HomeCyber BalkansNpm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Npm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Published on

spot_img

A new report has found that some malicious software is being distributed via trusted software repositories, despite efforts to monitor them. Recently, two packages containing the TurkoRat trojan remained undetected in the repositories for more than two months. The packages relied on typosquatting, where malicious code is added to a legitimate software package, which is then published with a similar name. Researchers, at ReversingLabs, discovered two legitimate-looking packages; nodejs-encrypt-agent and nodejs-cookie-proxy-agent; that contained unexpected behaviour. The two packages were downloaded 500 and 700 times respectively and were almost certainly responsible for TurkoRat being spread. The malware is designed to steal login credentials and cryptocurrencies from infected machines; it is also capable of taking screenshots. Compromised developer machines can give hackers access to the software development tools and infrastructure of the organisations that the developer works for, leading to a cascade of software supply chain attacks.

Source link

Latest articles

Ask Me Anything Cyber – CyberMaterial

On July 23, 2026, the cybersecurity community will convene for an engaging discussion titled...

Ask Me Anything: Cyber – CyberMaterial

Upcoming Live Event: "Ask Me Anything Cyber" On July 30, 2026, cybersecurity enthusiasts and professionals...

Bearlyfy Aims at Over 70 Companies with Ransomware

Emergence of Bearlyfy: A New Force in Cyber Warfare Against Russian Enterprises In the evolving...

LangChain and LangGraph Vulnerabilities Expose Data

Critical Security Flaws Discovered in LangChain and LangGraph Frameworks Recent investigations by security experts have...

More like this

Ask Me Anything Cyber – CyberMaterial

On July 23, 2026, the cybersecurity community will convene for an engaging discussion titled...

Ask Me Anything: Cyber – CyberMaterial

Upcoming Live Event: "Ask Me Anything Cyber" On July 30, 2026, cybersecurity enthusiasts and professionals...

Bearlyfy Aims at Over 70 Companies with Ransomware

Emergence of Bearlyfy: A New Force in Cyber Warfare Against Russian Enterprises In the evolving...