The “Skeleton Squad” is now targeting NPM
Blog post from Socket
The "Skeleton Squad," also known as "EsqueleSquad," has expanded its malicious activities from the Python Package Index (PyPI) to the npm ecosystem, posing a significant threat to developers and users of JavaScript package managers like npm, yarn, and pnpm. Initially appearing in February, this threat actor has been deploying harmful packages that drop malicious executables, with the latest being an npm package called `pyautodllxd`. Despite not impersonating popular packages, this package executes a PowerShell command targeting Windows systems, downloading a trojan marked by several vendors. The executable employs sophisticated techniques to bypass Windows Defender, using a script that exploits the CMSTP bypass technique. This approach mirrors their previous PyPI tactics, involving a Base64-encoded PowerShell command that initiates the download of a remote executable, leading to the deployment of multiple malware binaries. Despite efforts by security teams to remove these threats, the Skeleton Squad continues to exploit user accounts, even leaving cryptic messages in Spanish, suggesting a persistent and evolving cyber threat.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.