Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious “express-dompurify” npm Package Steals Browser and...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
1,139
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious npm package named "express-dompurify" has been identified by the Socket Research team as targeting users by masquerading as the legitimate and widely-trusted DOMPurify library, which is known for preventing cross-site scripting (XSS) attacks. This package serves as a dangerous supply chain attack, using obfuscated code to hide its intent to exfiltrate sensitive data, including browser credentials, cryptocurrency wallet information, and system details, to an external server. The package's README file mimics that of the legitimate DOMPurify, increasing the likelihood of unsuspecting developers installing it, thereby compromising their applications. The attack utilizes dynamically generated variable names and commands to conceal its malicious activities, while also employing specific functions to gather and upload sensitive data from various system locations and browser profiles. This scenario highlights the growing threat of impersonation attacks on trusted libraries and underscores the importance of regular audits and vigilance against obfuscated code in packages.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.