Home / Companies / Socket / Blog / Post Details
Content Deep Dive

The “Skeleton Squad” is now targeting NPM

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
629
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

The "Skeleton Squad," also known as "EsqueleSquad," has expanded its malicious activities from the Python Package Index (PyPI) to the npm ecosystem, posing a significant threat to developers and users of JavaScript package managers like npm, yarn, and pnpm. Initially appearing in February, this threat actor has been deploying harmful packages that drop malicious executables, with the latest being an npm package called `pyautodllxd`. Despite not impersonating popular packages, this package executes a PowerShell command targeting Windows systems, downloading a trojan marked by several vendors. The executable employs sophisticated techniques to bypass Windows Defender, using a script that exploits the CMSTP bypass technique. This approach mirrors their previous PyPI tactics, involving a Base64-encoded PowerShell command that initiates the download of a remote executable, leading to the deployment of multiple malware binaries. Despite efforts by security teams to remove these threats, the Skeleton Squad continues to exploit user accounts, even leaving cryptic messages in Spanish, suggesting a persistent and evolving cyber threat.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.