Supply chain

Nearly 800 malicious npm packages deliver cross-platform malware

(Credit: Araki Illustrations – stock.adobe.com)

A new campaign has published nearly 800 malicious packages to the npm registry, designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. These packages utilize AI-generated typo-squatting names and deliver a potent RAT and infostealer payload, based on information published by The Hacker News.

The campaign, tracked as Flooding Dropper by Sonatype, employs a novel approach by instructing developers to load packages using "require()", bypassing typical lifecycle hooks. Upon execution, a downloader named WEL1DROPPER identifies the operating system and architecture, fetching a compatible payload from Cloudflare Workers or, if that fails, using DNS TXT records from "wel1[.]ru". The final payload is executed in a detached process.

Windows and macOS versions attempt to disable security monitoring like ETW and AMSI, establish persistence, and download further payloads. The Linux variant deploys the open-source Sliver C2 framework. Some packages also contain a deceptive telemetry SDK with downloader logic. Indicators suggest potential targeting of Russian financial institutions. This campaign may be an evolution of the "Moika" dependency confusion campaign, highlighting a broader trend of supply chain attacks across npm and PyPI, including cryptocurrency stealers and credential exfiltration tools.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds