Researchers recently took advantage of a widely-used NPM package with millions of downloads.

It has been discovered that a popular npm package with over 3.5 million weekly downloads is at risk of an account takeover attack, setting users up for potential security breaches! "The package can be taken over by recovering an expired domain name for one of its maintainers and resetting the password," software supply chain security company Illustria said in a report. Although npm's security precautions only permit one active email address per profile, the Israeli organization found that it was capable of resetting GitHub password through the recovered domain.

In summary, this attack provides a malicious actor with the capability of gaining access to the package's GitHub account. This enables them to distribute dangerous versions on the npm registry which can be used for large-scale supply chain attacks. Unlock the potential of your repository by taking advantage of a GitHub Action that is configured to instantly publish packages upon code changes. "Even though the maintainer's npm user account is properly configured with [two-factor authentication], this automation token bypasses it," Bogdan Kortnov, co-founder and CTO of Illustria, said.

pasted image 0.jpg

Although the exact module remains unannounced, Illustria contacted its maintainer and enforced precautionary steps in order to block any possible takeover. Unfortunately, this isn't a one-time incident; malicious actors have targeted developer accounts for several years now - most notably in 2022 with ctx Python package's domain being seized and replaced by an unauthorized version. As such, it is essential that developers take all necessary measures to secure their accounts from potential threats.

Get the latest news, invites to events, and threat alerts

Cybercriminals have injected more than 15,000 malicious packages containing phishing links into the NPM repository, creating a dangerous environment for unsuspecting users.Cybercriminals have injected more than 15,000 malicious packages containing phishing links into the NPM repository, creating a dangerous environment for unsuspecting users.
VMware issued an immediate patch to fix a severe security flaw in its Carbon Black App Control productVMware issued an immediate patch to fix a severe security flaw in its Carbon Black App Control product
Fortinet provides critical security updates for 40 vulnerabilities in its products, including FortiWeb, FortiOS, FortiNAC and FortiProxy.Fortinet provides critical security updates for 40 vulnerabilities in its products, including FortiWeb, FortiOS, FortiNAC and FortiProxy.
GoDaddy Unveils a Years-Long Security Compromise Resulting in Malware Installations and Source Code Theft.GoDaddy Unveils a Years-Long Security Compromise Resulting in Malware Installations and Source Code Theft.
Researchers recently took advantage of a widely-used NPM package with millions of downloads.Researchers recently took advantage of a widely-used NPM package with millions of downloads.
A Major Remote Code Execution Vulnerability Has Been Found in ClamAV Open Source Antivirus Software, Exposing Users to Unforeseen Security Risks.A Major Remote Code Execution Vulnerability Has Been Found in ClamAV Open Source Antivirus Software, Exposing Users to Unforeseen Security Risks.
The importance of SAML in preventing cyber-attacks by hackersThe importance of SAML in preventing cyber-attacks by hackers
The benefits of working with edge computing technologyThe benefits of working with edge computing technology
It’s Time to Kill the PasswordIt’s Time to Kill the Password
It is time to Kill Security Questions—or Answer Them with LiesIt is time to Kill Security Questions—or Answer Them with Lies
Researchers recently took advantage of a widely-used NPM package with millions of downloads. | EdgeDefence