Malicious npm Packages Published Users’ Data On GitHub Page
Numerous malicious npm packages surfaced online once again. This time, four npm packages appeared in a repository that published user data online on a GitHub page.
npm Packages Published User Data Online
Researchers from Sonatype found two malicious npm packages that published user data online. As elaborated in their blog post, these packages, after download on a victim’s device, published the data on GitHub.
In brief, they found two packages “electorn” and “loadyaml” that supposedly exploited the typosquatting technique. Describing this technique, the researchers stated,
Typosquatting packages prey on a developer or unsuspecting user to make a minor typographical error which will trick them into installing the malicious package within their environment instead of the one they had originally intended to download.So, the attackers named the malicious packages with misspelled names of legit packages. Hence, if someone wanting to download “electron” inadvertently typed “electorn”, the malicious package would download.
Upon reaching the target device, the package would then steal the victim’s data, including IP address, geolocation, device fingerprint, and would publish them all on a GitHub page.
Both packages were uploaded by the same user “simplelive12”. They had also uploaded two other malicious packages, “lodashs” and “loadyml” earlier, but the author removed them before anyone could detect them.
Malicious Packages Removed
Upon detecting the malicious packages, Sonatype published their findings online to alert everyone.
According to the timeline they shared, the packages first appeared online on August 17, 2020. However, the author removed two of them soon after uploading.
Nonetheless, the other two persisted to catch the researchers’ attention who simultaneously alerted npm, GitHub, and publicly disclosed the details. Regarding the swift public disclosure, they clarified,
Our reason for the public disclosure centers on the fact that sensitive information of users who downloaded these packages inadvertently is already being exposed on the web and the malicious packages continue to exist on npm downloads, therefore the standard vulnerability disclosure timelines would not apply in this case.Shortly after their report, npm removed the malicious packages. Whereas, GitHub also removed the page broadcasting the data.
In September as well, npm disclosed the existence and subsequent removal of a malicious package that stole users’ data.
Posted from my blog with SteemPress : https://latesthackingnews.com/2020/10/11/malicious-npm-packages-published-users-data-on-github-page/
Leave Malicious npm Packages Published Users’ Data On GitHub Page to:
Read more #github posts
Best Posts From twr
We have not curated any of twr's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From twr
- Will a VPN Protect Me From a Data Breach?
- Why DDoS Attacks Are Still One of the Biggest Cyberthreats
- Why Do Subdomain Lookups for Cybersecurity?
- What You Need To Know About Bitcoin Before Investing Your Money In It
- Massive Cyberattacks that Shook the World in 2020
- Data of 176 Million Pakistani Citizens Found For Sale On Dark Web
- Apple Patched Three Zero-Days With The Release Of iOS 14.4
- Watch Out For This Wormable Malware Spreading Via WhatsApp
- What Password Managers Are Safe to Use in 2021
- 7 Reasons to Choose an Outsourced Security Services Provider