Targeted npm dependency confusion attack caught red-handed
Blog post from Snyk
Snyk researchers analyzed the npm package gxm-reference-web-auth-server after detecting its obfuscated post-install script and encrypted payload, initially assessing it as a targeted dependency-confusion attack against an unknown organization whose private registry likely contained a package of the same name. The first-stage wrapper collected system and package information through DNS queries, searched for private npm registry credentials, attempted to retrieve the legitimate private package, exfiltrated selected network configuration files, and then launched a decrypted second-stage agent while leaving misleading decoy files suggesting use of a private registry. The agent registered with a command-and-control server, encrypted its communications, reported detailed host and environment data, and supported commands for file transfer, code execution, evaluation, deletion, and re-registration, giving an operator potentially extensive control of an infected system. Researchers ran a controlled fake agent, observed live commands attempting filesystem exploration, and found indications of additional Go and browser-oriented agents. npm removed the packages on May 1, 2022, DigitalOcean investigated the command-and-control infrastructure, and on May 10 CodeWhite claimed responsibility, stating that the operation was an attack simulation conducted for clients.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.