HomeCyber BalkansNpm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Npm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Published on

spot_img

A new report has found that some malicious software is being distributed via trusted software repositories, despite efforts to monitor them. Recently, two packages containing the TurkoRat trojan remained undetected in the repositories for more than two months. The packages relied on typosquatting, where malicious code is added to a legitimate software package, which is then published with a similar name. Researchers, at ReversingLabs, discovered two legitimate-looking packages; nodejs-encrypt-agent and nodejs-cookie-proxy-agent; that contained unexpected behaviour. The two packages were downloaded 500 and 700 times respectively and were almost certainly responsible for TurkoRat being spread. The malware is designed to steal login credentials and cryptocurrencies from infected machines; it is also capable of taking screenshots. Compromised developer machines can give hackers access to the software development tools and infrastructure of the organisations that the developer works for, leading to a cascade of software supply chain attacks.

Source link

Latest articles

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

 Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS...

More like this

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...