HomeSecurityHackers target developers with 35 malicious npm packages

Hackers target developers with 35 malicious npm packages

Cybersecurity researchers have uncovered new malicious npm packagesthat are linked to the ongoing Contagious Interview, attributed to North Korean.

Hackers target developers with 35 malicious npm packages

According to a report by Socket, 35 infected packages uploaded via 24 different npm accounts, accumulating over 4,000 downloads. The full list of JavaScript libraries is as follows:

  • react-plaid-sdk
  • sumsub-node-websdk
  • vite-plugin-next-refresh
  • vite-plugin-purify
  • nextjs-insight
  • vite-plugin-svgn
  • node-loggers
  • react-logs
  • reactbootstraps
  • framer-motion-ext
  • serverlog-dispatch
  • mongo-errorlog
  • next-log-patcher
  • vite-plugin-tools
  • pixel-percent
  • test-topdev-logger-v1
  • test-topdev-logger-v3
  • server-log-engine
  • logbin-nodejs
  • vite-loader-svg
  • struct-logger
  • flexible-loggers
  • beautiful-plugins
  • chalk-config
  • jsonpacks
  • jsonspecific
  • jsonsecs
  • util-buffers
  • blur-plugins
  • proc-watch
  • node-orm-mongoose
  • prior-config
  • use-videos
  • lucide-node, and
  • router-parse

See also: 60 malicious npm packages collect sensitive network data

Although the majority have already been withdrawn, some packages remain active on the platform.

The malicious npm packages contain a hex-encoded loader called HexEval. HexEval collects information from the local host and carries a second, more dangerous payload — BeaverTail, a known JavaScript stealer.

From there, the scenario gets more complicated. BeaverTail downloads and executes InvisibleFerret, a Python-based backdoor, which provides remote control and access to sensitive data on infected machines.

This nesting-doll structure, as researcher Kirill Boychenko, makes the campaign extremely difficult to detect (by traditional analysis tools). In another case, a package was observed that incorporated a keylogger, capable of recording every keystroke of the user, highlighting the clear intention of the attackers to adapt their tools depending on the target.

Contagious Interview: North Korea Targets Developers

Contagious Interview, an ongoing hacking campaign first detected by Palo Alto Networks’ Unit 42 in late 2023, is back in the spotlight with these new malicious npm packages. The operation is attributed to North Korean, with the aim of illegally accessing software development environments to steal cryptocurrencies and sensitive data.

See also: Malicious NPM package uses Unicode steganography

The activity has been recorded under many names – including CL-STA-0240, DeceptiveDevelopment, UNC5342, Famous Chollima and Void Dokkaebi – indicating the scope and spread of the operation.

npm packages hackers Contagious Interview

According to the latest reports from Socket, attackers are adopting various methods to trick potential targets into installing malware under the guise of an interview or a Zoom meeting.

The latest tactic focuses on the use of the npm platform, where attackers masquerade as recruiters on LinkedIn and target developers or job seekers. Through misleading messages, they encourage them to participate in supposedly technical tests, providing a link to repositories on GitHub or Bitbucket that contain npm packages with malicious code.

“They target software engineers who are actively looking for work, exploiting the trust that job seekers typically have in recruiters,” Boychenko said. “Fake personas initiate contact, often with premeditated outreach messages and convincing job descriptions.”

Victims are asked to clone malicious projects and run them outside of a containerized environmentduring a supposed interview process. As Socket notes, the campaign is a complex mix of OSINT, malware staging , and social engineeringthat allow attackers to infiltrate software development systems through seemingly legitimate open source tools.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Supply chain attack hits npm package rand-user-agent

One of the most concerning aspects of this trend is the targeting of vulnerable individuals, such as those who are unemployed or seeking remote work opportunities. These individuals may be more likely to fall for scams that promise easy money or job security.

Furthermore, as technology continues to advance and more people rely on the Internet for work, education, and social interaction, the potential for widespread harm through fraud continues to grow. From identity theft to financial fraud , cybercriminals are constantly finding new ways to exploit technology for their own gain.

That's why it's important for both individuals and organizations to stay informed about cybersecurity measures and best practices . This includes using strong passwords, regularly updating software and systems, and paying attention to suspicious emails and websites.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS