Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious fezbox npm Package Steals Browser Passwords from C...

Blog post from Socket

Post Details
Company
Date Published
Author
Olivia Brown
Word Count
808
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

The fezbox npm package has been identified as malicious, employing an innovative QR code steganographic technique to steal browser credentials from cookies, as revealed by the Socket Threat Research Team. The package, ostensibly a utility library for JavaScript/TypeScript, covertly fetches and executes a QR code to acquire usernames and passwords, later sending the data to a remote server. The threat actor, operating under the alias 'janedu', obfuscates the malicious code using techniques like reversing strings and encoding. Despite the sophisticated methods employed, including the use of a QR code to hide the payload, the package remains active on npm, prompting security professionals to request its removal. This incident highlights the evolving nature of threat actors' obfuscation strategies and underscores the importance of vigilant dependency monitoring in software projects.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.