Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    These streaming services have the best offline mode for traveling

    June 8, 2025

    WWDC 2025: What is expected from the Worldwide Developers Conference of Apple Intellization, Apple from iOS 26

    June 8, 2025

    I defeated a bird by talking about the Bible in this low-Fi first-Person RPG, where you are the 19th-century Deman Summer

    June 8, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Do dozens of malicious package hosts and network data on NPM
    Security

    Do dozens of malicious package hosts and network data on NPM

    PineapplesUpdateBy PineapplesUpdateMay 23, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Do dozens of malicious package hosts and network data on NPM
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Do dozens of malicious package hosts and network data on NPM

    60 packages have been discovered in the NPM index that try to collect sensitive hosts and network data and send it to a discord webhook controlled by a danger actor.

    As Souck threatening research teamThe package was uploaded from three publisher accounts in the NPM repository starting on May 12.

    Each of the malicious package has a post-install script that automatically executes during ‘NPM installed’ and collects the following information:

    • Host name
    • Internal IP address
    • User home directory
    • Current working directory
    • User name
    • System DNS Server

    The script checks for hosts belonging to cloud providers, reverseing DNS strings, an attempt to determine if this analysis is running in the environment.

    The socket did not inspect the second -stage payload, privilege increase, or the distribution of any frequent mechanisms. However, given the type of data collected, the risk of targeted network attacks is important.

    Packages are still available on NPM

    Researchers reported malicious packages but at the time of writing they were still available at NPM and showed a cumulative download of 3,000. By publishing time, however, none of them was present in the repository.

    To use them to developers, the actor with danger behind the campaign used the same names as valid packages in the index, such as ‘Flipper-Plugins, “React-Extrem 2,’ and ‘Hermes-Inspector-Magen,’ Generic Trust-Evocking names, and others who indicate in tests, probably indicate CI/CD Pipelines.

    The complete list of 60 malicious packages is available at the bottom of the report of the socket.

    If you have installed any of them, it is recommended to remove them immediately and scan a full system to eradicate any transition residue.

    Data wiper on NPM

    Another Malisios campaign Socket exposed Yesterday the NPM consisted of eight malicious packages that mimic valid devices through typosketing, but can remove files, corrupt data, and turn off the system.

    The package, who targeted the response, Vue.JS, Vite, Node.JS, and Quill Ecosystems, were present at NPM for the last two years, receiving 6,200 downloads.

    This prolonged growth was due to the pelode being active on the basis of the partially hardcoded system dates and was structured to destroy progressively, corrupt core JavaScript methods and sabotage browser storage mechanisms.

    Script designed to remove vue.JS-related files on June 19-30, 2023
    Script designed to remove vue.JS-related files on June 19-30, 2023
    Source: socket

    The actor, who published him under the name ‘XuxingFeng’, has also listed several legitimate packages for the construction of trusts and aweed detections.

    Although this danger has now passed on the basis of hardcoded dates, removing packages is important because their writers can present the updates that will again trigger their wipes tasks in the future.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    data dozens hosts malicious Network NPM package
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe trailer of ‘The Bukeners season 2 is to tease romance and new characters here
    Next Article 10 best technology deals this week
    PineapplesUpdate
    • Website

    Related Posts

    AI/ML

    AI working is a rapid network case, the latest benchmark test show

    June 8, 2025
    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Security

    Supply series attacks Glustac NPM package with 960K weekly download

    June 7, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025594 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025536 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025465 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Meta delay entrusts ‘Bhamoth’ AI model, Openi and Google more than one more head start

    May 16, 20250 Views

    The new coding agent of Chatgpt is very big, even if you are not a programmer

    May 16, 20250 Views

    Google’s AI overview is often wrong with so confident that I have lost all confidence in them

    May 16, 20250 Views
    Our Picks

    These streaming services have the best offline mode for traveling

    June 8, 2025

    WWDC 2025: What is expected from the Worldwide Developers Conference of Apple Intellization, Apple from iOS 26

    June 8, 2025

    I defeated a bird by talking about the Bible in this low-Fi first-Person RPG, where you are the 19th-century Deman Summer

    June 8, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.