HomeCyber BalkansNpm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Npm Packages Found Hosting TurkoRat Infostealer with Legitimate Appearance

Published on

spot_img

A new report has found that some malicious software is being distributed via trusted software repositories, despite efforts to monitor them. Recently, two packages containing the TurkoRat trojan remained undetected in the repositories for more than two months. The packages relied on typosquatting, where malicious code is added to a legitimate software package, which is then published with a similar name. Researchers, at ReversingLabs, discovered two legitimate-looking packages; nodejs-encrypt-agent and nodejs-cookie-proxy-agent; that contained unexpected behaviour. The two packages were downloaded 500 and 700 times respectively and were almost certainly responsible for TurkoRat being spread. The malware is designed to steal login credentials and cryptocurrencies from infected machines; it is also capable of taking screenshots. Compromised developer machines can give hackers access to the software development tools and infrastructure of the organisations that the developer works for, leading to a cascade of software supply chain attacks.

Source link

Latest articles

Multiple cPanel and WHM Vulnerabilities Allow Root Code Execution and Admin Session Hijacking

cPanel Issues Urgent Security Updates to Address Critical Vulnerabilities in WHM Systems cPanel has recently...

Underground Crypto Theft Operation Extracts $100K

Cryptocurrency-Theft Operation Targets Victims with Browser Hijacking A sophisticated and alarming operation targeting cryptocurrency users...

Hacker Server Exposes Toolkit Used in Viva Aerobus-Linked Intrusion

Detailed Insight Into a Rapid Intrusion Linked to Viva Aerobus A recently uncovered attack staging...

Pentagon Breach Reveals 2.76 Million Social Security Numbers and Military Records

Pentagon Confirms Significant Data Breach Affecting Millions In a troubling revelation, the Pentagon has acknowledged...

More like this

Multiple cPanel and WHM Vulnerabilities Allow Root Code Execution and Admin Session Hijacking

cPanel Issues Urgent Security Updates to Address Critical Vulnerabilities in WHM Systems cPanel has recently...

Underground Crypto Theft Operation Extracts $100K

Cryptocurrency-Theft Operation Targets Victims with Browser Hijacking A sophisticated and alarming operation targeting cryptocurrency users...

Hacker Server Exposes Toolkit Used in Viva Aerobus-Linked Intrusion

Detailed Insight Into a Rapid Intrusion Linked to Viva Aerobus A recently uncovered attack staging...