HomeSecurityCompromised S3 buckets are used in attacks on npm packages

Compromised S3 buckets used in attacks on npm packages

Hacked S3 buckets are used in attacks on npm packages.

Hackers are using expired Amazon Web Services (AWS) S3 buckets to place malicious code into a legitimate package in the npm repository without having to tamper with the code.

Software security firm Checkmarx said it began investigating after GitHub published an advisory late last month about various versions of an npm package called bignum, which had been hijacked by cybercrooks and was serving malicious binaries that stole information such as user IDs, passwords and local host names from victims' systems

InfoSec engineers wrote a report describing the issue, noting that while the BigNum package threat was mitigated with a new release, they found that dozens of other open source packages in the NPM code repository were vulnerable to the same attack.

Compromised S3 buckets used in attacks on npm packages

Code repositories under attack

This latest threat is part of a growing trend of groups looking at the software supply chain as an easy way to deploy their malware and help it quickly reach a broad base of potential victims. Through attacks on npm and other repositories like GitHub, the Python Package Index (PyPI), and RubyGems, the bad guys are trying to place their malicious code into packages that are then downloaded by developers and used in their applications.

In this case, they found their way through abandoned S3 buckets, which are part of AWS’s object storage services that allow organizations to store and retrieve vast amounts of data – files, documents, and images, among other digital content – ​​in the cloud. These buckets are accessed via unique URLs and are used for tasks like hosting websites and backing up data.

The bignum package used node-gyp, a command-line tool written in Node.js, to download a binary file that was originally hosted in an S3 bucket. If the bucket was not accessible, the package was asked to search locally for the binary file.

S3

Theft and export of credentials

The malicious binary worked like the original, but also stole credentials and sent them to the hijacked bucket, with the data being extracted via a GET request. It was a compiled C/C++ binary that was called in JavaScript, supporting both JavaScript and C/C++ libraries, which allowed Node.js modules to access lower-level code and expand the attack surface.

Information source: theregister.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS