Malicious 'akiraa-wb' npm Package Exfiltrates Files to Exter...
Blog post from Socket
The "akiraa-wb" npm package has been identified by the Socket Research team as containing an obfuscated script designed to exfiltrate users' files to various external services without consent, using HTTP POST requests to suspicious URLs. The script embeds file data into form-data and sends it to multiple file-sharing services like telegra.ph, pomf2.lain.la, and catbox.moe, among others, with tailored functions for each service to facilitate unauthorized data uploads. The package's behavior, including continuous file monitoring for changes to avoid detection, has led to its classification as malicious, with the specific URLs used in the script being recognized as indicators of compromise. This discovery underscores the importance for security teams to monitor for such threats to prevent data breaches and mitigate potential risks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.