HomeSecurityFour malicious npm packages with infostealers and DDoS malware

Four malicious npm packages with infostealers and DDoS malware

Four malicious npm packages have been discovered by cybersecurity researchers containing infostealer malware and DDoS botnet functionality, with one of them being a clone of the Shai-Hulud worm recently leaked by TeamPCP. The discovery highlights the growing threat of supply chain attacks targeting developers through the npm, exploiting the trust developers place in public repositories.

npm infostealers DDoS

The four malicious npm packages detected are chalk -tempalte with 825 downloads, @deadcode09284814/axios-util with 284 downloads, axois-utils with 963 downloads , and color-style-utils with 934 downloads. All packages were published by the same user named deadcode09284814, but contain different malicious payloads, suggesting a coordinated and multi-layered attack. The total impact reaches 3,006 downloads, a number that may seem small but in reality represents thousands of potentially infected development environments.

How malicious npm packages work

According to OX Security, the chalk-tempalte contains a clone of the Shai-Hulud source code leaked by TeamPCP last week. The incident demonstrates how quickly cybercriminals can reuse leaked malware for new attacks, creating a dangerous cycle of threat reproduction.

See also: ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

The axois-utils package was designed to deliver a Golang-based DDoS botnet , called Phantom Bot . This malware has the ability to flood a target using HTTP , TCP , and UDP protocols. In addition, it installs persistence mechanisms on both Windows and Linux systems , adding the payload to the Windows Startup folder and creating scheduled tasks.

The remaining three npm packages install stealer payloads on victims' systems using highly sophisticated techniques. As we mentioned earlier, chalk-tempalte contains the clone of the Shai-Hulud worm . As OX Security reports, the perpetrator took the code and uploaded a working version with his own C2 server and private key to npm with almost no changes .

The stolen credentials are sent to the remote C2 server at 87e0bbc636999b.lhr[.]life. Additionally, the data is exported to a new public GitHub repository using the stolen GitHub token via the API. The repository is given the description “A Mini Sha1-Hulud has Appeared”, which facilitates the identification of infected systems but also acts as a “signature” of the attacker. This tactic of creating public repositories with stolen data is a new and worrying development in the field of supply chain attacks.

See also: 'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

The other two npm packages, @deadcode09284814/axios-util and color-style-utils, have simpler but equally dangerous functionality that steals SSH keys, environment variables, cloud credentials, system information, IP , and cryptocurrency wallet data. The data is sent to the addresses 80.200.28[.]28:2222 and edcf8b03c84634.lhr[.]life respectively. The targeting of cloud credentials and SSH keys is particularly concerning, as it can lead to lateral movement and privilege escalation in corporate environments.

Four malicious npm packages with infostealers and DDoS malware

Protection

To protect against such threats, organizations should implement software composition analysis tools that scan dependencies for known vulnerabilities and suspicious behavior. Additionally, it is recommended to use package-lock.json files to ensure release stability, implement npm audit on a regular basis, and create private npm registries for critical applications. Developers should also verify package names carefully before installation and avoid packages with suspicious names or low download counts.

See also: Malicious Laravel Packages on Packagist Install RAT

OX Security researchers warn that threat actors are increasingly conducting supply chain and typo-squatting attacks, as attacks become easier with the Shai-Hulud code becoming open source . We are now seeing a single actor with multiple techniques and infostealer types spreading malicious code on npm . This is just the first phase of an upcoming wave of supply chain attacks. This prediction is supported by the increasing frequency of such attacks and the ease with which criminals can now gain access to sophisticated malware frameworks.

Users who have downloaded the malicious npm packages should uninstall them immediately, find and delete malicious configurations from IDEs and coding agents, rotate secrets, check for GitHub repositories containing the string “A Mini Sha1-Hulud has Appeared,” and block network access to suspicious domains.

Continuous training of developers on security threats and creating a culture of security awareness are critical elements in addressing these evolving threats.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS