60 Malicious npm Packages Leak Network and Host Data in Acti...
Blog post from Socket
Socket's Threat Research Team has identified an ongoing malware campaign involving 60 malicious npm packages that use post-install scripts to exfiltrate sensitive network and host data to a Discord-controlled endpoint. These packages, published under three npm accounts, are designed to run on Windows, macOS, and Linux systems, performing reconnaissance to collect hostnames, IP addresses, DNS server lists, and user directories. The campaign aims to map developer and enterprise networks for potential follow-up attacks, with combined downloads exceeding 3,000 as of the report. Despite petitions for removal, the packages remain live on npm, posing a strategic risk by laying groundwork for deeper intrusions. The threat actor's ability to track downloads and quickly publish new packages suggests that without intervention, similar attacks could continue, emphasizing the need for enhanced security measures like dependency-scanning tools and automated checks in development pipelines.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.