NPM users warned dozens of malicious packages to steal host and network data


  • The socket found 60 malicious NPM packages
  • FALSIFIED FALLWARE PACKAGES
  • I was able to exfiltrate confidential data

Socket cybersecurity researchers have warned of multiple malicious packages housed in NPM, stealing data from confidential users and transmitting them to the attackers.

In a blog post, Socket said he identified 60 packages in NPM, which were loaded since May 12 onwards, using three separate accounts. The packages contained a subsequent script to the installation that is executed during the ‘NPM Installation’ and exfiltrates the host names, internal IP addresses, user starting directories, current work directories, user names and system DNS servers of the system.

Leave a Comment

Your email address will not be published. Required fields are marked *