Thousands of fake packages flood npm registry in major attack – here’s what we know

  • Over 43,000 dormant spam packages flooded npm in a coordinated two-year campaign
  • Some packages contained worm-like scripts that auto-generated and published new entries
  • Attackers may have faked TEA impact scores to earn decentralized developer rewards

Roughly 1% of the entire npm ecosystem now consists of bogus, dormant packages that were uploaded as part of a years-long targeted – and potentially malicious – campaign, experts have claimed.

Cybersecurity researchers Endor Labs discovered more than 43,000 spam packages which took almost two years to upload in a coordinated effort that took at least 11 distinct user accounts to pull off.

“The packages were systematically published over an extended period, flooding the npm registry with junk packages that survived in the ecosystem for almost two years,” the researchers said.

TEA token harvesting?

The researchers dubbed the campaign IndonesianFoods because of the way the packages are named. The malicious script used for naming contains two internal dictionaries, one with Indonesian names, and other with Indonesian food terms. When the script runs, it selects two terms at random, adds a number, and appends a suffix.

The strange part is that the packages themselves are not malicious. They’re not designed to steal sensitive developer data, or to act as a backdoor. Instead, they just lie there, dormant, gathering downloads.

Some packages have thousands of weekly downloads, the researchers explain, hinting that it gives the attacker a potential edge: “This leaves an opportunity for the attackers to push a malicious commit in the future that would affect all those downloads.”

Some of the packages did contain a worm-like script which, if run, would generate and create additional scripts which would then be added to npm.

Besides malicious potential, the researchers also believe this could be a part of a financially motivated campaign. Apparently, some of the packages included tea.yaml files, listing TEA accounts. Tea is a decentralized framework protocol in which open source devs are rewarded when contributing software.

This could mean that the attackers tried to fake their impact scores, thus earning more TEA tokens.

Via The Hacker News

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malware

A final hearing will take place in June. | The Verge / Beatrice Sala Federal authorities have arrested a Florida man suspected of stealing at...

Is America ready for this quirky Jeep-looking EV that can park itself?

Are we living through a small car renaissance? There's the Slate Truck, Amble's dune buggy, and the Fiat Topolino, as well as a whole...

Samsung’s redesigned Z Fold 8 with a wide display just leaked

Leaker Evan Blass shared images of Samsung's redesigned Galaxy Z Fold 8 just days before the July 22nd launch event where Samsung is expected...

Asus’ top-end 4K QD-OLED gaming monitor is $400 off

The discounted Asus QD-OLED in all its glory. | Image: The Verge The Asus ROG Swift 32-inch 4K QD-OLED gaming monitor has almost everything I...

Apple’s plot to crush OpenAI

Apple is suing OpenAI. The complaint is readable and intense, as these things often are, though many experts seem to think many of the...

Apple Music is getting a price hike

Apple Music is more expensive now. In the US, an individual plan now costs $11.99 per month, a $1 bump up from the previous...

Pebble founder Eric Migicovsky says his 30-day warranty is all about trust

The Pebble Appstore is filled with stuff, but you don’t need much of it. | Photo by Amelia Holowaty Krales / The Verge Pebble founder...

TikTok is testing an AI likeness detection tool

TikTok is starting to test an opt-in tool that scans for AI likenesses and lets creators report them to the company, as spotted by...

Friday’s Android app deals and freebies: Final Fantasy VII, Serial Cleaner, Parabellum, more

Your Friday afternoon lineup of the best Android game and app deals has arrived, including titles like Foretales, Looking for Aliens, Serial Cleaner, Parabellum:...

Pixel 11 reportedly getting ‘improved’ face unlock as 11a said to use Tensor G6

While we wait for the Pixel 11 launch, rumors about the Pixel 11a and even 12a are already emerging. Read more @ 9to5google