Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious npm Package Wipes Codebases with Remote Trigger - ...

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
972
Company Posts That Month
23
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious npm package named xlsx-to-json-lh was identified as a typosquat of the legitimate xlsx-to-json-lc, designed to exploit a single-letter typing mistake. The package, undetected for six years, contained a hidden payload that established a connection to a command and control server, enabling remote code execution to delete entire project directories without warning. The attack was discovered by Socket's Threat Research Team, highlighting the risks of supply chain attacks and the challenges in detecting them due to the package's functionality and the use of legitimate author's metadata to build trust. The French command "remise à zéro" suggests regional targeting, and the potential for future attacks to use more sophisticated methods, like time-based triggers or selective file exfiltration, emphasizes the need for heightened vigilance in dependency management. Despite the petition for its removal, the package remained live on npm, underscoring the importance of proactive security measures to safeguard development environments against such vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.