Destructive npm Packages Disguised as Utilities Enable Remot...
Blog post from Socket
Two malicious npm packages, express-api-sync and system-health-sync-api, were discovered by Socket's Threat Research Team, masquerading as legitimate utilities with backdoors designed for system destruction. These packages, published by a user named botsailer, execute file deletion commands upon receiving a specific HTTP request, effectively wiping out application directories. While express-api-sync presents itself as a simple Express middleware, it harbors a backdoor activated upon any HTTP request to delete files using a Unix command. The more sophisticated system-health-sync-api includes intelligence-gathering features and supports multiple platforms, executing different destruction commands depending on the operating system. It uses real dependencies and sends server status emails to attackers, exploiting SMTP's allowance in firewalls for data exfiltration. These packages are indicative of a shift from financial theft to targeted sabotage, demonstrating a concerning evolution in threat techniques within the npm ecosystem.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.