[ << ALL_FEED ]

Enterprise-grade validation system with schema support

More in General

Enterprise-grade validation system with schema support

(c) The author of a dozen trojans who forgot to add "Enterprise-grade" obfuscation

We discovered and reported to the npm administration a series of malicious packages:

  • @phonos/types
  • @structureit/ir-dealapi-js
  • @wame/ngx-adfs
  • @wame/ngx-frf-utilities
  • cclr-component-resources
  • compliancepolicyserv
  • connectedmerchantsserv
  • ftapi-core
  • lakk-analytics
  • meshim-frontend-config
  • nms-dashboard-js
  • oc-aa-module-client
  • oc-ccp-module-client
  • oc-navbar-module-client
  • qr-code-styling-temp
  • uploader-frontend
  • uploader-frontend-legacy
In total, the packages were downloaded more than 1,600 times

The listed packages contain similar code and a similar distribution strategy: first a clean version is published (usually 9.9.0), and a couple of days later an “update” with unwanted functionality is published.

ㅤ

The malicious logic triggers during installation, executing index.js with control passed to ./lib/core.js

The scripts with malicious logic are quite compact — each one individually takes up no more than a kilobyte.

ㅤ

The code uses two techniques to conceal the logic: one-liners and storing constants as arrays of ASCII codes without additional obfuscation.

ㅤ

The purpose of the snippets, using @phonos/types as an example (we added explanatory comments to the code):

b02e30.js stores information about the C2. Of note: the attacker was too lazy to encode the campaign name
6ad264.js — resolves the os, dns, and process modules
core.js — retrieves and exfiltrates information

At first glance, the payload looks harmless — merely the attacker obtaining a basic profile of the user who installed the package. One could even entertain the notion that these packages were created with noble intentions. On the other hand, npm explicitly prohibits hosting such packages even for research purposes:

Several examples of unacceptable content:
…
3. Content containing malicious computer code, such as computer viruses, computer worms, rootkits, backdoors, or spyware. This includes content submitted for research purposes.

https://docs.npmjs.com/policies/open-source-terms#acceptable-use (translation)

Don’t want your CI/CD pipelines and developers’ devices to take part in this kind of unscheduled survey? There’s a solution: feeds for secure development within PT Fusion.

Supply Chain Security Team

#npm #scs #ti

@ptescalator

More from ti_author

More from ti_author

More in General