A new campaign has published nearly 800 malicious packages to the npm registry, designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. These packages utilize AI-generated typo-squatting names and deliver a potent RAT and infostealer payload, based on information published by The Hacker News.The campaign, tracked as Flooding Dropper by Sonatype, employs a novel approach by instructing developers to load packages using "require()", bypassing typical lifecycle hooks. Upon execution, a downloader named WEL1DROPPER identifies the operating system and architecture, fetching a compatible payload from Cloudflare Workers or, if that fails, using DNS TXT records from "wel1[.]ru". The final payload is executed in a detached process.Windows and macOS versions attempt to disable security monitoring like ETW and AMSI, establish persistence, and download further payloads. The Linux variant deploys the open-source Sliver C2 framework. Some packages also contain a deceptive telemetry SDK with downloader logic. Indicators suggest potential targeting of Russian financial institutions. This campaign may be an evolution of the "Moika" dependency confusion campaign, highlighting a broader trend of supply chain attacks across npm and PyPI, including cryptocurrency stealers and credential exfiltration tools.Source: The Hacker News
Supply chain
Nearly 800 malicious npm packages deliver cross-platform malware
(Credit: Araki Illustrations – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
