Deceptive npm Bundles Uncovered Using Picture Files to Conceal Backdoor Script

î ‚Jul 16, 2024î „NewsroomOpen Source / Software Supply Chain

Cybersecurity experts have pinpointed two duplicitous bundles on the npm parcel registry which masked backdoor script to conduct harmful directives dispatched from a distant server.

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

î ‚Jul 16, 2024î „NewsroomOpen Source / Software Supply Chain

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

Cybersecurity experts have pinpointed two duplicitous bundles on the npm parcel registry which masked backdoor script to conduct harmful directives dispatched from a distant server.

The bundles under scrutiny – img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy – have been retrieved 190 and 48 times each. At present, they have been discontinued by the npm security crew.

“They comprised intricate command and control functionality camouflaged in picture files that would be triggered during bundle installation,” software supply chain safety agency Phylum stated in an assessment.

The bundles are crafted to mimic a genuine npm repository named aws-s3-object-multipart-copy, but feature a modified variant of the “index.js” script to launch a JavaScript script (“loadformat.js”).

Regarding the JavaScript script, it is built to handle three illustrations — showcasing the official emblems for Intel, Microsoft, and AMD — with the illustration representing Microsoft’s emblem utilized to extract and enact the insidious content.

CybersecurityAbout Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.