Cybercriminals have injected more than 15,000 malicious packages containing phishing links into the NPM repository, creating a dangerous environment for unsuspecting users.

In a brazen attack on the open-source community, nearly 15,000 spam packages have clogged up the npm repository to spread malicious phishing links. "The packages were created using automated processes, with project descriptions and auto-generated names that closely resembled one another," Checkmarx researcher Yehuda Gelb said in a Tuesday report. "The attackers referred to retail websites using referral IDs, thus profiting from the referral rewards they earned." This modus operandi poisons the registry with malicious packages that contain links to phishing efforts in their README.md files, much like what software supply chain security uncovered back in December 2022.

The malicious modules posed as beneficial cheats and gratis supplies, with some bundles entitled "free-tiktok-followers," "free-xbox-codes," and "instagram-followers-free." The ultimate mission of the operation is to beguile users into downloading these packages and clicking on links that lead to phishing sites where they can get false guarantees of amplified followers on social media. "The deceptive web pages are well-designed and, in some cases, even include fake interactive chats that appear to show users receiving the game cheats or followers they were promised," Gelb explained.

pasted image 0.jpg

Cybercriminals are coaxing victims to complete surveys, which then open the door for even further ones or redirect them to legitimate e-commerce websites such as AliExpress. Surprisingly, these malicious packages were uploaded from multiple user accounts in a matter of hours between February 20th and 21st with an automated Python script on npm.In addition, the Python script is designed to add links of published npm packages on WordPress websites operated by the threat actor that allegedly offer Family Island cheats. To achieve this, it uses selenium package for Python to interact with these websites and make necessary modifications.

pasted image 0 (1).jpg

Automation was an integral factor in the success of this attack, as it enabled the adversary to rapidly publish a substantial number of packages within a concise timeframe - not to mention setting up multiple user accounts for evasion tactics. "This shows the sophistication and determination of these attackers, who were willing to invest significant resources in order to carry out this campaign," Gelb said. The findings once again demonstrate the challenges in securing the software supply chain, as threat actors continue to adapt with "new and unexpected techniques."

Get the latest news, invites to events, and threat alerts

Cybercriminals have injected more than 15,000 malicious packages containing phishing links into the NPM repository, creating a dangerous environment for unsuspecting users.Cybercriminals have injected more than 15,000 malicious packages containing phishing links into the NPM repository, creating a dangerous environment for unsuspecting users.
VMware issued an immediate patch to fix a severe security flaw in its Carbon Black App Control productVMware issued an immediate patch to fix a severe security flaw in its Carbon Black App Control product
Fortinet provides critical security updates for 40 vulnerabilities in its products, including FortiWeb, FortiOS, FortiNAC and FortiProxy.Fortinet provides critical security updates for 40 vulnerabilities in its products, including FortiWeb, FortiOS, FortiNAC and FortiProxy.
GoDaddy Unveils a Years-Long Security Compromise Resulting in Malware Installations and Source Code Theft.GoDaddy Unveils a Years-Long Security Compromise Resulting in Malware Installations and Source Code Theft.
Researchers recently took advantage of a widely-used NPM package with millions of downloads.Researchers recently took advantage of a widely-used NPM package with millions of downloads.
A Major Remote Code Execution Vulnerability Has Been Found in ClamAV Open Source Antivirus Software, Exposing Users to Unforeseen Security Risks.A Major Remote Code Execution Vulnerability Has Been Found in ClamAV Open Source Antivirus Software, Exposing Users to Unforeseen Security Risks.
The importance of SAML in preventing cyber-attacks by hackersThe importance of SAML in preventing cyber-attacks by hackers
The benefits of working with edge computing technologyThe benefits of working with edge computing technology
It’s Time to Kill the PasswordIt’s Time to Kill the Password
It is time to Kill Security Questions—or Answer Them with LiesIt is time to Kill Security Questions—or Answer Them with Lies