Cyber Security News

Malicious npm and PyPi Packages Exfiltrate SSH Keys From Server

JavaScript and Python both have their own package repositories called npm (Node Package Manager) and PyPi (Python Package Index), respectively.

They act as key centers for publishing and exchanging reusable code libraries and packages by developers.

Sonatype Security Research tracks the npm registry campaign extracting Kubernetes configs and SSH keys via npm packages. Their automated system found 14 malicious packages, which were promptly reported to npm registry admins by researchers.

Sonatype researchers Carlos Fernandez and Gustavo Simoes find deceptive packages mimicking JavaScript libraries containing obfuscated code to steal sensitive files post-installation.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

Tracked packages

Here below, we have mentioned all the packages that are tracked as “Sonatype-2023-4000” and “Sonatype-2023-4004”:-

  • @am-fe/hooks
  • @am-fe/provider
  • @am-fe/request
  • @am-fe/utils
  • @am-fe/watermark
  • @am-fe/watermark-core
  • @dynamic-form-components/mui
  • @dynamic-form-components/shineout
  • @expue/app
  • @fixedwidthtable/fixedwidthtable
  • @soc-fe/use
  • @spgy/eslint-plugin-spgy-fe
  • @virtualsearchtable/virtualsearchtable
  • shineouts

Technical analysis

Batches of packages with under 200 downloads shared the commonality of using “app.threatest.com” in their accounts.

The package, named ‘fixedwidthtable,’ links to a non-descriptive ‘typescript-sdk-tools’ GitHub repository, raising the first red flag, as highlighted by Simoes.

fixedwidthtable or fixedwidthtable package (Source – SonaType)

While on the other hand, the package versions include functional code from real open-source packages, with alterations. In the ‘scripts’ folder, experts spot an ‘index.js’ file running obfuscated code.

index.js file (Source – SonaType)

Similar code and tactics are found in other campaign packages, and the cybersecurity researchers deobfuscated payloads. 

While the earlier versions, like ‘@am-fe/hooks,’ revealed attacker intentions with unobfuscated payload. Mirroring previous PoC exploits, the script gathers SSH keys, Kubernetes config, and basic system info like:-

  • Username
  • IP
  • Hostname

Yet, this stealthy data collection and deceptive npm metadata indicate the malicious intent.

Fernandez highlights the risk of unauthorized Kubernetes access, especially if it exploits recent vulnerabilities. The domain app.threatest[.]com resolves to Cloudflare IPs (172.67.141.49, 104.21.9.30), making attribution challenging. 

However, besides this, security analysts found Mandarin comments during their analysis, but the comments are not conclusive of a specific threat actor.

Researchers tried contacting package publishers via metadata and WHOIS records but received no response. Given the current findings, analysts still consider these packages malicious.

Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

1 hour ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago