Backdoor for Windows, macOS, and Linux went undetected until now

Backdoor for Windows, macOS, and Linux went undetected until now

Researchers have uncovered a never-before-seen backdoor written from scratch for systems running Windows, macOS, or Linux that remained undetected by virtually all malware scanning engines.

Researchers from security firm Intezer said they discovered SysJoker—the name they gave the backdoor—on the Linux-based Webserver of a “leading educational institution.” As the researchers dug in, they found SysJoker versions for both Windows and macOS as well. They suspect the cross-platform malware was unleashed in the second half of last year.

The discovery is significant for several reasons. First, fully cross-platform malware is something of a rarity, with most malicious software being written for a specific operating system. The backdoor was also written from scratch and made use of four separate command-and-control servers, an indication that the people who developed and used it were part of an advanced threat actor that invested significant resources. It’s also unusual for previously unseen Linux malware to be found in a real-world attack.

Analyses of the Windows version (by Intezer) and the version for Macs (by researcher Patrick Wardle) found that SysJoker provides advanced backdoor capabilities. Executable files for both the Windows and macOS versions had the suffix .ts. Intezer said that may be an indication the file masqueraded as a type script app spread after being sneaked into the npm JavaScript repository. Intezer went on to say that SysJoker masquerades as a system update.

Wardle, meanwhile, said the .ts extension may indicate the file masqueraded as video transport stream content. He also found that the macOS file was digitally signed, though with an ad-hoc signature.

SysJoker is written in C++, and as of Tuesday, the Linux and macOS versions were fully undetected on the VirusTotal malware search engine. The backdoor generates its control-server domain by decoding a string retrieved from a text file hosted on Google Drive. During the time the researchers were analyzing it, the server changed three times, indicating the attacker was active and monitoring for infected machines.

Based on organizations targeted and the malware’s behavior, Intezer’s assessment is that SysJoker is after specific targets, most likely with the goal of “​​espionage together with lateral movement which might also lead to a ransomware attack as one of the next stages.”

https://arstechnica.com/?p=1826079




Sviluppatori nel mirino con una versione infetta di dnSpy


Il popolare debugger è stato manipolato da un gruppo di pirati informatici che hanno diffuso sul Web una versione contenente un trojan.

Le vittime di un cyber attacco non sono tutte uguali e, in molti casi, non si tratta soltanto di una questione di “valore” squisitamente economico. La categoria degli sviluppatori, per esempio, rappresenta sempre più spesso un bersaglio privilegiato dei cyber criminali.

Il motivo è semplice: colpire chi sviluppa software apre la strada ad attacchi di filiera che possono coinvolgere “a cascata” molte più vittime.

L’ultima campagna di questo tipo individuata dagli esperti del MalwareHunterTeam riguarda dnSpy, uno strumento di debugging utilizzato in ambiente .NET.

Come riporta Bleeping Computer in un articolo pubblicato sabato scorso, la strategia adottata dai cyber criminali è piuttosto elaborata e ha compreso anche la creazione di un “sito civetta” per attirare potenziali vittime.

A rendere possibile gli attacchi sono le caratteristiche di dnSpy, il cui sviluppo è stato abbandonato dall’autore ma che “sopravvive” grazie alla disponibilità del codice sorgente e all’attività di altri sviluppatori che ne distribuiscono le nuove versioni su GitHub.

Proprio questa modalità aperta di sviluppo del software avrebbe offerto ai pirati informatici l’opportunità di creare una loro versione di dnSpy, al cui interno però si nascondono numerosi malware che vengono inoculati al momento dell’installazione del software.

dnSpy

Per distribuire con maggiore efficacia l’applicazione infetta, i cyber criminali hanno anche creato un sito Web (ora offline) con un look accattivante e hanno lanciato una campagna pubblicitaria per promuoverlo su diversi motori di ricerca.

dnSpy

Il cocktail di malware contenuto nella versione malevola di dnSpy comprende un po’ di tutto: da un crypto-miner a più classici trojan come Quasar RAT, passando per un eseguibile che consente di disattivare Windows Defender.

Con la chiusura del sito e la rimozione del repository su GitHub la vicenda sembra essersi conclusa. Almeno per adesso.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/10/sviluppatori-nel-mirino-con-una-versione-infetta-di-dnspy/?utm_source=rss&utm_medium=rss&utm_campaign=sviluppatori-nel-mirino-con-una-versione-infetta-di-dnspy




Malsmoke: la campagna di attacchi sfrutta un certificato Microsoft


Nuova tecnica sviluppata dai pirati informatici che sfruttano il malware ZLoader, già usato per diffondere ransomware come Conti e Ryuk.

Il sistema di certificazione digitale è uno strumento utile per verificare l’affidabilità di un’applicazione, ma quando i pirati riescono a violarne l’integrità si trasforma in una micidiale arma a doppio taglio.

Nel caso della campagna Malsmoke, individuata e descritta in un report pubblicato su Internet dai ricercatori di Check Point, è stato utilizzato un certificato valido di Microsoft che consente ai pirati di portare a termine i loro attacchi.

Il vettore iniziale di attacco sarebbe un falso aggiornamento Java che avvia la catena di infezione, utilizzando una serie di tecniche che consente a ZLoader di aggirare i sistemi di controllo.

Malsmoke

Secondo i ricercatori, il file collegato al certificato si chiama appContast.dll e consente loro di avviare l’iniezione al suo interno del payload.

Se in passato ZLoader era stato utilizzato come veicolo per la diffusione di noti ransomware come Ryuk e Conti, in questa particolare campagna i cyber criminali utilizzano invece un software per la gestione in remoto del computer, che permette di caricare e scaricare file, oltre a eseguire script sulla macchina compromessa.

Si tratta di Atera, un software commerciale che gli autori degli attacchi non si sono nemmeno sprecati ad acquistare: sembra infatti che sfruttino i 30 giorni di prova gratuiti offerti dal programma.

Malsmoke

L’obiettivo, insomma, sarebbe quello di rubare informazioni dal computer infetto, anche se le capacità del software non escludono che i pirati possano in seguito utilizzarlo per ulteriori tipologie di attacco.

Stando alle analisi di Check Point, la campagna di attacchi sarebbe iniziata nello scorso novembre e al momento le vittime complessive sarebbero più di 2.000.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2022/01/05/malsmoke-la-campagna-di-attacchi-sfrutta-un-certificato-microsoft/?utm_source=rss&utm_medium=rss&utm_campaign=malsmoke-la-campagna-di-attacchi-sfrutta-un-certificato-microsoft




Quando il malware è nascosto dal firmware del disco SSD


La tecnica consentirebbe di nascondere il codice malevolo a qualsiasi software antivirus. La chiave è nella funzionalità flex capacity.

Come nascondere un malware ai controlli dei software antivirus? Secondo quanto si legge in uno studio pubblicato da un gruppo di ricercatori coreani, è possibile farlo sfruttando le caratteristiche dei software di gestione dei dischi SSD.

La funzione su cui hanno concentrato l’attenzione gli autori della ricerca è flex capacity, un sistema che consente di gestire in maniera dinamica lo spazio su disco a seconda delle esigenze.

Flex capacity, nel dettaglio, permette di definire quanto spazio sia necessario per gestire la scrittura dei dati in maniera automatica, in modo da ottimizzare le prestazioni del disco.

SSD

Tutto questo è gestito a livello di firmware e sfrutta un’area del disco chiamata over-provisioning (OP area). La tecnica messa a punto dai ricercatori punta proprio su questo, consentendo di ottenere due possibili risultati particolarmente “appetitosi” per i pirati informatici.

Il primo riguarda l’accesso ai dati conservati in questa porzione del disco SSD che, come in molti altri casi, non vengono immediatamente eliminati una volta destinati alla cancellazione, ma vengono semplicemente “scollegati” dalla mapping table.

Questo aprirebbe la strada a un recupero di informazioni sensibili potenzialmente presenti in quella porzione di disco riservata alla funzione flex capacity.

La seconda opzione, più inquietante, riguarda l’ipotesi che i cyber criminali sfruttino questa sezione del disco per inserire il codice di un malware.

Il motivo? Semplice: la OP area è “nascosta” e, di conseguenza, non può essere soggetta a scansione con i normali strumenti antivirus. Il luogo ideale per nascondere un malware, che di conseguenza potrebbe agire indisturbato.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/12/31/quando-il-malware-e-nascosto-dal-firmware-del-disco-ssd/?utm_source=rss&utm_medium=rss&utm_campaign=quando-il-malware-e-nascosto-dal-firmware-del-disco-ssd




AvosLocker usa una semplice ma geniale tecnica di evasione


Gli autori del ransomware hanno trovato il modo per aggirare (o rendere più difficile) l’individuazione del malware. Ecco come funziona il trucchetto.

La soluzione più efficace, spesso, è anche quella più semplice. La regola si applica anche ai malware e, in particolare, alle tecniche di offuscamento ed evasione utilizzate dai cyber criminali per aggirare i controlli dei sistemi di sicurezza informatica.

Gli autori di AvosLocker hanno preso sul serio questa filosofia per dotare il loro ransomware di un sistema che, in molti casi, potrebbe permettergli di sfuggire ai controlli dei normali antivirus.

Lo stratagemma, come anticipato, non è particolarmente complicato: prevede semplicemente il riavvio del computer compromesso usando la modalità provvisoria di Windows.

Come spiegano in un post i ricercatori di Sophos, si tratta di una tecnica usata anche da altri gruppi di cyber criminali, come REvil e BlackMatter.

La variante messa a punto dai pirati del gruppo AvosLocker sfrutta uno strumento ulteriore: AnyDesktop. Si tratta di un popolare strumento di controllo a distanza per PC Windows che i pirati utilizzano per gestire le attività “collaterali” all’attacco.

AvosLocker

La procedura utilizzata dai cyber criminali prevede anche la creazione di un nuovo account utente con privilegi di amministratore (user: newadmin – password: password123456) e prevede un sistema per “tagliare fuori” gli amministratori legittimi dall’accesso in remoto al computer.

Non solo: utilizzando la modalità provvisoria, l’attività non viene registrata da molti antivirus che, in questa particolare condizione, non sono in grado di controllare le attività della macchina.

Insomma: seguendo questa procedura, i pirati informatici che distribuiscono AvosLocker riescono a ottenere il cntrollo del computer, impedire l’intervento dei responsabili IT che non hanno accesso fisico alla macchina e creare tutte le condizioni per avviare i loro ransomware.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/12/23/avoslocker-usa-una-semplice-ma-geniale-tecnica-di-evasione/?utm_source=rss&utm_medium=rss&utm_campaign=avoslocker-usa-una-semplice-ma-geniale-tecnica-di-evasione




Ecco PseudoManuscrypt: il tool di spionaggio derivato dal gruppo Lazarus


Individuata un’ondata di attacchi che usa un malware simile a quello sviluppato dal gruppo APT legato al governo della Corea del Nord.

Non si può dire che il gruppo Lazarus non sappia fare le cose in grande: stando alle attribuzioni ufficiali, ai pirati nordcoreani sarebbero da ricondurre attacchi come quello di WannaCry, la violazione dei sistemi di Sony e la (tentata) mega-truffa dai danni della Banca Nazionale del Bangladesh.

Nel caso di PseudoManuscrypt, però, i pirati legati al governo nordcoreano potrebbero non avere alcuna responsabilità.

Secondo quanto riportano i ricercatori di Kaspersky, il malware è stato individuato lo scorso gennaio (con un picco di diffusione a giugno) e avrebbe colpito più di 35.000 computer in 195 paesi diversi.

PseudoManuscrypt

Il nome PseudoManuscrypt, è stato scelto a causa delle somiglianze con Manuscrypt, un “impianto” utilizzato in passato da Lazarus.

Tuttavia, tenuto conto del gran numero di vittime e della mancanza di un focus definito, dalle parti di Kaspersky non collegano la campagna direttamente a Lazarus o ad altri gruppi APT (Advanced Persistent Threat) conosciuti.

Il nuovo malware, in realtà, condivide con il predecessore alcune caratteristiche peculiari, come l’utilizzo di un protocollo di comunicazione verso i server Command and Control piuttosto raro, usato appunto da Lazarus.

PseudoManuscrypt

Il modus operandi dei pirati che stanno usando PseudoManuscrypt, però, diverge da quello di un gruppo APT. Come si legge nel report, il trojan è stato diffuso in una prima fase attraverso falsi installer di software pirata, alcuni dei quali utilizzati nel settore industriale.

In seguito, però, i cyber criminali hanno cominciato a sfruttare come vettore di attacco la botnet Glupteba, nota per fornire un servizio “Malware as a Service”.

Insomma: il contesto in cui si muove PseudoManuscrypt è decisamente orientato al comune cyber crimine e non a quel settore specifico di “hacking di stato” di cui fa parte il gruppo Lazarus.

Le caratteristiche del malware rimangono quelle di un classico tool di spionaggio: capacità di registrare il testo digitato sul dispositivo compromesso, copiare gli appunti, rubare le credenziali di autenticazione VPN e RDP, catturare screenshot e simili.

PseudoManuscrypt

Stando all’analisi dei ricercatori, gli autori del malware si concentrerebbero sul settore ingegneristico e questo, insieme alle peculiarità della prima fase di diffusione del malware, farebbero pensare a un gruppo specializzato in spionaggio industriale.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/12/17/ecco-pseudomanuscrypt-il-nuovo-tool-di-spionaggio-derivato-dal-gruppo-lazarus/?utm_source=rss&utm_medium=rss&utm_campaign=ecco-pseudomanuscrypt-il-nuovo-tool-di-spionaggio-derivato-dal-gruppo-lazarus




Google Play app with 500,000 downloads sent user contacts to Russian server

A robotic hand tries to activate a smartphone.

An Android app with more than 500,000 downloads from Google Play has been caught hosting malware that surreptitiously sends users’ contacts to an attacker-controlled server and signs up users to pricey subscriptions, a security firm reported.

The app, named Color Message, was still available on Google servers at the time this post was being prepared. Google removed it more than three hours after I asked the company for comment.

Ostensibly, Color Message enhances text messaging by doing things such as adding emojis and blocking junk texts. But according to researchers at Pradeo Security said on Thursday, Color Message contains a family of malware known as Joker, which has infected millions of Android devices in the past.

“Our analysis of the Color Message application through the Pradeo Security engine shows that it accesses users’ contact list and exfiltrates it over the network,” the company’s blog post stated. “Simultaneously, the application automatically subscribes to unwanted paid services unbeknownst to users. To make it difficult to be removed, the application has the capability to hide its icon once installed.”

Pradeo’s discovery marks only the latest instance of Google hosting malicious wares that harm users of its Android mobile operating system. While the company scans apps for malware and regularly removes huge numbers of submissions proactively, there’s no shortage of apps Google misses. The frequent reports of rogue apps available through Play tarnishes an otherwise clean security scorecard for the mobile OS, at least as it’s available on Google-developed Pixel devices.

Joker falls into a category of malware known as Fleeceware. It simulates clicks and intercepts text messages in an attempt to surreptitiously subscribe users to paid premium services they never intended to buy. Joker is hard to detect because of the tiny footprint of its code and the techniques its developers use to stash it. Over the past few years, the malware has been found lurking in hundreds of apps downloaded by millions of people.

Besides sending users’ contacts to a server that appears to be located in Russia and subscribing to unwanted services, Color Message also fails to disclose the extent of the actions the app can perform on users’ devices.

As usual, Android users should be circumspect before downloading apps. A good rule of thumb is to download apps only when they provide a true benefit and then to choose ones made by known companies, when possible. People should also read the user reviews to see if there are reports of malice.

https://arstechnica.com/?p=1821282




Backdoor gives hackers complete control over federal agency network

Backdoor gives hackers complete control over federal agency network

A US federal agency has been hosting a backdoor that can provide total visibility into and complete control over the agency network, and the researchers who discovered it have been unable to engage with the administrators responsible, security firm Avast said on Thursday.

The US Commission on International Religious Freedom, associated with international rights, regularly communicates with other US agencies and international governmental and nongovernmental organizations. The security firm published a blog post after multiple attempts failed to report the findings directly and through channels the US government has in place. The post didn’t name the agency, but a spokeswoman did in an email.

Members of Avast’s threat intelligence team wrote:

While we have no information on the impact of this attack or the actions taken by the attackers, based on our analysis of the files in question, we believe it’s reasonable to conclude that the attackers were able to intercept and possibly exfiltrate all local network traffic in this organization. This could include information exchanged with other US government agencies and other international governmental and nongovernmental organizations (NGOs) focused on international rights. We also have indications that the attackers could run code of their choosing in the operating system’s context on infected systems, giving them complete control.

Bypassing firewalls and network monitoring

The backdoor works by replacing a normal Windows file named oci.dll with two malicious ones—one early in the attack and the other later on. The first imposter file implements WinDivert, a legitimate tool for capturing, modifying, or dropping network packets sent to or from the Windows network stack. The file allows the attackers to download and run malicious code on the infected system. Avast suspects the main purpose of the downloader is to bypass firewalls and network monitoring.

At a later stage in the attack, the intruders replaced the fake oci.dll downloader with code that decrypts a malicious file named SecurityHealthServer.dll and loads it into memory. The functions and flow of this second fake DLL are almost identical to rcview40u.dll, a malicious file that was dropped in espionage-driven supply chain hacks that targeted South Korean organizations in 2018.

“Because of the similarities between this oci.dll and rcview40u.dll, we believe it is likely that the attacker had access to the source code of the three year-old rcview40u.dll,” Avast researchers wrote. “The newer oci.dll has minor changes like starting the decrypted file in a new thread instead of in a function call which is what rcview40u.dll does. oci.dll was also compiled for x86-64 architecture while rcview40u.dll was only compiled for x86 architecture.”

The net effect of the attack sequence is that the attackers were able to compromise the federal agency network in a way that allowed them to execute code with the same unfettered system rights as the OS and capture any traffic passing into or out of the infected machines.

Because officials with the compromised agency didn’t engage with Avast researchers, they can’t be sure precisely what the attackers were doing inside the network. But the implications are clear.

“It is reasonable to presume that some form of data gathering and exfiltration of network traffic happened, but that is informed speculation,” the researchers wrote. “Further because this could have given total visibility of the network and complete control of an infected system it is further reasonable speculation that this could be the first step in a multi-stage attack to penetrate this, or other networks more deeply in a classic APT-type operation.”

https://arstechnica.com/?p=1821223




Google: l’exploit usato da Pegasus per l’iPhone ha dell’incredibile


La tecnica che consente di compromettere lo smartphone Apple con una strategia “zero-click” sfrutta una sorprendente forma di emulazione in iMessage.

Non solo devastante dal punto di vista dell’impatto sulle vittime: la tecnica di attacco messa a punto da NSO Group per diffondere il suo spyware Pegasus sugli iPhone ha anche caratteristiche tecniche sorprendenti.

A spiegarlo sono i ricercatori del Project Zero di Google, che in un report pubblicato su Internet esaminano i dettagli di funzionamento dell’exploit messo a punto dalla società israeliana specializzata in “sorveglianza” cibernetica.

La tecnica di attacco, denunciata qualche tempo fa da Citizen Lab e Amnesty International come uno strumento utilizzato per colpire attivisti dei diritti civili, avvocati, giornalisti e oppositori politici di regimi ben poco democratici, fa leva su iMessage e consente di compromettere un dispositivo in modalità “zero-click”, senza cioè che l’utente debba fare nulla.

In altre parole, di fronte alla strategia adottata da NSO Group, anche quelle “buone pratiche” che siamo abituati a considerare utili per evitare gli attacchi, come evitare di aprire link sospetti, non servono a nulla.

L’analisi tecnica dell’exploit, però, svela qualcosa in più. In particolare, gli autori del report (Ian Beer e Samuel Groß) spiegano che la tecnica fa leva sul sistema di visualizzazione delle GIF animate in iMessage.

Pegasus

Per rendere più accattivanti le GIF animate in iMessage, Apple ha utilizzato un trucchetto che consente di creare un loop dell’animazione. Per farlo, però, il sistema crea una nuova GIF prima che questa sia visualizzata in iMessage. In altre parole, tutto avviene prima che l’utente apra il messaggio e questo spiega come possa agire senza alcun click da parte dell’utente. Ma su quale vulnerabilità fa leva?

A occuparsi dell’elaborazione in iOS, spiegano i ricercatori, sono le API CoreGraphics. Proprio una di queste contiene la vulnerabilità sfruttata da NSO Group per installare Pegasus. Nel dettaglio, la “vittima” dell’exploit è il sistema di parsing di CoreGraphics PDF.

Il trucco funziona a causa di una particolarità di iOS, in cui la scelta del formato non è legata all’estensione del file, ma affidata alla libreria ImageIO che ne analizza il contenuto. Anche se l’estensione è .GIF, quindi, un PDF viene trattato come tale.

Il formato PDF, spiegano gli autori del report, è stato usato spesso come vettore di attacco a causa della sua complessità e di caratteristiche particolari come la possibilità di integrare JavaScript.

Gli sviluppatori di NSO Group, però, hanno utilizzato un’altra strada e, in particolare, hanno usato le peculiari caratteristiche di un formato di compressione chiamato JBIG2, utilizzato negli anni 90 da produttori come  Xerox per ridurre ai minimi termini le dimensioni delle scansioni. La sua implementazione in iOS è basata su Xpdf, il cui codice è disponibile gratuitamente online.

Ed è qui che si annida la vulnerabilità sfruttata per diffondere Pegasus. JBIG utilizza infatti una serie di comandi che gli sviluppatori israeliani sono riusciti a usare per creare una sorta di architettura personalizzata in cui eseguire degli script.

Insomma: tutto il processo di attacco avviene all’interno di un ambiente di emulazione personalizzato, praticamente impossibile da interpretare a monte. Una tecnica che gli autori dello studio definiscono, a ragione, “incredibile e terrificante”.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2021/12/16/google-lexploit-usato-da-pegasus-per-liphone-ha-dellincredibile/?utm_source=rss&utm_medium=rss&utm_campaign=google-lexploit-usato-da-pegasus-per-liphone-ha-dellincredibile




Malicious NPM packages are part of a malware “barrage” hitting repositories

Malicious NPM packages are part of a malware “barrage” hitting repositories

Researchers have found another 17 malicious packages in an open source repository, as the use of such repositories to spread malware continues to flourish.

This time, the malicious code was found in NPM, where 11 million developers trade more than 1 million packages among each other. Many of the 17 malicious packages appear to have been spread by different threat actors who used varying techniques and amounts of effort to trick developers into downloading malicious wares instead of the benign ones intended.

This latest discovery continues a trend first spotted a few years ago, in which miscreants sneak information stealers, keyloggers, or other types of malware into packages available in NPM, RubyGems, PyPi, or another repository. In many cases, the malicious package has a name that’s a single letter different than a legitimate package. Often, the malicious package includes the same code and functionality as the package being impersonated and adds concealed code that carries out additional nefarious actions.

A ripe attack vector

“We are witnessing a recent barrage of malicious software hosted and delivered through open-source software repositories,” JFrog researchers Andrey Polkovnychenko and Shachar Menashe wrote on Wednesday. “Public repositories have become a handy instrument for malware distribution: the repository’s server is a trusted resource, and communication with it does not raise the suspicion of any antivirus or firewall. In addition, the ease of installation via automation tools such as the npm client, provides a ripe attack vector.”

Most of the packages JFrog flagged stole credentials or other information for Discord servers. Discord has become a popular platform for people to communicate through text, voice, and video. Compromised servers can be used as command and control channels for botnets or as a proxy when downloading data from a hacked server. Some packages stole credit card data associated with hacked Discord accounts.

Two packages—discord-lofy and discord-selfbot-v14—came from an author using the name davisousa. They masquerade as modifications of the popular legitimate library discord.js, which enables interaction with the Discord API. The malware incorporates the original discord.js library as its base and then injects obfuscated malicious code into one of the package files.

The JFrog researchers wrote:

The obfuscated version of the code is enormous: more than 4,000 lines of unreadable code, containing every possible method of obfuscation: mangled variable names, encrypted strings, code flattening and reflected function calls:

Through manual analysis and scripting, we were able to deobfuscate the package and reveal that its final payload is quite straightforward—the payload simply iterates over the local storage folders of well-known browsers (and Discord-specific folders), then searches them for strings looking like a Discord token by using a regular expression. Any found token is sent back via HTTP POST to the hardcoded server https://aba45cf.glitch.me/polarlindo.

Another package named fix-error claimed to fix errors in a discord “selfbot.” It, too, contained malicious code that had been obfuscated but, in this case, was much easier for the researchers to deobfuscate. The researchers soon determined that the hidden code was a stolen version of the PirateStealer, an app that steals credit card information, login credentials, and other private data stored in a Discord client. It works by injecting malicious Javascript code into the Discord client. The code then “spies” on the user and sends the stolen information to a hardcoded address.

A third example is prerequests-xcode, a package that contains remote-access trojan functionality. The researchers wrote:

When inspecting the package’s code, we identified it contains a Node.JS port of
DiscordRAT(originally written in Python) which gives an attacker full control over the victim’s machine. The malware is obfuscated with the popular online tool obfuscator.io, but in this case it is enough to inspect the list of available commands to understand the RAT’s functionality (copied verbatim).

The full list of packages is:

Package Version Payload Infection Method
prerequests-xcode 1.0.4 Remote Access Trojan (RAT) Unknown
discord-selfbot-v14 12.0.3 Discord token grabber Typosquatting/Trojan (discord.js)
discord-lofy 11.5.1 Discord token grabber Typosquatting/Trojan (discord.js)
discordsystem 11.5.1 Discord token grabber Typosquatting/Trojan (discord.js)
discord-vilao 1.0.0 Discord token grabber Typosquatting/Trojan (discord.js)
fix-error 1.0.0 PirateStealer (Discord malware) Trojan
wafer-bind 1.1.2 Environment variable stealer Typosquatting (wafer-*)
wafer-autocomplete 1.25.0 Environment variable stealer Typosquatting (wafer-*)
wafer-beacon 1.3.3 Environment variable stealer Typosquatting (wafer-*)
wafer-caas 1.14.20 Environment variable stealer Typosquatting (wafer-*)
wafer-toggle 1.15.4 Environment variable stealer Typosquatting (wafer-*)
wafer-geolocation 1.2.10 Environment variable stealer Typosquatting (wafer-*)
wafer-image 1.2.2 Environment variable stealer Typosquatting (wafer-*)
wafer-form 1.30.1 Environment variable stealer Typosquatting (wafer-*)
wafer-lightbox 1.5.4 Environment variable stealer Typosquatting (wafer-*)
octavius-public 1.836.609 Environment variable stealer Typosquatting (octavius)
mrg-message-broker 9998.987.376 Environment variable stealer Dependency confusion

As noted earlier, NPM isn’t the only open source repository to be infiltrated with malicious packages. The PyPi repository for Python has seen its share of malware-laden packages, as has RubyGems.

People downloading open source packages should take extra care in making sure the item they’re downloading is legitimate and not malware masquerading as something legitimate. Larger organizations that rely heavily on open source software may find it useful to purchase package management services, which JFrog just happens to sell.

https://arstechnica.com/?p=1818997