HomeSecurityBeware! New malware campaign distributes the Skuld info-stealer

Beware! New malware campaign distributes Skuld info-stealer

Security researchers have discovered a new malware campaign that distributes the Skuld info-stealer via malicious packages, posing as legitimate tools. The hackers behind this campaign are tracked as “k303903” and have compromised hundreds of machines.

Beware! New malware campaign distributes Skuld info-stealer

Subsequent analysis revealed that the “k303903” group likely also operates under the aliases “shegotit2” and “pressurized.” In all cases, identical or very similar tactics, techniques, and procedures (TTPs) for infiltrating the npm ecosystem with malware have been identified.

A recent malicious campaign targeting npm developers delivered the Skuld info-stealer malware. This attack closely resembles a previous attack on Roblox developers.

Threat actors used typosquatting and obfuscation techniques to compromise development machines and steal sensitive data.

See also: Hacker jailed for his involvement in Raccoon Stealer malware

The December campaign leveraged common development methods and relied on commodity malware, highlighting the consistent use of deceptive tactics by these threat actors.

The code snippet reveals a malicious download and execution process. Libraries such as “fs-extra”, “path”, “node-fetch”, and “child_process” are used to download a malicious binary from a URL that has been disguised to appear legitimate. The binary is then executed.

Researchers observed that Obfuscator.io was used to obfuscate the code, making detection difficult. Once installed, the malware retrieves and executes the final payload (Skuld info stealer malware) under the filename download.exe.

The hacking group k303903 used typosquatting to upload malicious npm packages (that looked like popular libraries), which tricked developers into installing them . As a result, data could be extracted via a Discord webhook.

The use of seemingly legitimate commands and trusted services (replit.dev) further conceals malicious intent, which highlights the importance of carefully reviewing the package before installation.

See also: Hackers use RedLine Stealer to steal credentials

Malicious npm packages were downloaded more than 600 times, stealing credentials and sensitive data from users. Despite the swift removal of the npm registry, the impact was significant.

To mitigate these risks, developers should implement a layered security approach. Using automated tools can help proactively detect and identify malicious dependencies within the development lifecycle, intercepting threats before they compromise systems.

Skuld info-stealer malware

General tips for protection against info-stealer malware like Skuld

First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from these types of attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.

See also: macOS Malware Banshee Stealer Source Code Leaked

Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.

Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS