Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » XMLRPC npm library goes malicious, steals data, deploys Crypto Miner
Global Security

XMLRPC npm library goes malicious, steals data, deploys Crypto Miner

AdminBy AdminNovember 28, 2024No Comments4 Mins Read
npm Library
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


November 28, 2024Ravi LakshmananSoftware security / data breach

npm library

Cybersecurity researchers discovered a software supply chain attack that remained active for more than a year in the npm package registry, starting with an innocuous library and later adding malicious code to steal sensitive data and mine cryptocurrency from infected systems.

Package, no @0xengine/xmlrpcwas originally published on October 2, 2023. as a JavaScript-based XML-RPC server and client for Node.js. To date, it has been downloaded 1790 times and remains available for download from the repository.

Checkmarxwho discovered the package said that the malicious code was strategically injected into version 1.3.4 every other day, containing functionality to collect valuable information such as SSH keys, bash history, system metadata and environment variables every 12 hours and filter it through such services like Dropbox and file.io.

Cyber ​​security

“The attack achieved propagation through several vectors: a direct npm installation and as a hidden dependency in a repository that looks legitimate,” security researcher Yehuda Gelb. said in a technical report published this week.

The second approach involves a GitHub project repository called yawpp (short for “Yet Another WordPress Poster”), which purports to be a tool designed to programmatically create posts on the WordPress platform.

Its “package.json” file. lists the latest version of @0xengine/xmlrpc as a dependency, causing a malicious npm package to be automatically downloaded and installed when users try to configure the yawpp tool on their systems.

It is currently unclear whether the tool’s developer intentionally added this package as a dependency. The repository has been forked once at the time of writing. Needless to say, this approach is another effective method of spreading malware, as it exploits users’ trust in package dependencies.

Once installed, the malware is designed to collect system information, install security on the host via systemd, and deploy the XMRig cryptocurrency miner. 68 compromised systems were found to be actively mining cryptocurrency through the attacker’s Monero wallet.

In addition, it is equipped to constantly monitor the list of running processes to check for commands such as top, iostat, sar, glances, dstat, nmon, vmstat and ps, and stop all mining-related processes if found. It is also capable of suspending mining operations when user activity is detected.

“This discovery serves as a stark reminder that a package’s longevity and consistent maintenance history do not guarantee its safety,” Gelb said. “The software supply chain requires constant vigilance both during initial inspection and throughout the package’s lifecycle, whether they are initially malicious packages or legitimate packages compromised through updates.”

Disclosure occurs as Datadog Security Labs have discovered an ongoing malware campaign targeting Windows users that uses fake packages uploaded to both npm repositories and the Python Package Index (PyPI) with the ultimate goal of deploying open-source malware known as Blank-Grabber and Skuld Stealer .

Cyber ​​security

The company that discovered the supply chain attack last month is tracking a threat cluster called MUT-8694 (where MUT stands for “Mysterious Unattributed Threat”), saying it matches the company that was documented Socket earlier this month in an attempt to infect Roblox users with the same malware.

As many as 18 and 39 fake unique packages have been uploaded to npm and PyPI, with the libraries attempting to pass off as legitimate packages using typosquatting techniques.

“The use of multiple packages and the involvement of multiple malicious users suggests that MUT-8694 is persistently trying to compromise developers,” Datadog researchers said. “Unlike the PyPI ecosystem, most npm packages had references to Roblox, an online game creation platform, suggesting that the threat actor is targeting Roblox developers specifically.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025

Posted and Pubshell Sarsware used in Tibet’s Mustang Panda attack

June 27, 2025

The Chinese Silver Fox Group uses fake web -sats to deliver Sainbox Rat and Hidden Rortkit

June 27, 2025

Business -SUCKS FOR AGENTIC AI SOC -Analytics

June 27, 2025

Transfer of person transfer is increased by threats when directed by scanning and disadvantages CVE

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.