Hackers have been spotted spreading trojanized versions of jQuery across platforms including npm, GitHub , and jsDeliv, in a seemingly sophisticated and persistent supply chain attack .

“This attack stands out due to its high variability across packages,” Phylum said in an analysis published last week. “The hacker has cleverly hidden the malware in the rarely used jQuery ‘end’ function, which is called internally by the more popular ‘fadeTo’ function of animation utilities.”
Read more: Mekotio banking trojan targets users in Latin America
So far, 68 packages have been linked to this malicious campaign. These packages were published to the npm registry between May 26 and June 23, 2024, using names such as cdnjquery, footersicons, jquertyi, jqueryxxx, logoo, and sytlesheets, among others.
There is evidence that each of the fake packages was assembled and published manually, due to the large number of packages published by different accounts, differences in naming conventions, the inclusion of personal files, and the extended period of time over which they were uploaded. This contrasts with other commonly observed methods, where hackers typically follow a predetermined pattern that suggests the involvement of an element of automation in the creation and publication of the packages.
According to Phylum, the malicious changes were introduced into a function called “end,” allowing the hacker to trigger website form data on a remote URL.
Further investigation revealed that the trojanized jQuery file is hosted in a GitHub repository associated with an account named “indexsc.” The same file also contains JavaScript with a script that points to the trojanized version.
“It’s worth noting that jsDelivr automatically generates these GitHub URLs without requiring an explicit upload to the CDN,” Phylum said. “Most likely, this is an attempt by the hacker to make the source look more legitimate or to bypass firewalls by using jsDelivr instead of loading the code directly from GitHub.”

See also: GootLoader malware: Returns with a new powerful version
This development comes as Datadog identified a number of packages in the Python Package Index (PyPI) repository that have the ability to download a second-stage binary from a server controlled by the hacker, depending on the CPU.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
