Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Do dozens of malicious package hosts and network data on NPM
    Security

    Do dozens of malicious package hosts and network data on NPM

    PineapplesUpdateBy PineapplesUpdateMay 23, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Do dozens of malicious package hosts and network data on NPM
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Do dozens of malicious package hosts and network data on NPM

    60 packages have been discovered in the NPM index that try to collect sensitive hosts and network data and send it to a discord webhook controlled by a danger actor.

    As Souck threatening research teamThe package was uploaded from three publisher accounts in the NPM repository starting on May 12.

    Each of the malicious package has a post-install script that automatically executes during ‘NPM installed’ and collects the following information:

    • Host name
    • Internal IP address
    • User home directory
    • Current working directory
    • User name
    • System DNS Server

    The script checks for hosts belonging to cloud providers, reverseing DNS strings, an attempt to determine if this analysis is running in the environment.

    The socket did not inspect the second -stage payload, privilege increase, or the distribution of any frequent mechanisms. However, given the type of data collected, the risk of targeted network attacks is important.

    Packages are still available on NPM

    Researchers reported malicious packages but at the time of writing they were still available at NPM and showed a cumulative download of 3,000. By publishing time, however, none of them was present in the repository.

    To use them to developers, the actor with danger behind the campaign used the same names as valid packages in the index, such as ‘Flipper-Plugins, “React-Extrem 2,’ and ‘Hermes-Inspector-Magen,’ Generic Trust-Evocking names, and others who indicate in tests, probably indicate CI/CD Pipelines.

    The complete list of 60 malicious packages is available at the bottom of the report of the socket.

    If you have installed any of them, it is recommended to remove them immediately and scan a full system to eradicate any transition residue.

    Data wiper on NPM

    Another Malisios campaign Socket exposed Yesterday the NPM consisted of eight malicious packages that mimic valid devices through typosketing, but can remove files, corrupt data, and turn off the system.

    The package, who targeted the response, Vue.JS, Vite, Node.JS, and Quill Ecosystems, were present at NPM for the last two years, receiving 6,200 downloads.

    This prolonged growth was due to the pelode being active on the basis of the partially hardcoded system dates and was structured to destroy progressively, corrupt core JavaScript methods and sabotage browser storage mechanisms.

    Script designed to remove vue.JS-related files on June 19-30, 2023
    Script designed to remove vue.JS-related files on June 19-30, 2023
    Source: socket

    The actor, who published him under the name ‘XuxingFeng’, has also listed several legitimate packages for the construction of trusts and aweed detections.

    Although this danger has now passed on the basis of hardcoded dates, removing packages is important because their writers can present the updates that will again trigger their wipes tasks in the future.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    data dozens hosts malicious Network NPM package
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe trailer of ‘The Bukeners season 2 is to tease romance and new characters here
    Next Article 10 best technology deals this week
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How to Disable ACR on Your TV (And Stop Data Tracking Forever)

    January 13, 2026
    Startups

    Can You Become an AI Data Trainer? How to prepare and what is it worth

    January 3, 2026
    Startups

    Goodbye, Wi-Fi: How to Add a Wired Network to Your Home Without Running Ethernet

    December 27, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.