HomeSecurityMalicious NPM package uses Unicode steganography

Malicious NPM package uses Unicode steganography

A malicious package in the Node Package Manager (NPM) uses invisible Unicode characters to hide malicious code, while leveraging Google Calendar links to host the command-and-control point URL.

See also: Supply chain attack hits npm package rand-user-agent

NPM Unicode package

The package, named os-info-checker-es6, is presented as an information utility and has been downloaded over 1,000 times since the beginning of the month.

Researchers at Veracode, a software security assessment firm, found that the first version of the package was added to the NPM catalog on March 19 and was harmless, only collecting information about the operating system . The package creator added modifications a few days later, incorporating platform-specific executables and disguised installation scripts.

A new version of the package was published on May 7, which includes code for a “complex command and control (C2) mechanism” that delivers the final malicious payload. The latest available version of os-info-checker-es6 on npm is v1.0.8 and is malicious, Veracode warns.

Additionally, this particular package is declared as a dependency on four other NPM packages: skip-tot, vue-dev-serverr, vue-dummyy , and vue-bit — all presented as tools for accessibility and cross-platform development.

It remains unclear whether or how these packets are being forwarded by the threat actor. In the malicious version, the attacker embeds data inside what appears to be a string with a '|' (slash) character. However, it is followed by a long sequence of invisible Unicode characters from the Variation Selectors Supplement (U+E0100 to U+E01EF).

These Unicode characters normally function as modifiers, usually to provide letter variations in complex writing systems. In this case, they are used to implement text steganography — that is, hiding information within other data.

See also: Malicious npm package targets Atomic Wallet and Exodus

Veracode decrypted and decoded the string, identifying a payload that is part of a sophisticated command and control (C2) mechanism that relies on a short Google Calendar link to reach the location hosting the final malware.

Malicious NPM package uses Unicode steganography
Malicious NPM package uses Unicode steganography

The researchers explain that after retrieving the Google Calendar link, the malware follows a series of redirects until it receives an HTTP 200 OK response . It then extracts the content of the data-base-title attribute from the event HTML page, which contains a base64 -encoded URL that leads to the final payload.

Using a function called ymmogvj, the URL is decoded and the malicious payload is revealed. According to the researchers, the request expects a base64-encoded second-stage malicious payload in the response body, as well as possibly an initializer vector (IV) and a secret key in the HTTP headers – suggesting possible encryption of the final payload.

Veracode also found that the malicious payload is executed via the eval(). The script includes a simple persistence mechanism in the system's temporary directory, which prevents multiple processes from running concurrently.

During analysis, researchers were unable to recover the final payload, suggesting that the malicious campaign may be paused or still in its early stages. Despite Veracode reporting its findings to NPM, the suspicious packages are still available on the platform.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Malicious NPM packages target PayPal users

Based on the above, a worrying phenomenon arises regarding the security of the software supply chain. The case of os-info-checker-es6 is a typical example of a malicious open source package that exploits developers' trust in widely used ecosystems such as npm.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS