PULSE NAME
New Wave of Malicious npm Packages
WHITE BITSecurity 2023-08-15 Modified: 2023-09-14
14
IOCs
MEDIUM VOLUME
The npm package registry has emerged as the target of yet another highly targeted attack campaign that aims to entice developers into downloading malevolent modules. Software supply chain security firm Phylum told The Hacker News the activity exhibits similar behaviors to that of a previous attack wave uncovered in June, which has since been linked to North Korean threat actors. As many as nine packages have been identified as uploaded to npm between August 9 and 12, 2023. This includes: ws-paso-jssdk, pingan-vue-floating, srm-front-util, cloud-room-video, progress-player, ynf-core-loader, ynf-core-renderer, ynf-dx-scripts, and ynf-dx-webpack-plugins. "Due to the sophisticated nature of the attack and the small number of affected packages, we suspect this is another highly targeted attack, likely with a social engineering aspect involved in order to get targets to install these packages," the company said.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (14)
All URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://ns1.dyna-ns.net/ 2023-08-15
URL http://ns2.dyna-ns.net/ 2023-08-15
URL https://ql.rustdesk.net 2023-08-15
URL https://ql.rustdesk.net/api/index 2023-08-15
URL https://rustdesk.com 2023-08-15
domain axios.post 2023-08-15
domain decipher.final 2023-08-15
domain response.data 2023-08-15
domain rustdesk.com 2023-08-15
domain rustdesk.net 2023-08-15
hostname array.prototype.slice.call 2023-08-15
hostname ns1.dyna-ns.net 2023-08-15
hostname ns2.dyna-ns.net 2023-08-15
hostname ql.rustdesk.net 2023-08-15