unsuspecting user. See also: New pig butchering scam promises profits from gold investments











Check Point NPM speed testers crypto miners packages
NPM: 'Supposed' speed tester packages installed crypto miners!

Check Point analysts noted that the differences in coding are likely related to the so-called “trial and error” method, in their attempt to find the most effective way to hide their activities from security programs.

In a separate incident, researchers at Phylum revealed that they found 451 malicious typosquatting packages on “PyPI”, a repository Python packages, which installed a password-stealing malware.

To avoid such attacks in the supply chain, developers should resort only to trusted sources, as well as publishers.
Validate names to avoid installing malicious typosquatting packages and check the code of packages used in their programs.

Source of information: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS