Multiple nefarious npm, Python, and Ruby packages have been exfiltrating pilfered data to actor-controlled webhooks by exploiting Discord as a command-and-control channel, reports The Hacker News.While the npm package 'mysql-dumpdiscord' drains developer configuration file content to a Discord webhook, the npm package 'nodejs[.]discord' harnesses the webhook for log alerts, according to findings from Socket's Threat Research Team.On the other hand, a trio of PyPI packages leveraged Discord as a C2 through channel-directed HTTP requests, while the Ruby package 'sqlcommenter_rails' delivered pilfered host data to a hard-coded webhook."Abuse of Discord webhooks as C2 matters because it flips the economics of supply chain attacks. By being free and fast, threat actors avoid hosting and maintaining their own infrastructure. Also, they often blend in to regular code and firewall rules, allowing exfiltration even from secured victims," said Socket researcher Olivia Brown.Such findings follow the discovery of over 300 illicit npm packages spread as part of the North Korean Contagious Interview campaign.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
