Cybersecurity researchers discovered two malicious packages in npm files, which contained backdoor code to execute malicious commands sent from a remote server.

See more: ERP vendor's server hacked to distribute Xctdoor backdoor
The two packages have been downloaded 190 and 48 times respectively and have so far been removed by the npm security team.
"Software supply chain security firm Phylum reported in an analysis that the files contained sophisticated command and control functions, hidden in images, which would be executed during the package installation.".
These packages are designed to mimic a legitimate npm library named aws-s3-object-multipart-copy, but they include a modified version of the “index.js” file that executes a JavaScript (“loadformat.js”).
The JavaScript file, in turn, is designed to process three images — which include the corporate logos of Intel, Microsoft, and AMD. The image containing the Microsoft is used to extract and execute the malicious content.
The code registers the new client with a command-and-control (C2) server by sending the host name and operating system details. It then attempts to execute the hacker's commands, repeating the attempt every five seconds.
In the final stage, the results of the command execution are returned to the hacker via a designated endpoint.

In recent years, we have observed a significant increase in the complexity and number of malicious packages published in open-source ecosystems, as stated by Phylum.
Read also: Malicious advertising campaign spreads Oyster Backdoor
“So because these attacks are so successful, it is of utmost importance for developers and businesses to be fully aware of this fact and to pay extreme attention to the open-source libraries they use.”
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
