Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Quasar RAT Disguised as an npm Package for Detecting Vulnera...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
814
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

Researchers from Socket have discovered a malicious npm package, named ethereumvulncontracthandler, which masquerades as a tool for detecting vulnerabilities in Ethereum smart contracts while secretly deploying Quasar RAT, a remote access trojan, on developers' systems. Published by a threat actor using the alias "solidit-dev-416," the package is heavily obfuscated and retrieves a malicious script from a remote server to execute on Windows systems. Quasar RAT, known for its capabilities like keystroke logging and credential harvesting, poses a severe threat to developers and organizations, particularly those handling sensitive financial data. The package's covert techniques include multiple layers of obfuscation and resource checks to evade detection, and once installed, it ensures persistence by modifying registry keys. The malware's control server, captchacdn.com:7000, allows the threat actor to manage compromised systems and exfiltrate data, highlighting the need for developers to scrutinize third-party code and utilize security tools to protect their environments.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.