Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious 'akiraa-wb' npm Package Exfiltrates Files to Exter...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
607
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

The "akiraa-wb" npm package has been identified by the Socket Research team as containing an obfuscated script designed to exfiltrate users' files to various external services without consent, using HTTP POST requests to suspicious URLs. The script embeds file data into form-data and sends it to multiple file-sharing services like telegra.ph, pomf2.lain.la, and catbox.moe, among others, with tailored functions for each service to facilitate unauthorized data uploads. The package's behavior, including continuous file monitoring for changes to avoid detection, has led to its classification as malicious, with the specific URLs used in the script being recognized as indicators of compromise. This discovery underscores the importance for security teams to monitor for such threats to prevent data breaches and mitigate potential risks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.