Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » BeaverTail malware reappears in npm malware packages targeting developers
Global Security

BeaverTail malware reappears in npm malware packages targeting developers

AdminBy AdminOctober 28, 2024No Comments2 Mins Read
BeaverTail Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 28, 2024Ravi LakshmananMalware / Threat Intelligence

BeaverTail malware

Three malicious packages published to the npm registry in September 2024 were found to contain known malware called BeaverTail, a JavaScript downloader, and an information stealer linked to an ongoing campaign in North Korea tracked as Contagious Interview.

Datadog Security Research Team monitoring activity under the name Stubborn pungsanwhich is also known by the aliases CL-STA-0240 and Famous Chollima.

Cyber ​​security

The names of the malicious packages that are no longer available for download from the package registry are listed below –

  • passports-js, passport backdoor (118 downloads)
  • bcrypts-js, a backdoor copy of bcryptjs (81 downloads)
  • blockscan-api, a backdoor copy of etherscan-api (124 downloads)

Contagious interview refers to a annual campaign started by the Democratic People’s Republic of Korea (DPRK), which involves tricking developers into downloading malicious packages or seemingly harmless video conferencing applications as part of a coding test. He was born for the first time in November 2023.

BeaverTail malware

This is not the first time that threat actors have used npm packages to distribute BeaverTail. In August 2024, supply chain security software firm Phylum opened another group of npm packages that paved the way for BeaverTail deployments and a Python backdoor called InvisibleFerret.

The names of the malicious packages discovered at the time were temp-etherscan-api, ethersscan-api, telegram-con, helmet-validate and qq-console. One aspect shared by the two sets of packages is the continued effort by threat actors to mimic the etherscan-api package, signaling that the cryptocurrency sector is a constant target.

Cyber ​​security

Stacklock said this last month revealed a new wave of fake packages – eslint-module-conf and eslint-scope-util – that are designed to harvest cryptocurrency and establish permanent access to compromised developer machines.

Division 42 of Palo Alto Networks told The Hacker News earlier this month that the company has found an effective way to spread malware by exploiting a job seeker’s trust and urgency when applying for opportunities online.

The findings show how threat actors are increasingly abusing the open source software supply chain as an attack vector to infect downstream targets.

“Copying and backdooring legitimate npm packages continues to be a common tactic of threat actors in this ecosystem,” Datadog said. “These campaigns, as well as Contagious Interview more broadly, highlight that individual developers remain valuable targets for these North Korean-related threats.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.