Two malicious packages, discovered in the npm package repository, were found to hide an open-source information-stealing malware named TurkoRat.
See also: Hackers target vulnerable WordPress Elementor plugin after Proof-of-Concept release

The packages – named nodejs-encrypt-agent and nodejs-cookie-proxy-agent – were downloaded a total of about 1,200 times and were available for more than two months before being detected and removed.
See also: Apple: Fixes three new zero-days that hack iPhones and Macs
ReversingLabs, which analyzed the campaign details, described TurkoRat as an information thief capable of collecting sensitive information such as login credentials, website cookies, and data from cryptocurrency wallets.
While the nodejs-encrypt-agent was equipped with malicious software inside, the nodejs-cookie-proxy-agent was found to be disguising the trojan as a dependency named axios-proxy.
The nodejs-encrypt-agent was also designed to masquerade as another legitimate npm module known as agent-base, which has been downloaded over 25 million times to date.
The list of rogue packages and their respective versions are listed below –
- nodejs-encrypt-agent (versions 6.0.2, 6.0.3, 6.0.4, and 6.0.5)
- nodejs-cookie-proxy-agent (versions 1.1.0, 1.2.0, 1.2.1, 1.2.2, 1.2.3, and 1.2.4), and
- axios-proxy (versions 1.7.3, 1.7.4, 1.7.7, 1.7.9, 1.8.9, and 1.9.9)
The findings underscore once again the ongoing risk that threat actors are breeding, who orchestrate attacks on the supply chain through open-source packages and lure developers into downloading potentially untrusted code.
The growing use of malicious npm packages is part of a broader pattern of increasing attacker interest in open-source software supply chains.
Even more concerning is the fact that researchers from Checkmarx published a new study this month, which showed how threat actors can impersonate authentic NPM packages “using lowercase letters to mimic the uppercase letters in the initial names of the packages” (e.g., MemoryStorageDriver versus memorystoragedriver).
The supply chain security company found that 1,900 of the 3,815 packages with capital letters in their titles could be at risk from copycat attacks unless a fix promoted by npm maintainers to address the issue was present.
The disclosure also follows another advisory from Check Point, which identified three malicious extensions hosted on the VS Code Extensions Marketplace. These have been cleared since May 14, 2023.
The add-ons, named prettiest java, Darcula Dark, and python-vscode, were cumulatively downloaded over 46,000 times and incorporated features that allowed threat actors to steal credentials, system information , and create a remote shell on the victim's computer.
See also: Vulnerability in KeePass extracts password
It's not only the npm and VS Code market, because a similar set of rogue libraries has also been discovered from the Python Package Index (PyPI) software repository.
Some of these packages were designed to distribute malicious software that steals cryptocurrency named KEKW, while other releases of the popular Flask framework that performed typosquatting included backdoor functionalities for receiving commands from a remote server.
Another Python package discovered by the Israeli company Phylum this week was found to contain a malicious dependency that hosted an encrypted payload, which was designed to hijack Discord tokens and steal the contents of the clipboard, in order to siphon cryptocurrency transactions.
The package, referred to as chatgpt-api by its developer Patrick Pogoda and accessible via GitHub, provided the functionality it advertised (i.e., interaction with the OpenAI ChatGPT tool) in an attempt to complete the trick. The repository is still available at the time of writing.
Information source: thehackernews.com
