Nearly 800 Malicious npm Packages Spread Malware Across Windows, macOS and Linux

Nearly 800 Malicious npm Packages Spread Malware Across Windows, macOS and Linux

Cybersecurity researchers have discovered nearly 800 harmful packages on the npm software registry. The malicious npm packages are connected to a campaign that can affect computers running Windows, macOS, and Linux.

According to researchers, the packages are designed to deliver harmful software that can allow unauthorized access to computers and collect sensitive information. Many of the packages appear to use random names, misspelled names, or names that resemble legitimate software. This can make it difficult for developers to identify them as unsafe.

Nearly 800 Malicious npm Packages Spread Malware Across Windows, macOS and Linux

The harmful packages were designed to look like ordinary software components that developers might use in their projects.

Instead of relying on automatic installation processes, the packages contain instructions that encourage developers to load them as part of their applications. Once activated, the harmful software checks the type of computer on which it is running and attempts to obtain the appropriate malicious component.

Researchers found that the campaign uses several different methods to deliver its harmful software. Having more than one delivery method may help the attackers continue their operation when one method is unsuccessful.

Threats to Different Operating Systems

The campaign affects multiple major computer operating systems.

On Windows, the harmful software can attempt to remain active on an infected computer and avoid certain security checks. Researchers also found evidence of techniques that can help the malware continue operating after the initial infection.

On macOS, the campaign uses similar methods. The software can check the computer for signs that it is being examined by security researchers and can attempt to remain active on the system.

The Linux version was also found to contain harmful functionality and could download additional components. Researchers said the infection could eventually provide attackers with further control over an affected computer.

Malicious Code Disguised as Telemetry

One interesting part of the campaign is a file that appears to provide normal telemetry or analytics functions.

Researchers discovered that this component also contained harmful functionality. They believe the additional code may have been included to make the package look more legitimate and to make its real purpose harder to notice during a quick review.

This technique highlights the importance of carefully reviewing software before adding it to a project. Code that appears to have a normal purpose can sometimes contain unexpected functions.

Possible Interest in Financial Organizations

Researchers also discovered references to Russian financial and payment services within one part of the campaign.

These findings may suggest that financial organizations or payment services could be of interest to the attackers. However, researchers have not confirmed the exact targets or the identity of those responsible.

Possible Connection to an Earlier Campaign

The researchers believe the new campaign may have similarities to an earlier operation known as Moika.

The earlier campaign involved hundreds of harmful packages published to npm. Those packages were reportedly capable of collecting information about affected systems and delivering additional harmful software.

The similarities have raised the possibility that the campaigns could be connected. However, the available information does not conclusively prove that they were operated by the same people.

Other Harmful Software Packages

The discovery comes as security researchers continue to find harmful packages on software repositories such as npm and PyPI.

Other recent campaigns have involved software capable of stealing cryptocurrency, account credentials, private configuration information and other sensitive data. Some attacks have also attempted to obtain information from development platforms and online services.

These incidents demonstrate that software repositories can become attractive targets for attackers because developers and organizations regularly depend on third-party software.

Risks From Browser Extensions

The researchers also reported concerns involving certain browser extensions.

Some extensions were promoted as useful tools, including productivity applications, password managers, game-related tools and web development utilities.

However, some of these extensions contained additional software that could use users’ browsers for remote web activity. The extensions could receive instructions from outside systems and process information from websites.

In some cases, this functionality was mentioned in the extension’s description or privacy policy. Researchers nevertheless warned that users should carefully consider the permissions requested by browser extensions before installing them.

Why Developers Should Be Careful

The discovery shows why developers need to pay close attention to third-party software.

Before installing a package, developers should check its name, publisher, reputation and available documentation. They should also review unexpected changes to software dependencies and remove packages that are no longer required.

Organizations can further reduce their risk by maintaining approved software lists, regularly reviewing third-party components and monitoring systems for unusual activity.

Browser extensions should also be reviewed carefully, particularly when they request permissions that appear unrelated to their main purpose.

Conclusion

The discovery of nearly 800 harmful npm packages highlights the continuing security risks associated with third-party software.

The campaign uses misleading package names and hidden functionality to make harmful software appear legitimate. Because the packages can affect Windows, macOS and Linux systems, the campaign represents a broad threat to developers and organizations.

The discovery of other harmful packages and questionable browser extensions also shows that attackers are increasingly looking for opportunities within commonly used software platforms.

For developers and organizations, carefully selecting third-party software, regularly reviewing dependencies and maintaining good security practices can help reduce the risk of unwanted software entering their systems.

Mobile Phone Taxes Portal

Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.

Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).

Explore NowFollow us on Google News!

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *