Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Crypto Analyst Predicts 1 Altcoin Will Fall Down Hard – Is It Cardano? bitcoin news
  • Bitcoin Could See 10% Jump, As Volatility Drops To 18-Month Low bitcoin news
  • Dragon War is Bringing the Most Exclusive NFT Collections to Magic Eden bitcoin news
  • Public Consultations Reveal Positive Interest in Bank of Israel’s Digital Shekel – Finance Bitcoin News bitcoin news
  • Unizen Grows Its CeDeFi Exchange, Adding ZCX/USDT Trading Pair Into The Mix bitcoin news
  • QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available cyber security news
  • Sneakmart Brings Its Web3-oriented Metakicks NFTs To Market In June 2022 bitcoin news
  • Wikipedia Stops Accepting Cryptocurrency Donations Citing Community’s Environmental Concerns – Featured Bitcoin News bitcoin news

Malicious NPM Packages Target German Companies in Supply Chain Attack

Posted on May 11, 2022 By root


Supply Chain Attack

Cybersecurity researchers have discovered a number of malicious packages in the NPM registry specifically targeting a number of prominent companies based in Germany to carry out supply chain attacks.

“Compared with most malware found in the NPM repository, this payload seems particularly dangerous: a highly-sophisticated, obfuscated piece of malware that acts as a backdoor and allows the attacker to take total control over the infected machine,” researchers from JFrog said in a new report.

The DevOps company said that evidence points to it being either the work of a sophisticated threat actor or a “very aggressive” penetration test.

All the rogue packages, most of which have since been removed from the repository, have been traced to four “maintainers” – bertelsmannnpm, boschnodemodules, stihlnodemodules, and dbschenkernpm — indicating an attempt to impersonate legitimate firms like Bertelsmann, Bosch, Stihl, and DB Schenker.

Some of the package names are said to be very specific, raising the possibility that the adversary managed to identify the libraries hosted in the companies’ internal repositories with the goal of staging a dependency confusion attack.

Supply Chain Attack

The findings build on a report from Snyk late last month that detailed one of the offending packages, “gxm-reference-web-auth-server,” noting that the malware is targeting an unknown company that has the same package in their private registry.

“The attacker(s) likely had information about the existence of such a package in the company’s private registry,” the Snyk security research team said.

Calling the implant an “in-house development,” JFrog pointed out that the malware harbors two components, a dropper that sends information about the infected machine to a remote telemetry server before decrypting and executing a JavaScript backdoor.

The backdoor, while lacking a persistence mechanism, is designed to receive and execute commands sent from a hard-coded command-and-control server, evaluate arbitrary JavaScript code, and upload files back to the server.

“The attack is highly targeted and relies on difficult-to-get insider information,” the researchers said. But on the other hand, “the usernames created in the NPM registry did not try to hide the targeted company.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Cryptocurrency Exchange Kucoin Raises $150 Million in Pre-Series B Funding Round, Reaches $10 Billion Valuation – Bitcoin News
Next Post: Mexican Crypto Exchange Bitso Launches Stable Yield Program – Exchanges Bitcoin News

Related Posts

  • U.S. Charges Venezuelan Doctor for Using and Selling Thanos Ransomware cyber security news
  • Europe Agrees to Adopt New NIS2 Directive Aimed at Hardening Cybersecurity cyber security news
  • Zyxel Releases Patch for Critical Firewall OS Command Injection Vulnerability cyber security news
  • Yes, Containers Are Terrific, But Watch the Security Risks cyber security news
  • Google’s New Safety Section Shows What Data Android Apps Collect About Users cyber security news
  • Everything We Learned From the LAPSUS$ Attacks cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys
  • ETH Back Under $2,000 as Balenciaga Gains Lose Steam – Market Updates Bitcoin News

Recent Comments

No comments to show.
  • Circle Says USDC Reserve Backed Entirely in Cash and Short-Dated US Treasuries – Bitcoin News bitcoin news
  • Veteran Investor Jim Rogers Optimistic About Future of Crypto Money – Bitcoin News bitcoin news
  • How Blockchain Technology Expands The Education Frontiers bitcoin news
  • Derivatives, Spot Markets, Dex Swaps — 30 Day Crypto Trade Volumes Slipped Across the Board Last Month – Market Updates Bitcoin News bitcoin news
  • El Salvador’s Bitcoin Volcano Bonds Launch Still on Hold, According to Treasury Minister – Bitcoin News bitcoin news
  • Market Downtrend Trigger Bitcoin Inflows From Institutional Investors bitcoin news
  • Bitcoin Miners Expected to Catch a Break in 2 Days, Mining Difficulty Estimated to Drop Close to 4% – Mining Bitcoin News bitcoin news
  • LUNA Falls to 6-Week Low, as ALGO Surges 15% on Saturday – Market Updates Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme