HomeSecurity60 malicious npm packages collect sensitive network data

60 malicious npm packages collect sensitive network data

A sophisticated malware campaign targeting the npm ecosystem has compromised development environments through 60 malicious packages, which are designed to silently collect sensitive network data.

See also: Malicious NPM package uses Unicode steganography

npm packages network data

The operation, which began eleven days ago and remains active to this day, highlights the growing threat to supply chains through compromised open source packages.

The malicious packages originate from three npm accounts and have amassed over 3,000 downloads, creating an extensive network of recognition for the attackers. Each package contains identical scripts that are automatically executed after installation via npm, targeting Windows, macOS, and Linux operating systemson developer workstations and continuous integration environments.

Socket.dev researchers detected the campaign through their threat detection systems, revealing that the malware collects hostnames, internal and external IP addresses, DNS server settings , and user paths, before sending this data to a webhook controlled via Discord.

See also: Supply chain attack hits npm package rand-user-agent

The persistence and scale of the operation indicate a well-coordinated mechanism aimed at mapping corporate networks and identifying high-value targets for future attacks.

60 malicious npm packages collect sensitive network data
60 malicious npm packages collect sensitive network data

The attackers published packages through three accounts, with registration emails following the pattern npm9960+[1-3]@gmail.com, and each included exactly twenty malicious packages with legitimate-sounding names, such as “react-xterm2,” “seatable ,” and “garena-admin.” Combined with the rapid publication schedule and identical malicious payloads, this suggests systematic automation in the execution of the campaign.

The extracted data offers attackers extensive network mapping capabilities, connecting private development environments with public infrastructure and revealing organizational relationships that could facilitate targeted breaches.

On continuous integration (CI) servers, malware exposes internal package registry URLs and build paths, information particularly valuable for subsequent attacks in the software supply chain.

See also: Malicious npm package targets Atomic Wallet and Exodus

Based on the above, it is clear that software supply chain attacks are one of the most sophisticated and worrying forms of cyberthreat today. The fact that perpetrators exploit the trust in the open source community – through packages on npm with seemingly legitimate names – makes the attacks particularly insidious and difficult to detect.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS