Weaponizing OAST: How Malicious Packages Exploit npm, PyPI, ...
Blog post from Socket
Researchers from Socket have discovered that threat actors are exploiting Out-of-Band Application Security Testing (OAST) techniques to exfiltrate sensitive data and conduct reconnaissance across npm, PyPI, and RubyGems ecosystems. These methods, originally designed for ethical security assessments, are being misused to execute attacks, such as establishing command and control (C2) channels and conducting multi-stage attacks. Threat actors employ tactics like typosquatting, obfuscated code, and high-version number deception to infiltrate systems and evade detection. Malicious packages target Linux, macOS, and Windows systems, employing tools like oastify.com to exfiltrate data. The misuse of OAST for malicious purposes contrasts with its ethical applications, where it helps identify and address vulnerabilities. The report emphasizes the need for vigilance and proactive measures, recommending the use of tools like Socket’s GitHub app and CLI tool to safeguard the software supply chain against these threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.